Don't miss out on any news and changes relating to CE! Register now for the CE InfoService
Share Article
On 20 November 2024, Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements, the so-called Cyber Resilience Act (CRA for short), was published in the EU Official Journal. The regulation is intended to ensure that a wide range of products such as networked home cameras, refrigerators, televisions, toys and even machines are secure before they are placed on the market.
The new regulation is intended to close gaps, clarify interrelationships and make the existing legal framework for cybersecurity more coherent in order to ensure that products with digital components, e.g. Internet of Things (IoT) products, are secure throughout the entire supply chain and life cycle.
Note: This technical article is updated on an ongoing basis. Don't miss any important updates and subscribe to our free newsletter or follow us on LinkedIn!
Subscribe to newsletter
Follow IBF on LinkedIn
Background
With the Cyber Resilience Act, the EU has established its first horizontal regulatory framework for the cybersecurity of products with digital elements. Its aim is to improve the cybersecurity of hardware and software products throughout their entire lifecycle and to close existing gaps in the European regulatory framework.
The European Commission presented its proposal for the CRA in September 2022. Following the conclusion of the legislative process, Regulation (EU) 2024/2847 was published in the Official Journal of the European Union on 20 November 2024 and entered into force on 10 December 2024. Most requirements will apply from 11 December 2027, while certain provisions will become applicable earlier.
Seminar tip
Designing safe machines - risk assessment in practice
In just one day, our seminar "Designing safe machines - risk assessment in practice" teaches technical designers and technical planners how risk assessments should be integrated as efficiently as possible into the development processes of machines or systems.
Register now
When will the Cyber Resilience Act apply?
On 20 November 2024, the Cyber Resilience Act, the new law on cybersecurity requirements for products with digital elements, was published in the EU Official Journal.
When does the Cyber Resilience Act become applicable?
The new regulation will enter into force twenty days after publication in the Official Journal of the EU (10 December 2024) and will apply directly in every EU member state 36 months after this entry into force, namely from 11 December 2027.
Some provisions will apply earlier:
Why was the Cyber Resilience Act introduced?
The new ‘Cyber Resilience Act’ is intended to ensure that digital products become more secure for individuals and businesses. Manufacturers of such products, both hardware and software, will be obliged to use software updates to fix vulnerabilities and to inform the end users of their products about possible cybersecurity risks. In addition, the regulation defines requirements for software development and thus also emphasises the ‘security by design’ required by the ‘Cyber Security Act’ already in force.
What are the goals of the Cyber Resilience Act?
The overarching aim of the Cyber Resilience Act is to improve the cybersecurity of hardware and software products on the EU internal market. The Commission has defined four key objectives of the legislation:
What is the scope of the Cyber Resilience Act?
The scope of the regulation shows that this area is very broadly defined:
‘This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.’
Given the broad definition of products with digital elements, the regulation thus covers both hardware products such as machines and IoT devices as well as software products.
Exceptions are also mentioned in the scope of application; for example, medical devices according to Regulation (EU) 2017/745 do not fall within the scope of the regulation.
The CRA also addresses its interaction with Delegated Regulation 2022/30, which already establishes cybersecurity requirements for certain internet-connected radio equipment under the Radio Equipment Directive 2014/53/EU. To avoid regulatory overlap, Delegated Regulation (EU) 2022/30 will be repealed. The corresponding legal act was published in the Official Journal of the European Union on 29 April 2026 and provides for the repeal to take effect in December 2027, in connection with the general application of the CRA.
Does the Cyber Resilience Act require a conformity assessment procedure and a ‘cyber risk assessment’?
In line with other EU legislation, such as the Machinery Directive and the Low Voltage Directive, the Cyber Resilience Act also provides for a conformity assessment procedure.
At the core of this procedure is what we refer to here as the “cyber risk assessment”. This creates a useful parallel, particularly for machinery manufacturers, with the risk assessment already familiar from machinery safety. The CRA itself refers to an “assessment of the cybersecurity risks”. Article 13(2) provides:
‘[...] manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users.’
Depending on the criticality of the products, the conformity assessment procedure distinguishes between self-certification and two procedures in which notified bodies must be involved. Details can be found in the factsheet on the Cyber Resilience Act.
In our view, the details point 2 of Annex VII of the regulation are particularly noteworthy for manufacturers. The document mentions various aspects (design, development, production, vulnerability analysis) as content for the technical documentation. Accordingly, software architecture decisions as well as decisions relating to development and build processes will need to be documented in the software development process in the future. For manufacturers, this may result in additional documentation requirements. In particular, the rapid technological development of software development tools (e.g. for build processes) will certainly present companies with organisational challenges in the future that can be overcome but should not be underestimated.
The relevant provision reads as follows
"CONTENTS OF THE TECHNICAL DOCUMENTATION
(…)
a description of the design, development and production of the product with digital elements and vulnerability handling processes, including:
(a) necessary information on the design and development of the product with digital elements, including, where applicable, drawings and schemes and a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing;
(b) necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;
(c) necessary information and specifications of the production and monitoring processes of the product with digital elements and the validation of those processes;'
What do the requirements of the Cyber Resilience Act mean for manufacturers?
The German Federal Office for Information Security (BSI) is providing support for manufacturers in identifying the CRA requirements with the publication of the Technical Guideline TR-03183. Further information can be found in our technical article ‘Technical guideline for cyber resilience requirements’.
How do the reporting obligations and the Single Reporting Platform work?
The reporting obligations under the Cyber Resilience Act will apply from 11 September 2026. From that date, manufacturers will be required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
For these notifications, ENISA provides the Single Reporting Platform (SRP), which serves as a central reporting point and enables manufacturers to submit a notification only once. When submitting a notification, the manufacturer selects the competent CSIRT (Computer Security Incident Response Team) as the coordinator. As a general rule, the competent CSIRT is determined by the Member State in which the manufacturer has its main establishment. The notification is also made available to ENISA and, where necessary, forwarded to other affected CSIRTs and market surveillance authorities.
The CRA provides for a multi-stage reporting procedure. An early warning must be submitted within 24 hours of becoming aware of a reportable vulnerability or incident. Within 72 hours, manufacturers must provide additional information and an initial assessment. A final report must subsequently be submitted. For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, it must be submitted no later than one month after the 72-hour notification.
ENISA now provides specific guidance on registration and use of the SRP as well as on submitting and updating notifications. Manufacturers should therefore familiarise themselves with the platform at an early stage and establish internal processes for identifying and assessing potentially reportable vulnerabilities and incidents and for handling notifications within the applicable deadlines.
When will harmonised standards for the Cyber Resilience Act be introduced?
On 3 February 2025, the Commission officially called upon the European standardisation organisations CEN, CENELEC and ETSI to draw up “harmonised standards for the essential cybersecurity requirements set out in Annex I to this Regulation”. As part of this standardisation request, the Commission aims to take into account existing European and international standards in the field of cybersecurity that have already been published or are currently being developed.
The main document of the standardisation request contains the recitals as well as formal aspects such as reporting and validity; the annexes to the request set out specific lists of the new European standards to be developed (Annex I) and their requirement profiles (Annex II), categorised into horizontal and vertical standards.
Horizontal standards (lines 1–15 in Annex I) are intended to establish a coherent general framework regarding security requirements and the management of vulnerabilities. Vertical standards, on the other hand (lines 16–41), cover security requirements for specific product categories.
In their webinar ‘Standards supporting the Cyber Resilience Act’1, CEN/CENELEC also presented a hierarchical model of such future CRA standards, which is strongly reminiscent of the division into Type A, B and C standards in the Official Journal of the European Union for the Machinery Directive and the Machinery Regulation respectively. Here too, the following applies:
According to the information provided in the webinar, the deadline for the adoption of the horizontal Type A standard(s) and the Type B standards on vulnerability management is set for 30 August 2026 at the latest. Type-C standards for the individual product categories must be in place by 30 October 2026; shortly before the CRA comes into force on 11 December 2027, the Type B standards for technical measures will follow (30 October 2027). At present, it seems likely that the 2026 deadlines in particular will not be met – for this reason, an amendment to the CRA standardisation request is planned, under which the two deadlines are to be postponed by two months. This amendment is currently only available as a draft; final publication of the corresponding implementing decision in the Official Journal of the EU is still pending.
An overview of the future categorisation and its planned implementation (based on current information) can be found in the chart below2:
Are there already examples of standards and specifications that could potentially be harmonised to meet CRA requirements?
The standardisation mandate explicitly refers to ‘new European standards to be drafted’. Nevertheless, CEN, CENELEC and ETSI could draw on existing documents.
Examples of such standards and specifications that could potentially be harmonised to meet the CRA requirements are:
In line with the new Machinery Regulation (EU) 2023/1230, the Commission may, in the absence of harmonised standards for the cybersecurity requirements of Annex I, adopt implementing acts with common specifications for technical requirements. The legislator reserves this option in case the desired standards are not delivered within the set deadline, the standardisation mandate is not accepted or the content of the documents does not comply with the mandate.
The following documents are a valuable source of information for machine manufacturers:
What is the relationship between the Cyber Resilience Act and the NIS 2 Directive?
The NIS 2 Directive primarily addresses the cybersecurity of essential and important entities and their network and information systems. Entities within its scope are required to take appropriate and proportionate measures to manage cybersecurity risks. In our technical article "NIS-2 Directive in mechanical engineering", we explain which companies are directly affected (as operators) and what requirements and sanctions the directive provides for.
The Cyber Resilience Act, by contrast, lays down cybersecurity requirements for products with digital elements and addresses the economic operators involved, in particular manufacturers.
In simplified terms, NIS 2 therefore focuses primarily on the cybersecurity of entities and their network and information systems, whereas the CRA focuses on the cybersecurity of products with digital elements throughout their lifecycle.
On 20 November 2024, the final version of the Cyber Resilience Act was published in the EU Official Journal. You can access the full text of Regulation (EU) 2024/2847 via the following link:
Cyber Resilience Act 2024/2847 of 20 November 2024
Amendments and corrigenda to the Cyber Resilience Act
On 5 March 2025, the Cyber Resilience Act was amended by Regulation (EU) 2025/327 on the European Health Data Space (EHDS). The regulation governs the access to, use and protection of electronic health data within the EU.
It supplements the provisions of the Cyber Resilience Act with regard to security requirements for digital health products, defines standardised technical documentation for health software and creates rules for software-as-a-service (SaaS) models that do not fall directly under the Cyber Resilience Act.
On 2 July 2025, the EU Commission published the Corrigendum 2025/90555. In all language versions of the CRA, Article 64(10), has been amended. Previously, the phrase ‘By way of derogation from paragraphs 3 to 9...’ appeared there, but now the deviation applies to paragraphs 2to 9. This means that the microenterprises, small businesses or open-source software stewards listed in Article 64(10) are exempt from the corresponding fines in Article 64(2).
Further publications on the CRA in the Official Journal of the EU
On 1 December 2025, Commission Implementing Regulation (EU) 2025/2392 was published in the Official Journal of the European Union. This implementing act had to be published by 11 December 2025 at the latest (i.e. two years before the CRA becomes generally applicable) in accordance with the regulation and contains the technical description of the categories of important (Annex III) and critical products (Annex IV) with digital elements of the CRA.
Annex I of Regulation 2025/2392 contains the technical descriptions of important products with digital elements, divided into classes 1 (e.g. password managers, network management systems or operating systems) and 2 (e.g. hypervisors, firewalls and tamper-resistant microprocessors). Annex II contains descriptions of critical elements such as hardware devices with security boxes, devices for advanced security purposes and smartcards.
On April 20, 2026, Delegated Regulation (EU) 2026/881 was published. It supplements the Cyber Resilience Act and sets out in detail the conditions under which the forwarding of reports concerning actively exploited vulnerabilities or serious security incidents may be temporarily delayed for cybersecurity reasons.
In principle, reports are forwarded to the relevant authorities via the Single Reporting Platform. In exceptional cases, however, the CSIRT that initially receives a report may delay its forwarding to other relevant CSIRTs for the period strictly necessary. This is subject to there being justified cybersecurity grounds for doing so.
The Regulation specifies the following cases in particular:
Sensitive information in the report: Disclosure may be delayed if it would give rise to a significant cybersecurity risk that cannot be sufficiently mitigated by appropriate restrictions on the processing or disclosure of the information. This may be the case, for example, if the reported information could facilitate the development of an attack method or if an effective risk mitigation measure, such as a security update, is expected in the short term.
Confidentiality at a specific CSIRT: If there are reasonable doubts as to whether a relevant CSIRT can guarantee the confidentiality of the reported information – for example, due to a cybersecurity incident of its own or significant security deficiencies – disclosure to that CSIRT may be temporarily suspended.
Disruption to the Single Reporting Platform: If the platform itself has been affected by a cybersecurity incident and the confidentiality of the reported information can no longer be guaranteed as a result, disclosure via the platform may be delayed until its secure operation has been restored.
The possibility of a delay therefore does not affect the manufacturer’s reporting obligation as such. Rather, the Delegated Regulation sets out the specific circumstances under which the subsequent transmission of a report that has already been submitted may be restricted or delayed.
FAQs on the Cyber Resilience Act
On 3 December 2025, the European Commission published a document on its website containing frequently asked questions about the Cyber Resilience Act (CRA). The 66-page document contains a collection of technical FAQs and is intended to help stakeholders implement the CRA. The FAQs do not cover the entire scope of the CRA, but rather address recurring questions that the Commission's services have collected since the CRA came into force. It is a ‘living document’ that will be updated by the Commission as necessary.
Guidance on the Cyber Resilience Act
On 27 July 2026, the European Commission published the final version of their guidance on the “Cyber Resilience Act”. The aim of the document is to define the obligations and scope of the regulation more clearly.
Particular emphasis is placed on making it easier for micro-enterprises and small and medium-sized enterprises to comply with the regulations. They can apply for additional support with implementation under the SECURE programme.In terms of content, the document focuses on solutions for remote data processing and on free and open-source software, on the concept of “support periods”, and on the interaction between the CRA and other EU legal acts.
ENISA Security by Design and Default Playbook
In the ‘Security by Design and Default Playbook’, ENISA, the European Union Agency for Cybersecurity, sets out in concrete terms how manufacturers of products with digital elements can implement the CRA’s requirements from both a technical and organisational perspective.
The practical guide, published in July 2026, is aimed in particular at software and IoT manufacturers and aims to systematically embed cybersecurity throughout the entire product lifecycle.
Further information
You can read an analysis of the Cyber Resilience Act from a legal perspective in the corresponding technical article by Dr Gerhard Wiebe.
Footnote:1 Webinar 'Standards supporting the Cyber Resilience Act' – see Details on the CEN/CENELEC Website2 Categorisation of future standards for CRA. Own representation based on the above-mentioned CEN/CENELEC webinar
Posted on: 2026-09-03 (last amendment)
Johannes Windeler-Frick, MSc ETH Member of the IBF management board. Specialist in CE marking and Safexpert. Presentations, podcasts and publications on various CE topics, in particular CE organisation and efficient CE management. Management of the further development of the Safexpert software system. Degree in electrical engineering from ETH Zurich (MSc) with a focus on energy technology and specialisation in the field of machine tools.
Email: johannes.windeler-frick@ibf-solutions.com | www.ibf-solutions.com
Daniel Zacek-Gebele, MSc Product manager at IBF for additional products and data manager for updating standards data on the Safexpert Live Server. Studied economics in Passau (BSc) and Stuttgart (MSc), specialising in International Business and Economics. Email: daniel.zacek-gebele@ibf-solutions.com | www.ibf-solutions.com
CE software for systematic and professional safety engineering
Practical seminars on aspects of risk assessment and ce marking
With the CE InfoService you stay informed about important developments in the field of product safety.