The accelerated digitization of economic activities brings not only opportunities but also growing cybersecurity risks. Software products, internet-connected devices, applications, access systems, smart devices, and other digital solutions can become targets of cyberattacks or contain vulnerabilities that affect both users and the companies that use them.
In this context, the European Union has adopted Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital components, known as the Cyber Resilience Act – CRA. The regulation introduces, for the first time at the European Union level, a common and mandatory set of cybersecurity requirements for hardware and software products placed on the European market.
What does cybersecurity mean?
Cybersecurity essentially refers to the set of technical, organizational, and legal measures designed to protect information systems, networks, devices, applications, and data against unauthorized access, attacks, compromise, or destruction.
Risks can take many forms: unauthorized access to a system, data theft, the installation of malicious software, ransomware attacks, the exploitation of vulnerabilities in a program or device, or the compromise of internet-connected devices.
Cybersecurity is therefore no longer just a technical issue for a company’s IT department. It is increasingly becoming a legal compliance obligation, and European legislation imposes specific responsibilities on companies regarding the prevention, identification, management, and reporting of security incidents.
What is the Cyber Resilience Act?
The Cyber Resilience Act aims to increase the security level of products with digital components sold in the European Union.
The underlying principle of the regulation is that cybersecurity must be taken into account from the very moment of product design and development, and not only after an incident or vulnerability has occurred. We are thus referring to concepts such as “security by design” and “security by default”: products must be designed, developed, and configured to provide an adequate level of security from the very beginning.
The Regulation entered into force in December 2024, and most of its obligations will become applicable as of December 11, 2027. However, a significant portion of the obligations regarding the reporting of actively exploited vulnerabilities and serious security incidents applies as of September 11, 2026.
Which products are covered?
The Regulation applies primarily to products with digital elements that are placed on or made available on the European Union market and that can be connected, directly or indirectly, to a device or a network.
Depending on the specific characteristics of the product, this category may include:
– software programs and applications;
– operating systems;
– routers and network equipment;
– connected surveillance cameras;
– access control systems;
– smart home devices;
– IoT (Internet of Things) products;
– connected industrial equipment;
– various other hardware or software products that communicate via a network.
The regulation also provides for certain exceptions for products that are already subject to specific sector-specific regulations.
Who has obligations under the regulation?
The Cyber Resilience Act does not apply exclusively to manufacturers.
Depending on their role in the supply chain, obligations may apply to:
– manufacturers, who develop or market products under their own name or brand;
– importers, who place products from third countries on the European Union market;
– distributors, who make products available to customers on the European market.
–
In certain situations, an importer or distributor may also assume the obligations of a manufacturer, for example, if they place the product on the market under their own brand or make substantial modifications to it. For this reason, it is not sufficient for a company that sells digital products to verify only the product’s technical characteristics. It is also necessary to precisely determine the legal role the company plays in the supply chain.
Key obligations introduced by the Cyber Resilience Act
One of the main changes brought about by the regulation is the shift from a reactive to a preventive approach.
Manufacturers must conduct a cybersecurity risk assessment and take its results into account throughout the entire product lifecycle. Products must be designed to provide a level of security appropriate to the risks and, as far as possible, be placed on the market without any known exploitable vulnerabilities.
Manufacturers must also establish procedures for:
– identifying and documenting vulnerabilities;
– conducting periodic security testing;
– addressing identified vulnerabilities;
– providing security updates;
– managing incidents;
– notifying users;
– documenting relevant software components and dependencies.
–
Security Updates and Support Period
An important element of the new regulation is the obligation of manufacturers to provide security support for the products they sell. Identified vulnerabilities must be remedied without undue delay, and security updates must, in principle, be provided at no additional cost to the user. The manufacturer must also establish a support period, taking into account the period for which the product is reasonably intended to be used.
As a general rule, this period must be at least five years, with the possibility of adjusting it based on the product’s normal useful life.
The user must be clearly informed of the period during which they will receive security updates and support.
Obligation to Report Vulnerabilities and Incidents
Some of the obligations under the Cyber Resilience Act are already applicable as of September 11, 2026.
Manufacturers are required to report certain actively exploited vulnerabilities and serious incidents affecting product security.
For such situations, the regulation establishes very short deadlines.
In certain cases, the initial notification must be made within 24 hours of the manufacturer becoming aware of the vulnerability or incident, followed by additional information and reports.
For companies, this obligation requires a very clear internal procedure: who identifies the incident, who analyzes it, who decides whether it must be reported, and who actually submits the notification.
In the absence of such a procedure, the risk of missing legal deadlines can be significant.
Conformity Assessment and the CE Marking
The Cyber Resilience Act integrates cybersecurity requirements into the European product conformity system.
Before placing a product on the market, the manufacturer must verify compliance with the regulation’s requirements, prepare the necessary documentation, and draw up the EU Declaration of Conformity.
Products covered by the regulation will be required to bear the CE marking, which will also confirm compliance with the relevant cybersecurity requirements.
Stricter assessment procedures are provided for certain product categories considered important or critical.
What are the risks for companies that do not comply with the regulation?
The Cyber Resilience Act provides for significant penalties. For violations of certain essential obligations, fines can reach up to 15 million euros or 2.5% of the company’s total annual global turnover, whichever is higher. In addition to financial penalties, non-compliance may also lead to measures affecting the product in question, including restrictions or withdrawal from the market.
The impact can therefore be legal and financial, as well as commercial and reputational.
The Cyber Resilience Act, NIS2, and Other European Regulations
The Cyber Resilience Act is part of a broader European framework on digital security.
In practice, a company may be subject to multiple regulations simultaneously.
NIS2 primarily concerns the security of the networks and information systems of certain entities and mandates risk management and incident reporting measures.
The Cyber Resilience Act focuses primarily on the security of hardware and software products placed on the market.
The Cybersecurity Act establishes the European framework for ENISA and cybersecurity certification.
In certain areas, other European acts may also be relevant, such as DORA for the financial sector, or the AI Act for systems based on artificial intelligence.
For this reason, an analysis of a company’s obligations must be conducted in an integrated manner, depending on its business activities, the products it offers, and its position in the supply chain.
Compliance with European cybersecurity legislation involves both technical and legal aspects.
The lawyer’s role is to identify the obligations applicable to the company and to translate legislative requirements into clear procedures, documents, and contractual mechanisms.
For companies that develop, import, or sell software and hardware products, preparation for the Cyber Resilience Act should not be postponed until 2027.
Obligations regarding the reporting of certain incidents and vulnerabilities are already in effect, and full implementation of product security requirements often involves reviewing internal processes, contracts, and compliance documentation well in advance of a product’s market launch.
A timely legal analysis can help identify specific obligations, ensure the proper allocation of responsibilities among participants in the supply chain, and mitigate the legal risks associated with the new European cybersecurity legislation.
We are available to provide further information. Please contact us by phone at 0720291919 or by email at [email protected].
