Loading…
Loading…
The Cyber Resilience Act establishes the first horizontal EU statutory cybersecurity regime for "products with digital elements" (PDEs), defined as any software or hardware product — and its remote data-processing solutions — whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Scope is deliberately horizontal: IoT devices, industrial control systems, consumer electronics, operating systems, libraries, embedded firmware, and separately-marketed components are all in.
The regulation operates through four instruments:
1. Essential cybersecurity requirements (Annex I) — manufacturers must design, develop, and produce PDEs to meet the Annex I essential requirements during the entire defined "support period," which must be communicated to purchasers at the point of sale. 2. Conformity assessment + CE marking — manufacturers choose between Module A self-assessment, Module B-C / H third-party assessment via notified bodies, or approved European cybersecurity certification schemes. "Important" and "critical" PDE categories face restricted options. Successful assessment yields an EU declaration of conformity and the cyber CE mark. 3. Mandatory vulnerability handling and notification — manufacturers must notify the relevant Member State CSIRT and ENISA within 24 hours (early warning) and 72 hours (main notification) of actively-exploited vulnerabilities or severe incidents, with final reports at 14 days (vulnerabilities) or one month (severe incidents). Free security updates are required throughout the support period. 4. Market surveillance and penalties — Member State market-surveillance authorities can require corrective action, recall, or withdrawal. Administrative fines reach EUR 15 million or 2.5% of worldwide annual turnover (whichever higher) for essential-requirements infringements.
The regime applies extraterritorially: any non-EU OEM, software publisher, or open-source steward whose products are placed on the EU market is in scope (with carve-outs limiting fines for microenterprises and open-source stewards).
publication on 20 November 2024).
assessment bodies) becomes applicable, allowing the EU notified-body ecosystem to stand up.
(vulnerability and severe-incident notifications to CSIRTs and ENISA) begin to apply.
full: essential cybersecurity requirements, technical documentation, EU declaration of conformity, CE marking. The Article 14 reporting obligations cover all PDEs already on the Union market, including those placed before 11 December 2027; the design / CE-marking obligations apply only to PDEs placed on the market from 11 December 2027 onward.
extraterritorial reach — non-EU OEMs (US, Chinese, Korean, Japanese hardware vendors and software publishers) must redesign product lifecycles, vulnerability disclosure, and update programmes for EU-market access by Dec 2027. Compliance cost is the new floor on EU-market entry for connected products.
second leg of the EU horizontal-digital-regulation stack: AI Act governs AI systems, CRA governs every other product with digital elements. Together they form the EU's "Brussels effect" cybersecurity / AI regulatory perimeter.
reduced fine exposure but must still meet essential requirements when commercialised; redefines the responsibilities of upstream maintainers vs. downstream commercial integrators.
industry and for cybersecurity-services incumbents (TÜV Rheinland, DEKRA, Bureau Veritas, SGS, NCC Group) and cyber-product vendors with established EU compliance footprints.
(smart-home, wearables), industrial-automation OEMs (PLC, SCADA), and embedded-firmware vendors. Banking, medical-device, and motor-vehicle products with sectoral cybersecurity regimes have partial carve-outs.
enforcement across borders for products sold pan-EU?
Cybersecurity Act, Reg 2019/881) be used as the primary conformity-assessment route for "important" / "critical" PDEs, or will Module B-C notified-body assessment dominate in practice?
vendors whose products fall under the PDE definition via "remote data-processing solutions"?
early-warning notifications, especially in critical-vulnerability events affecting widely-deployed open-source components?