CRA: What you need to know

From December 2027, all products with digital elements must be fully compliant with the CRA. TQ supports you from regulatory assessment through to certification-ready series production.

Cyber Resilience Act (CRA) Compliance support for manufacturers

With the Cyber Resilience Act, the European Commission has, for the first time, established binding requirements to strengthen cybersecurity. The new regulation brings far-reaching changes and requires early action. TQ supports you in understanding the CRA and efficiently implementing all necessary measures.

Requirements     Services     FAQs     Contact

Key questions at a glance

What is the Cyber Resilience Act?

Blue globe icon inside a shield on a white background

 

The Cyber Resilience Act (EU Regulation 2024/2847) defines mandatory cybersecurity requirements for products with digital elements within the EU.

Which products are affected by the Cyber Resilience Act?

Blue laptop icon with interlocking circles on a white background


All products with digital elements across the entire value chain are affected. This includes, among others, mobile devices (e.g. smartphones, tablets), smart home devices (e.g. thermostats, connected door locks), networked industrial control systems (e.g. PLCs with network connectivity, IoT gateways), networking equipment (e.g. routers, managed switches), and software installed locally on electronic devices (e.g. drivers, applications).

What are products with digital elements?

According to the EU, the term “products with digital elements” includes software or hardware products and their remote data processing solutions, including individual software or hardware components that are placed on the market separately. This means the scope of the CRA is very broad and extends down to the smallest component level.

Which companies are affected by the Cyber Resilience Act?

Blue icon of a person with a magnifying glass on a white background

 

The regulation applies to manufacturers, importers, and distributors.

When do key deadlines apply?

Blue calendar icon on a white background

 

Initial reporting obligations apply from September 11, 2026. The regulation becomes fully applicable from December 11, 2027.

Reporting obligations for manufacturers

TQ provides clarity: To help you understand which reporting obligations apply, when they take effect, and what actions are required, we have summarized the key deadlines and information in a concise and easy-to-understand format. If you have any questions or need guidance, our cybersecurity experts will be happy to support you.

 

Why you should act now

In the future, products may only be placed on the EU market if they comply with the requirements of the Cyber Resilience Act. The regulation is therefore closely linked to CE marking and integrates cybersecurity requirements into the conformity assessment process.

For companies, this means: security requirements must be considered from the earliest stages of development. Otherwise, the following risks may arise:

CRA requirements explained

Implementation of cybersecurity measures

Security requirements must be considered throughout the entire product lifecycle – from development to maintenance – and appropriate measures must be implemented. 

 

Documentation and user instructions

Risks must be clearly documented, and users must be informed about safe use and potential hazards.

 

Mandatory updates

Manufacturers are required to provide security updates for at least five years and promptly address known vulnerabilities.

 

Increased requirements for critical products

Products with higher risk potential are subject to stricter testing and verification requirements, including detailed risk assessments and advanced security mechanisms.

 

TQ supports your path to CRA compliance

At TQ, we consistently follow a Security-by-Design approach. This means cybersecurity is integrated into the entire product lifecycle from the very beginning. Based on a structured Secure Development Lifecycle, we support you in efficiently implementing regulatory requirements and sustainably aligning your products with CRA compliance. 

Six Steps to CRA Compliance
TQ expert Ralf Wagner framed by a green rectangle

Your Cybersecurity expert

The Cyber Resilience Act requires fast and consistent action. Secure early support from our experienced cybersecurity team. 

Ralf Wagner
Cybersecurity Specialist (TÜV Rheinland)
Email: info@tq-group.com 
Phone: +49 8153 9308-0

Contact us now

FAQs on the Cyber Resilience Act

What is the Cyber Resilience Act?

The Cyber Resilience Act is an EU regulation that defines binding cybersecurity requirements for products with digital elements. Its goal is to ensure a consistent level of security throughout the entire product lifecycle.

Does the CRA also apply to components and embedded systems?

Yes. Individual components, embedded systems, and software elements can also fall under the CRA, especially if they perform security-relevant functions or are used in connected products.

What happens if deadlines are missed?

Companies risk delays in market access, sales bans, or fines. In addition, non-compliance may prevent CE marking, making it impossible to sell products within the EU.

Which products are considered “important products” under the CRA (Class I & II)?

The CRA distinguishes products by risk classes. “Important products” in Classes I and II are subject to stricter requirements, such as extended testing obligations, documentation requirements, and security verification – particularly in critical infrastructure or sensitive applications.

When must security incidents be reported?

Manufacturers are required to report actively exploited vulnerabilities and security incidents within defined timeframes (typically within 24 hours of becoming aware) to the relevant authorities. You can find a detailed overview of the reporting requirements that apply to manufacturers in our handy one-pager.

Download now 

Start your free consultation

It is worthwhile to assess at an early stage whether your company is affected by the Cyber Resilience Act. We are happy to support you and guide your product safely through the new regulatory requirements. We look forward to hearing from you!

captcha
38