No CE marking
The sale of non-compliant products in the EU may be restricted or even prohibited by authorities.
From December 2027, all products with digital elements must be fully compliant with the CRA. TQ supports you from regulatory assessment through to certification-ready series production.
With the Cyber Resilience Act, the European Commission has, for the first time, established binding requirements to strengthen cybersecurity. The new regulation brings far-reaching changes and requires early action. TQ supports you in understanding the CRA and efficiently implementing all necessary measures.

The Cyber Resilience Act (EU Regulation 2024/2847) defines mandatory cybersecurity requirements for products with digital elements within the EU.

All products with digital elements across the entire value chain are affected. This includes, among others, mobile devices (e.g. smartphones, tablets), smart home devices (e.g. thermostats, connected door locks), networked industrial control systems (e.g. PLCs with network connectivity, IoT gateways), networking equipment (e.g. routers, managed switches), and software installed locally on electronic devices (e.g. drivers, applications).
According to the EU, the term “products with digital elements” includes software or hardware products and their remote data processing solutions, including individual software or hardware components that are placed on the market separately. This means the scope of the CRA is very broad and extends down to the smallest component level.

The regulation applies to manufacturers, importers, and distributors.

Initial reporting obligations apply from September 11, 2026. The regulation becomes fully applicable from December 11, 2027.
Why you should act now
In the future, products may only be placed on the EU market if they comply with the requirements of the Cyber Resilience Act. The regulation is therefore closely linked to CE marking and integrates cybersecurity requirements into the conformity assessment process.
For companies, this means: security requirements must be considered from the earliest stages of development. Otherwise, the following risks may arise:
Implementation of cybersecurity measures
Security requirements must be considered throughout the entire product lifecycle – from development to maintenance – and appropriate measures must be implemented.
Documentation and user instructions
Risks must be clearly documented, and users must be informed about safe use and potential hazards.
Mandatory updates
Manufacturers are required to provide security updates for at least five years and promptly address known vulnerabilities.
Increased requirements for critical products
Products with higher risk potential are subject to stricter testing and verification requirements, including detailed risk assessments and advanced security mechanisms.
At TQ, we consistently follow a Security-by-Design approach. This means cybersecurity is integrated into the entire product lifecycle from the very beginning. Based on a structured Secure Development Lifecycle, we support you in efficiently implementing regulatory requirements and sustainably aligning your products with CRA compliance.


Your Cybersecurity expert
The Cyber Resilience Act requires fast and consistent action. Secure early support from our experienced cybersecurity team.
Ralf Wagner
Cybersecurity Specialist (TÜV Rheinland)
Email: info@tq-group.com
Phone: +49 8153 9308-0
The Cyber Resilience Act is an EU regulation that defines binding cybersecurity requirements for products with digital elements. Its goal is to ensure a consistent level of security throughout the entire product lifecycle.
Yes. Individual components, embedded systems, and software elements can also fall under the CRA, especially if they perform security-relevant functions or are used in connected products.
Companies risk delays in market access, sales bans, or fines. In addition, non-compliance may prevent CE marking, making it impossible to sell products within the EU.
The CRA distinguishes products by risk classes. “Important products” in Classes I and II are subject to stricter requirements, such as extended testing obligations, documentation requirements, and security verification – particularly in critical infrastructure or sensitive applications.
Manufacturers are required to report actively exploited vulnerabilities and security incidents within defined timeframes (typically within 24 hours of becoming aware) to the relevant authorities. You can find a detailed overview of the reporting requirements that apply to manufacturers in our handy one-pager.