Berlin, 19 July 2026
The Cyber Resilience Act introduces binding cybersecurity obligations for almost all connected products for the first time. An overview – and what businesses should tackle now.
With the EU Cyber Resilience Act (Regulation (EU) 2024/2847), binding horizontal cybersecurity requirements now apply to „products with digital elements" placed on the EU market. They affect manufacturers, importers and distributors of hardware and software – explicitly not only classic „IT companies". The requirements are backed by CE marking, market surveillance and substantial fines of up to EUR 15 million or 2.5 % of worldwide annual turnover.
CRA at a glance
At its core, the CRA obliges manufacturers – and in part importers and distributors – to ensure:
- Security by design and by default: essential cybersecurity requirements (Annex I) across the entire product lifecycle.
- Vulnerability handling and reporting: actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform (ENISA/CSIRT) – early warning within 24 hours, notification within 72 hours.
- Support period: provision of security updates for, as a rule, at least five years.
- Transparency and supply chain: technical documentation, a software bill of materials (SBOM) and due care regarding third-party components.
- Conformity assessment and CE marking: depending on product criticality, with an EU declaration of conformity.
- Special regime: lighter obligations, among others, for open-source software stewards.
Timeline: in force since 10 December 2024 · reporting and vulnerability obligations from 11 September 2026 · full application from 11 December 2027. Starting now means a clear head start.
Learn more
We have prepared the CRA for you:
- What Must Be Done? – a step-by-step compliance guide with direct links to each relevant provision.
- CRA FAQ – the most frequent questions, answered in practical terms.
- Regulation Text – the full wording of all articles and annexes with convenient article navigation.
Not sure whether and how the CRA affects your business? SES Berlin supports you from the initial scope check through conformity assessment to contract and supply-chain design. Get in touch.
Berlin, 19 July 2026
The Cyber Resilience Act introduces binding cybersecurity obligations for almost all connected products for the first time. An overview – and what businesses should tackle now.
With the EU Cyber Resilience Act (Regulation (EU) 2024/2847), binding horizontal cybersecurity requirements now apply to „products with digital elements" placed on the EU market. They affect manufacturers, importers and distributors of hardware and software – explicitly not only classic „IT companies". The requirements are backed by CE marking, market surveillance and substantial fines of up to EUR 15 million or 2.5 % of worldwide annual turnover.
CRA at a glance
At its core, the CRA obliges manufacturers – and in part importers and distributors – to ensure:
- Security by design and by default: essential cybersecurity requirements (Annex I) across the entire product lifecycle.
- Vulnerability handling and reporting: actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform (ENISA/CSIRT) – early warning within 24 hours, notification within 72 hours.
- Support period: provision of security updates for, as a rule, at least five years.
- Transparency and supply chain: technical documentation, a software bill of materials (SBOM) and due care regarding third-party components.
- Conformity assessment and CE marking: depending on product criticality, with an EU declaration of conformity.
- Special regime: lighter obligations, among others, for open-source software stewards.
Timeline: in force since 10 December 2024 · reporting and vulnerability obligations from 11 September 2026 · full application from 11 December 2027. Starting now means a clear head start.
Learn more
We have prepared the CRA for you:
- What Must Be Done? – a step-by-step compliance guide with direct links to each relevant provision.
- CRA FAQ – the most frequent questions, answered in practical terms.
- Regulation Text – the full wording of all articles and annexes with convenient article navigation.
Not sure whether and how the CRA affects your business? SES Berlin supports you from the initial scope check through conformity assessment to contract and supply-chain design. Get in touch.