KNOWLEDGE HUB
The EU Cyber Resilience Act (CRA)
The first EU-wide horizontal law requiring security-by-design in products with digital elements — with a key deadline just around the corner: September 11, 2026.
What it is
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal EU regulation imposing mandatory cybersecurity requirements on 'products with digital elements' — essentially any hardware or software that connects to a network, from an industrial PLC to a commercially distributed open-source library.
It entered into force on December 10, 2024. Where the product is manufactured doesn't matter — what triggers the obligation is placing it on the EU market, regardless of where the manufacturer is headquartered.
Why it matters (and why now)
Unlike 62443 (voluntary) or CIP (sector-specific), the CRA is directly applicable law across all 27 EU member states, with real fines. And there's a date that anyone manufacturing or integrating industrial products destined for the EU should have circled: September 11, 2026, when obligations to report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT take effect — with a 24-hour early warning, a 72-hour triage report, and a 14-day final report.
For the OT/ICS world this is directly relevant: a PLC, an HMI, or an industrial switch sold in the EU is, unambiguously, a 'product with digital elements'.
How it's structured
- Obligations across the whole lifecycle: security by design, continuous vulnerability management, and a declared support period (with a minimum of 10 years of documentation).
- Incident reporting (Article 14): actively exploited vulnerabilities and severe incidents, reported to ENISA via its single reporting platform — applies from September 11, 2026, even to products already on the market.
- Conformity assessment and CE marking: higher-criticality products require assessment by a notified body before sale.
- Full application: December 11, 2027 — the deadline for completed conformity assessments, EU declaration of conformity, and full technical documentation.
Best practices
- Don't wait for 2027: the vulnerability reporting obligation already applies from September 2026, even for existing ('legacy') products, unless withdrawn from the market before that date.
- Build on what you already know from 62443 — the CRA's harmonised standards (expected Q3 2026, via CEN/CENELEC/ETSI) are expected to lean heavily on IEC 62443-4-1 and 4-2 for the presumption of conformity. If you already work with 62443, you're not starting from zero.
- Start the vulnerability-monitoring process and an SBOM-style inventory now — it's the foundation for both 2026's incident reporting and 2027's full compliance.
Common mistakes
- Assuming the CRA 'doesn't apply to me' because the company isn't EU-based — what matters is selling into the EU, not where the factory is.
- Treating 2027 as the only relevant date and ignoring that incident reporting is already mandatory from 2026.
- Assuming a product already on the market is permanently exempt — a substantial modification after December 2027 can re-trigger the conformity obligation.
References
- Regulation (EU) 2024/2847 — Cyber Resilience Act
- European Commission — Cyber Resilience Act (digital-strategy.ec.europa.eu)
- ENISA — Single Reporting Platform (Art. 16 CRA)