← Back

KNOWLEDGE HUB

The EU Cyber Resilience Act (CRA)

The first EU-wide horizontal law requiring security-by-design in products with digital elements — with a key deadline just around the corner: September 11, 2026.

What it is

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal EU regulation imposing mandatory cybersecurity requirements on 'products with digital elements' — essentially any hardware or software that connects to a network, from an industrial PLC to a commercially distributed open-source library.

It entered into force on December 10, 2024. Where the product is manufactured doesn't matter — what triggers the obligation is placing it on the EU market, regardless of where the manufacturer is headquartered.

Why it matters (and why now)

Unlike 62443 (voluntary) or CIP (sector-specific), the CRA is directly applicable law across all 27 EU member states, with real fines. And there's a date that anyone manufacturing or integrating industrial products destined for the EU should have circled: September 11, 2026, when obligations to report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT take effect — with a 24-hour early warning, a 72-hour triage report, and a 14-day final report.

For the OT/ICS world this is directly relevant: a PLC, an HMI, or an industrial switch sold in the EU is, unambiguously, a 'product with digital elements'.

How it's structured

  • Obligations across the whole lifecycle: security by design, continuous vulnerability management, and a declared support period (with a minimum of 10 years of documentation).
  • Incident reporting (Article 14): actively exploited vulnerabilities and severe incidents, reported to ENISA via its single reporting platform — applies from September 11, 2026, even to products already on the market.
  • Conformity assessment and CE marking: higher-criticality products require assessment by a notified body before sale.
  • Full application: December 11, 2027 — the deadline for completed conformity assessments, EU declaration of conformity, and full technical documentation.

Best practices

  • Don't wait for 2027: the vulnerability reporting obligation already applies from September 2026, even for existing ('legacy') products, unless withdrawn from the market before that date.
  • Build on what you already know from 62443 — the CRA's harmonised standards (expected Q3 2026, via CEN/CENELEC/ETSI) are expected to lean heavily on IEC 62443-4-1 and 4-2 for the presumption of conformity. If you already work with 62443, you're not starting from zero.
  • Start the vulnerability-monitoring process and an SBOM-style inventory now — it's the foundation for both 2026's incident reporting and 2027's full compliance.

Common mistakes

  • Assuming the CRA 'doesn't apply to me' because the company isn't EU-based — what matters is selling into the EU, not where the factory is.
  • Treating 2027 as the only relevant date and ignoring that incident reporting is already mandatory from 2026.
  • Assuming a product already on the market is permanently exempt — a substantial modification after December 2027 can re-trigger the conformity obligation.

References

  • Regulation (EU) 2024/2847 — Cyber Resilience Act
  • European Commission — Cyber Resilience Act (digital-strategy.ec.europa.eu)
  • ENISA — Single Reporting Platform (Art. 16 CRA)