Prof. Sven Kolja

Braune

Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), entered into force on 10 December 2024. It will apply in full from 11 December 2027. However, the reporting obligations of manufacturers under Art. 14 CRA already apply from 11 September 2026. The CRA establishes a uniform legal framework for the cybersecurity of products with digital elements (PDE) within the internal market of the European Union. It sets out requirements for the products and for the manufacturers' procedures for handling vulnerabilities.

 

1. Which products are covered by the CRA?

 

1.1 Material scope and basic concepts

Pursuant to Art. 2(1) CRA, the CRA applies to all products with digital elements (PDE) made available on the EU market. Under Art. 3 No. 1 CRA, PDEs are defined as software or hardware products including their remote data processing solutions, which can be directly or indirectly connected to a device or network. Accordingly, the CRA applies both to connected hardware products (e.g. smartphones, laptops, smart home products, smartwatches, connected toys, but also microprocessors, firewalls, and smart meter gateways in intelligent metering systems) and to pure software products (e.g. accounting software, computer games, mobile apps). The decisive factor is that the intended purpose or reasonably foreseeable use of the product includes a direct or indirect logical or physical data connection to a device or network.

The scope is broad. It can cover simple household appliances, standard software, and complex industrial system components. It is irrelevant whether the product is supplied to consumers (B2C) or to businesses (B2B). The size of the manufacturer's company is also generally not relevant. What matters is the making available on the Union market in the course of a commercial activity (Art. 3 No. 22 CRA). Therefore, pure free and open-source software that is not made available on the Union market in the course of a commercial activity generally does not fall under the CRA. The decisive factor for the initial making available is the placing on the market, i.e. the first making available of a PDE on the Union market (Art. 3 No. 21 CRA). From 11 December 2027, every single instance of a product model placed on the market must meet the requirements of the CRA.

 

1.2 Exclusions from the scope

Pursuant to Art. 2(2) to (7) CRA, certain products are excluded from the scope:

–    Medical devices and in vitro diagnostic medical devices: Products falling under Regulation (EU) 2017/745 (medical devices) or Regulation (EU) 2017/746 (in vitro diagnostic medical devices) are excluded (Art. 2(2)(a) and (b) CRA).

–    Motor vehicles: Products falling under Regulation (EU) 2019/2144 (type-approval of motor vehicles) are excluded (Art. 2(2)(c) CRA).

–    Aviation products: Products certified under Regulation (EU) 2018/1139 are excluded (Art. 2(3) CRA).

–    Marine equipment: Equipment falling within the scope of Directive 2014/90/EU on marine equipment is excluded (Art. 2(4) CRA).

–    Spare parts: Spare parts made available on the market to replace identical components in PDEs and manufactured according to the same specifications are excluded (Art. 2(6) CRA).

–    National security and defense: Products developed or modified exclusively for national security or defense purposes, as well as products specifically designed for processing classified information, are excluded (Art. 2(7) CRA).

–    Other sector-specific legislation: Pursuant to Art. 2(5) CRA, the application of the CRA may be restricted or excluded by a delegated act of the Commission if sector-specific rules ensure the same or a higher level of protection.

 

1.3 Product categories according to cybersecurity risk

For conformity assessment, the CRA distinguishes between other, important, and critical PDEs. The frequently used term "basic category" is not in the text of the Regulation, but is adopted here as a catch-all term. The core function of the product is decisive for classification as an important or critical PDE:

a) Other PDEs (basic category)

This includes all covered PDEs that do not have a core function of a category listed in Annex III or IV CRA. The general requirements of the CRA apply to them. They may regularly be assessed according to the internal control procedure (Module A).

b) Important products with digital elements of Class I (Annex III CRA)

Pursuant to Art. 7(1) CRA, PDEs are considered important if they have the core function of a product category listed in Annex III CRA. The categories listed in Annex III are already assigned to Classes I and II there. Overall, they meet at least one of the criteria mentioned in Art. 7(2) CRA: The product primarily performs functions that are critical to the cybersecurity of other products, networks, or services, or it performs a function that carries a significant risk of adverse effects. According to Annex III, Class I includes, for example, browsers, password managers, operating systems, routers, and certain internet-connected toys.

c) Important products with digital elements of Class II (Annex III CRA)

Class II is also defined in Annex III. Art. 7(2) CRA does not assign the two criteria to a specific class. The concrete assignment follows solely from Annex III. Class II includes hypervisors and container runtime systems, firewalls, intrusion detection systems, intrusion prevention systems, and tamper-resistant microprocessors and microcontrollers. A notified body must always be involved for these products (Art. 32(3) CRA).

Important: The integration of an important PDE into another product does not, pursuant to Art. 7(1) second sentence CRA, result in the receiving product itself being subject to the stricter conformity assessment procedures for important PDEs.

d) Critical products with digital elements (Annex IV CRA)

Critical PDEs are listed in Annex IV CRA. Pursuant to Art. 8(2) CRA, they meet at least one of the following criteria: There is a critical dependency of essential entities within the meaning of the NIS 2 Directive (Directive 2022/2555) on the respective product category, or security incidents and exploited vulnerabilities could lead to major disruptions to critical supply chains across the internal market. Examples from Annex IV CRA are hardware devices with secure enclaves, smart meter gateways, and smart cards or similar devices. Pursuant to Art. 8(1) CRA, the EU Commission is empowered to determine, by means of a delegated act, which critical PDEs must mandatorily obtain a European cybersecurity certificate (at least assurance level "substantial").

The Commission specified the technical descriptions of the categories in Annex III and IV with Implementing Regulation (EU) 2025/2392 of 28 November 2025.

 

2. What security requirements does the CRA place on PDEs?

Art. 6 CRA refers to the essential cybersecurity requirements in Annex I CRA. These apply to all covered PDEs. The CRA follows a risk-based approach: Not every PDE has to meet all requirements flat-rate. What matters are always the intended purpose (Art. 3 No. 23 CRA), the reasonably foreseeable use (Art. 3 No. 24 CRA), and the practical operating environment of the respective product (Art. 13(2) and (3) CRA). Annex I CRA divides the requirements into two parts:

 

Annex I Part I – Product properties

Manufacturers must ensure that their PDE is designed, developed, and manufactured in such a way that it "ensures an appropriate level of cybersecurity in light of the risks" (Annex I Part I paragraph 1 CRA). Product properties include, among others:

–    Delivery without known exploitable vulnerabilities and with a secure default configuration,

–    Protection against unauthorized access as well as protection of the confidentiality, integrity, and availability of data and essential functions,

–    Limitation of processing to necessary data and reduction of the attack surface,

–    Possibility to address vulnerabilities through security updates, as well as secure deletion of data and settings.

 

Annex I Part II – Vulnerability handling

The obligations of manufacturers do not end with placing on the market. They must also carry out active vulnerability handling after placing on the market for a product-specific support period (Art. 3 No. 20, Art. 13(8) CRA). The support period is generally at least five years. If the expected lifetime of the product is shorter, it must correspond to that lifetime (Art. 13(8) CRA). This includes in particular:

–    Identifying and addressing vulnerabilities in PDEs,

–    Regular security testing, a policy on coordinated vulnerability disclosure, and secure and generally free dissemination of security updates,

–    Reporting actively exploited vulnerabilities (Art. 3 No. 42 CRA) and severe security incidents affecting the security of the PDE according to Art. 14 CRA (reporting obligation from 11 September 2026).

 

3. How is conformity assessment carried out under the CRA?

 

Conformity assessment is regulated in Art. 32 and Annex VIII CRA and is generally carried out by the manufacturer. Conformity assessment is a prerequisite for CE marking and placing the PDE on the market in the EU. Which procedure the manufacturer may choose depends on the product category.

Other PDEs (basic category)

For other PDEs, the conformity assessment procedures mentioned in Art. 32(1) CRA are open. In particular, manufacturers can choose the internal control procedure based on Module A (Annex VIII CRA). In doing so, they declare on their own responsibility that their PDE meets the essential cybersecurity requirements in Annex I CRA. Involvement of a notified body is not required, but is possible on a voluntary basis.

Important PDEs of Class I (Annex III CRA)

For important PDEs of Class I, Module A is only permissible if the manufacturer fully applies relevant harmonized standards, common specifications, or a relevant European cybersecurity certification scheme (Art. 32(2) CRA). Otherwise, they must use Module B in combination with Module C, Module H, or an applicable European cybersecurity certification scheme. A third party must always be involved in this process.

Important PDEs of Class II and critical PDEs (Annex III and IV CRA)

For these categories, an assessment by a notified body is mandatory. Manufacturers can choose between three procedures:

–    EU-type examination (Module B) in combination with conformity to type based on internal production control (Module C, Annex VIII CRA): A notified body examines the technical design and issues an EU-type examination certificate. The manufacturer then ensures that the manufactured PDEs conform to the approved type.

–    Conformity based on full quality assurance (Module H, Annex VIII CRA): The manufacturer implements and operates a quality management system. A notified body assesses this on-site and conducts regular audits. The quality system and its application are monitored by the notified body.

–    European cybersecurity certification scheme (Art. 27(9) CRA in conjunction with EU Regulation 2019/881): Insofar as a European cybersecurity certification scheme applicable under Art. 27(9) CRA is available, a corresponding certificate can serve as proof. For critical PDEs, the Commission may prescribe a certificate of at least assurance level "substantial". Pursuant to Art. 8(1) CRA, the EU Commission is empowered to establish an obligation for certain critical PDEs by means of a delegated act.

 

4. What is the significance of harmonized European standards for the CRA?

A key tool for meeting the requirements of the CRA are harmonized European standards (hEN). While standards are generally voluntary guidelines that define how products, services, and business processes should work, hEN are a special category of European standards developed by European standardization organizations at the request of the European Commission. While the technical requirements laid down in EU law are always mandatory, the application of harmonized standards is usually voluntary. However, compliance with relevant hEN by manufacturers regularly creates a presumption of conformity that their products comply with EU law. Alternatively, other technical solutions can be used, provided they are equally legally compliant. PDEs that comply with such hEN therefore enjoy a presumption of conformity under Art. 27 CRA: They are assumed to meet the essential cybersecurity requirements of the CRA.

The formal basis for standardization work in the field of the CRA is the standardization mandate M/606, with which the EU Commission tasked the European standardization organizations CEN, CENELEC, and ETSI in spring 2025. The standards are divided into three types:

–    Type A: Fundamental framework standard for the risk-based design, development, and manufacture of PDEs.

–    Type B: Horizontal, product-agnostic standards on product properties (Annex I Part I CRA) and vulnerability handling (Annex I Part II CRA).

–    Type C: Vertical, product-specific standards for important and critical PDEs (Annex III and IV CRA).

 

The CRA Dashboard provided by the BSI illustrates the progress of standardization at the time of publication.

CRA Standardization Dashboard

 

The timely availability of hEN is particularly important for manufacturers of Class I important PDEs. This is because the internal conformity assessment under Module A is only permissible if relevant hEN, common specifications, or applicable European cybersecurity certification schemes are fully applied (Art. 32(2) CRA). If hEN are missing, cost- and resource-intensive third-party assessments and, of course, delays in placing the PDEs on the market are imminent.

Direct advice, fast responses, clear responsibility

Based in Frankfurt am Main and Darmstadt, we work with startups, tech companies, consumer brands, media organisations, and Mittelstand businesses driving the German economy – maybe yours.

NOTOS Frankfurt am Main

Senckenberganlage 10-12
D-60325 Frankfurt am Main
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

NOTOS Darmstadt

Heidelberger Straße 6
D-64283 Darmstadt
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

English

Direct advice, fast responses, clear responsibility

Based in Frankfurt am Main and Darmstadt, we work with startups, tech companies, consumer brands, media organisations, and Mittelstand businesses driving the German economy – maybe yours.

NOTOS Frankfurt am Main

Senckenberganlage 10-12
D-60325 Frankfurt am Main
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

NOTOS Darmstadt

Heidelberger Straße 6
D-64283 Darmstadt
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

English

Direct advice, fast responses, clear responsibility

Based in Frankfurt am Main and Darmstadt, we work with startups, tech companies, consumer brands, media organisations, and Mittelstand businesses driving the German economy – maybe yours.

NOTOS Frankfurt am Main

Senckenberganlage 10-12
D-60325 Frankfurt am Main
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

NOTOS Darmstadt

Heidelberger Straße 6
D-64283 Darmstadt
Phone: +49 69 6677804-0
Fax: +49 69 6677804-99

English