The EU Cyber Resilience Act (CRA): A Practical Guide for Manufacturers

The Cyber Resilience Act (CRA) represents one of the most significant changes to European product legislation in recent years. While manufacturers have long been required to demonstrate compliance with regulations covering electrical safety, electromagnetic compatibility (EMC) and radio performance, cybersecurity is now becoming an equally important compliance requirement.

The CRA establishes mandatory cybersecurity requirements for products with digital elements placed on the European market. Unlike previous legislation, it does not only address product design before market placement, but also introduces obligations that continue throughout the product’s supported lifetime, including vulnerability handling and security updates.

For many manufacturers, this marks a fundamental shift. Cybersecurity is no longer solely an IT or software development topic—it becomes part of product compliance and should be considered alongside RF, EMC and Safety from the earliest stages of product development.

This article explains:

  • Which products fall within the scope of the CRA
  • Which products are generally excluded
  • The implementation timeline
  • The different CRA product categories
  • How conformity assessment works
  • The role of Notified Bodies and testing laboratories
  • Harmonised standards
  • Incident reporting obligations
  • Penalties for non-compliance
  • How the CRA interacts with other European product legislation

For the official legal text, see:

What is the Cyber Resilience Act?

The Cyber Resilience Act introduces mandatory cybersecurity requirements for Products with Digital Elements (PDEs).

According to the Regulation, a Product with Digital Elements is generally any hardware or software product whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to another device or network.

This definition is intentionally broad.

Many manufacturers initially assume the CRA only applies to computers or networking equipment. In reality, the regulation covers a wide range of industrial and consumer products.

Examples include:

  • Routers
  • Network switches
  • Wireless access points
  • Industrial gateways
  • PLCs
  • Variable Frequency Drives (VFDs)
  • Building automation controllers
  • Smart sensors
  • Consumer IoT products
  • Smart home devices
  • Connected household appliances
  • Industrial HMIs
  • EV chargers
  • Smart lighting systems
  • Connected laboratory equipment
  • Embedded software
  • Mobile applications
  • Stand-alone software products

The decisive factor is not whether the product is electrical, electronic or electromechanical.

Instead, the key question is:

Does the product contain digital elements that communicate with another device or network?

If the answer is yes, the CRA should be considered.

Traditional Products Can Also Be Covered

A common misconception is that traditional electromechanical equipment falls outside the scope of the CRA.

That is not necessarily true.

For example, consider a motor controller.

A conventional motor controller without any digital communication capabilities may fall outside the scope of the CRA.

However, if the same controller includes:

  • Ethernet
  • Wi-Fi
  • Bluetooth
  • Cellular communication
  • USB communication
  • CAN bus
  • RS-485
  • Modbus TCP
  • PROFINET
  • EtherCAT
  • IO-Link

or similar digital communication functionality, it may become a Product with Digital Elements, meaning the CRA could apply.

The same principle applies to many industrial products that historically were not considered cybersecurity products.

Examples include:

  • Industrial sensors
  • Temperature controllers
  • HVAC controllers
  • Smart meters
  • Lighting controllers
  • Battery management systems
  • Building automation devices
  • Industrial robots
  • Test and measurement equipment

Cybersecurity legislation is therefore no longer limited to traditional IT products.

Which Products Are Generally Excluded?

The CRA does not apply to every connected product.

Some products are already covered by sector-specific European legislation that contains its own cybersecurity requirements.

Examples include certain:

  • Medical Devices
  • In Vitro Diagnostic Medical Devices (IVDs)
  • Civil Aviation products
  • Motor Vehicles
  • Marine equipment

Manufacturers should therefore always determine whether sector-specific legislation already governs the cybersecurity aspects of their products before concluding that the CRA applies.

The European Commission provides additional guidance here:
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

Implementation Timeline

Although the CRA entered into force in 2024, manufacturers still have time to prepare.

However, this time should not be underestimated.

Several important milestones apply.

DateMilestone
10 December 2024Cyber Resilience Act entered into force
11 June 2026Rules concerning designation and notification of Notified Bodies apply
11 September 2026Vulnerability reporting obligations become applicable
11 December 2027Full application of the CRA

The period until December 2027 is intended to give manufacturers sufficient time to adapt products, documentation and internal processes.

For organisations developing connected products today, waiting until 2027 is unlikely to be sufficient.

Cybersecurity considerations should already be integrated into new product developments.

Official implementation timeline:
https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation

Product Categories

The CRA divides products into four different categories.

One important point is frequently misunderstood.

The classification does not depend on the individual components used inside the product.

Instead, it depends on the functionality provided by the product.

A product containing an identical processor or wireless module may fall into different categories depending entirely on what the final product actually does.

Default Category

Most connected products fall into the Default Category.

Typical examples include:

  • Smart lighting
  • Connected household appliances
  • Environmental sensors
  • Consumer IoT products
  • Building automation devices
  • Connected industrial equipment
  • Smart energy devices
  • Consumer electronics

These products generally follow the Internal Production Control conformity assessment procedure.

What does this mean?

The manufacturer performs the conformity assessment itself.

No Notified Body is required.

Likewise, there is no mandatory requirement to involve an external testing laboratory.

The manufacturer is responsible for:

  • preparing the Technical Documentation,
  • demonstrating compliance with the Essential Cybersecurity Requirements,
  • issuing the EU Declaration of Conformity,
  • affixing the CE marking.

This does not necessarily mean the assessment is simple.

Manufacturers must still be able to demonstrate compliance if requested by market surveillance authorities.

Important Class I

Important Class I products provide cybersecurity-relevant functionality.

Examples listed by the CRA include products such as:

  • Password managers
  • VPN products
  • Identity management systems
  • Secure communication software
  • Smart home security controllers

These products represent a higher cybersecurity risk than products within the Default Category.

Consequently, the conformity assessment requirements become more stringent.

Conformity Assessment

Unlike Default Category products, Important Class I products generally require the involvement of a Notified Body.

In practice, manufacturers will usually work with a testing laboratory or certification organisation that acts as, or includes, the required Notified Body.

Depending on the product and conformity assessment procedure, the assessment may include:

  • review of technical documentation,
  • cybersecurity evaluations,
  • assessment of the manufacturer’s secure development processes,
  • architecture reviews,
  • demonstrations,
  • laboratory testing where appropriate.

An important point should be noted.

The CRA foresees that once suitable harmonised European standards become available and are fully applied, certain Important Class I products may again become eligible for Internal Production Control, allowing manufacturers to demonstrate conformity without involving a Notified Body.

This is expected to become increasingly important as harmonised CRA standards are published over the coming years.

Important Class II

Important Class II products provide cybersecurity functionality that is considered more critical than products in the Default or Important Class I categories.

Typical examples listed in the CRA include:

  • Routers
  • Network switches
  • Firewalls
  • Intrusion Detection Systems (IDS)
  • Intrusion Prevention Systems (IPS)
  • Hypervisors

These products often form part of the infrastructure responsible for protecting networks or controlling communications between systems. As a result, failures or vulnerabilities can have a much greater impact than those associated with general connected products.

Conformity Assessment

Unlike products in the Default Category, manufacturer self-assessment is not permitted.

Instead, manufacturers must involve a Notified Body as part of the conformity assessment procedure.

In practice, manufacturers will typically work with a testing laboratory or certification organisation that acts as, or includes, the required Notified Body.

Depending on the product, the assessment may include:

  • Review of the technical documentation
  • Evaluation of the implemented cybersecurity measures
  • Assessment of secure development processes
  • Review of vulnerability handling procedures
  • Cybersecurity testing where appropriate
  • Additional laboratory testing where considered necessary

Compared with Important Class I products, the assessment is generally more comprehensive due to the higher cybersecurity relevance of these products.

Critical Products

The CRA defines a separate category for products considered to present the highest cybersecurity risk.

Typical examples include:

  • Hardware Security Modules (HSM)
  • Smart Meter Gateways
  • Smart Cards
  • Secure Elements
  • Qualified Signature Creation Devices

These products often form the foundation of trust within digital infrastructures. A successful attack on one of these products could affect many other connected systems.

EU Type Examination

Critical Products require an EU Type Examination.

This represents the highest conformity assessment procedure under the CRA.

Unlike Important Class I and II products, where the Notified Body primarily evaluates the manufacturer’s demonstration of compliance, an EU Type Examination focuses on the product type itself.

The Notified Body independently examines:

  • Product architecture
  • Hardware design
  • Software implementation
  • Technical documentation
  • Implemented cybersecurity measures
  • Security concepts
  • Supporting technical evidence

Where appropriate, additional laboratory testing may also be requested.

If the product successfully satisfies the applicable requirements, the Notified Body issues an EU Type Examination Certificate.

Only after this examination has been completed can the manufacturer continue with the applicable conformity assessment route and CE marking.

Harmonised Standards

One of the most common questions manufacturers ask today is:

“Which harmonised standards should we apply?”

The simple answer is:

Most of them do not yet exist.

The European Commission has issued a standardisation request to the European Standardisation Organisations to develop harmonised standards supporting the CRA.

Official information:
https://digital-strategy.ec.europa.eu/en/policies/cra-standardisation

Once these standards are cited in the Official Journal of the European Union (OJEU), manufacturers applying them will benefit from a presumption of conformity with the corresponding Essential Cybersecurity Requirements.

It is important to understand what this means.

Applying harmonised standards is generally voluntary.

Manufacturers remain free to use other technical solutions.

However, if harmonised standards are not used, the manufacturer must demonstrate—and be able to justify—that the chosen solution satisfies the Essential Requirements of the CRA.

For certain Important Class I products, harmonised standards may also allow manufacturers to perform Internal Production Control, eliminating the need for a Notified Body.

Essential Cybersecurity Requirements

Unlike EMC or Radio legislation, the CRA does not prescribe individual tests.

Instead, it defines Essential Cybersecurity Requirements that manufacturers must satisfy.

These requirements cover topics such as:

  • Secure-by-design principles
  • Appropriate cybersecurity risk management
  • Protection against unauthorised access
  • Secure default configurations
  • Protection of confidentiality and integrity
  • Secure authentication mechanisms
  • Logging where appropriate
  • Vulnerability management
  • Security updates
  • Protection of stored and transmitted data

The exact implementation depends on the product, its intended use and the identified cybersecurity risks.

Does the CRA Require Laboratory Testing?

This is an important distinction.

The CRA requires compliance to be demonstrated—not a predefined programme of laboratory tests.

However, where the involvement of a Notified Body is required, manufacturers will typically work with a testing laboratory or certification organisation that acts as, or includes, a Notified Body.

Depending on the product and conformity assessment procedure, the assessment may involve:

  • Documentation reviews
  • Cybersecurity evaluations
  • Architecture assessments
  • Software reviews
  • Penetration testing
  • Laboratory testing
  • Or a combination of these activities

Unlike EMC or RF compliance, there is no universal test programme that applies to every product.

The appropriate evidence depends on the product, the identified cybersecurity risks and the applicable conformity assessment procedure.

Vulnerability Reporting

The CRA introduces completely new obligations after products have been placed on the market.

Manufacturers must establish processes to:

  • Monitor vulnerabilities
  • Assess reported vulnerabilities
  • Provide security updates where appropriate
  • Cooperate with authorities

Beginning 11 September 2026, actively exploited vulnerabilities and severe incidents become subject to mandatory reporting requirements.

Manufacturers must submit reports through ENISA’s Single Reporting Platform.

Further information:
https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation

Reporting Deadlines

The reporting timelines are intentionally short.

Manufacturers should therefore establish internal incident handling procedures well before these obligations become applicable.

Typical reporting deadlines include:

  • Within 24 hours – Early warning following awareness of an actively exploited vulnerability or severe incident.
  • Within 72 hours – More detailed notification containing available technical information.
  • Within 14 days – Information on available mitigation measures or corrective actions where applicable.
  • Within one month – Final report summarising the incident, root cause and corrective actions.

Because these reporting obligations continue throughout the supported lifetime of a product, manufacturers should already consider post-market cybersecurity processes during product development.

Penalties for Non-Compliance

The CRA provides market surveillance authorities with significant enforcement powers.

Where products fail to comply, authorities may:

  • Prohibit products from being placed on the market
  • Require corrective actions
  • Suspend market availability
  • Order product withdrawals
  • Require product recalls
  • Publish enforcement decisions

In addition, Member States must establish effective, proportionate and dissuasive penalties.

The Regulation allows administrative fines of up to:

  • €15 million or 2.5% of the manufacturer’s total worldwide annual turnover, whichever is higher, for certain serious infringements.
  • €10 million or 2% of worldwide annual turnover for other specified infringements.
  • €5 million or 1% of worldwide annual turnover for supplying incorrect, incomplete or misleading information to authorities.

The applicable penalty depends on the nature of the infringement and the relevant provisions of the Regulation.

Relationship with Other European Product Legislation

The CRA does not replace existing European product legislation.

Instead, manufacturers often need to comply with multiple regulations simultaneously.

For example, a connected wireless product may need to satisfy:

  • Cyber Resilience Act (CRA)
  • Radio Equipment Directive (RED)
  • EMC Directive
  • Low Voltage Directive (where applicable)
  • RoHS Directive
  • Ecodesign requirements
  • Sector-specific legislation where applicable

Cybersecurity should therefore be considered alongside RF, EMC and Safety from the beginning of the development process rather than being treated as an additional task shortly before certification.

Final Thoughts

The Cyber Resilience Act fundamentally changes how connected products are developed and certified within the European Union.

Cybersecurity is no longer an optional feature or solely a software concern—it has become an essential product compliance requirement.

Manufacturers that begin preparing now will be better positioned to integrate cybersecurity into their existing compliance processes, avoid costly redesigns and reduce delays when the Regulation becomes fully applicable.

How ScopeRight Supports Manufacturers

At ScopeRight, we combine specialized compliance software with hands-on regulatory expertise.

Our platform helps manufacturers identify applicable RF, EMC, Safety and Cybersecurity requirements before testing begins, supporting product-specific compliance scoping, global certification strategies and worldwide market access planning.

However, compliance is not always straightforward. Product variants, wireless technologies, target markets and applicable legislation often require engineering judgement that goes beyond automation.

That’s why ScopeRight is backed by experienced compliance professionals with extensive expertise in international product approvals, helping manufacturers navigate complex regulatory challenges with confidence.

Whether you need a fast compliance assessment through our platform or expert support for more complex certification projects, ScopeRight provides both the software and the expertise to support your compliance journey.