In a world as technologically advanced as ours, cyberattacks have become the modern equivalents of armed robbery. Instead of holding up banks, corner stores, or unsuspecting individuals walking down the wrong alley in the middle of the night, many modern criminals focus their efforts on using cyberattacks to steal from corporations, governments, and regular people. While these attacks vary in size, scope, and audacity, they add up to an enormous criminal venture.
According to industry group Cybersecurity Ventures, the total annual cost of all global cybercrime is now over $10 trillion. These costs come from a combination of negative outcomes, including:
- Business downtime and the lost productivity that accompanies it
- Theft through fraud, extortion, and embezzlement
- Lost data
- Stolen intellectual property
The many different ways that cybercriminals can prey on individuals and entities—and the wide myriad of valuable information they can obtain from these attacks—adds up to a massive criminal sector, one that continues to grow on an annual basis. Data from Cybersecurity Ventures has suggested that the total cost of cybercrime has increased dramatically over the past decade:
- 2015: $3 trillion
- 2021: $6 trillion
- 2025: $10.5 trillion
While some organizations estimate the total figures to be significantly lower, even annual cybercrime costs between $1 and $2 trillion would put the criminal enterprise on par with the entire GDP of Indonesia or the Netherlands. So, what, exactly, are the world and its most powerful governments doing about this burgeoning new world of nefarious actors?
What Is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is a regulation created by the European Union to address the sprawling world of cybercrime. The act aims to force technology companies and other manufacturers to make hardware and software that is protected from cyberattacks and less likely to become a vector for crimes that target the data and/or financial resources of regular EU citizens. As the European Commission explains on its website, the Cyber Resilience Act aims to set “clear and mandatory cybersecurity requirements across the full lifecycle of digital products.”
The CRA was initially proposed by the European Commission in 2022. Two years later, in 2024, the European Parliament formally adopted the text of the CRA, and the European Council approved it. After being published in the EU’s Official Journal in November, the CRA officially entered into force in December 2024.
Given the breadth of obligations that the CRA imposes on businesses that fall inside the regulation’s scope, however, the EU has given companies ample time to prepare for their compliance responsibilities. The law is being implemented over a period of around 15 months, beginning in September 2026 and reaching full implementation in December 2027.
What Are the Requirements of the Cyber Resilience Act?
The EU CRA imposes a battery of obligations on in-scope organizations. The intention of the regulation is to legally compel these businesses to create safer, more resilient digital products, develop more robust protocols for handling cybersecurity incidents, and show greater transparency with consumers and other stakeholders regarding their mitigation measures and overall security posture.
The primary requirements for the Cyber Resilience Act can be found in Annex I of the law, titled Essential Cybersecurity Requirements. They are divided into two sections: what properties digital products manufactured by in-scope businesses must have, and what processes the manufacturers of those products must carry out to comply with the law.
Annex I, Part I: Properties Digital Products Must Have
This section of the law is in some ways the heart of the legislation. The EU wants digital products marketed and sold in Europe to be safer and more protected against cybercriminals, and these are the measures they believe will achieve that level of protection. To comply with the CRA, digital products should be designed and released into the EU market with the following characteristics:
- 1 No known exploitable vulnerabilities
- 2 A secure by default configuration. This means that secure settings are the default setting on the device or product.
- 3 Vulnerabilities can be effectively addressed through security updates, including automatic security updates that have a clear opt-out mechanism.
- 4 Protection from unauthorized access, including through features like authentication, identity, or access management mechanisms.
- 5 Preservation of the confidentiality of any data stored on the product, through encryption or other means.
- 6 Protection of the integrity of data, programs, and configurations against external manipulation or modification.
- 7 Only data that is necessary to the continued functioning of the product may be collected.
- 8 Preservation of basic functions of a product following a cyberattack.
- 9 Minimization of negative impact of cyberattacks on other devices or networks.
- 10 Limited “attack surfaces,” meaning points of exposure or vulnerability that can be exploited by malicious actors.
- 11 Mechanisms in place to limit the impact and effectiveness of successful cyberattacks.
- 12 Ability to record security events, including changes to data or device functions. This feature must have an opt-out mechanism for users.
- 13 Ability for the user to delete all data and personalized settings from the product.
Annex I, Part II: Processes Manufacturers Must Carry Out
Along with designing and producing digital products with the appropriate security features, manufacturers must also be prepared to play an active role in mitigating cyberattacks throughout a product’s full lifecycle.
Product manufacturers must carry out the following measures:
- 1 Identity and document product vulnerabilities, including by producing a bill of materials that covers all key dependencies.
- 2 Address and remediate security vulnerabilities as soon as they surface, including through security updates.
- 3 Carry out ongoing security testing for digital products.
- 4 Share information about vulnerabilities and security events, including the impact, severity, and clear instructions on how users can remediate the existing vulnerabilities.
- 5 Establish an official coordinated vulnerability disclosure (CVD) policy.
- 6 Create a framework for sharing and reporting on security vulnerabilities, including through a contact address disseminated so that individuals can report security issues.
- 7 Create mechanisms through which security updates can be transmitted to all digital products in a timely fashion and, where applicable, automatically.
These mechanisms should be distributed to users and products without delay, free of charge, and with messages conveying relevant information and outlining any necessary actions to be taken on the user’s part.
What Companies Are in the Scope of the CRA?
The Cyber Resilience Act casts a very wide net, and many businesses that operate in the EU will be legally obligated to comply with the directive. Broadly, the CRA applies to any businesses that manufacture “products with digital elements” that are available in the EU market. Put more simply, any hardware products that can connect to the internet or another device, and any software—including programs, applications, and firmware—are within the scope of the CRA.
While far from a comprehensive list, these are some of the items regulated by the Cyber Resilience Act:
- Consumer Electronics: Laptops, smartphones, tablets, routers, switches.
- Smart Devices: Smart appliances, smart speakers, virtual assistants, alarm systems.
- Wearable Technology: Smart watches, fitness trackers, smart glasses, smart rings.
- Software and Firmware: Mobile and desktop applications, operating systems, device firmware.
- Electronic Components: Graphics processors, computer processing units (CPUs), microprocessors (MPUs).
Digital and technology products have complex supply chains with many different manufacturers, suppliers, and sub-tier vendors. The EU singles out three specific groups, or “economic operators,” who must comply with the law:
Manufacturers
These are the companies who manufacture the product and market it under their brand name. They’re often referred to as original equipment manufacturers, or OEMs, and they generally source from large supply chains with dozens, hundreds, or even thousands of direct and indirect suppliers. These specific manufacturers bear the responsibility for complying with CRA.
Importers
As the name implies, these operators are businesses that import digital products from outside the EU—often from an OEM or other manufacturer—and sell them on the EU market.
Distributors
Distributors is something of a catch-all term for all actors other than manufacturers and importers who are responsible for placing digital products in the EU marketplace. Distributors include retailers and other related businesses, and often sell directly to consumers.
How Is the EU Enforcing the CRA?
The CRA requires all EU countries to designate their own market authority for enforcing the law and surveilling companies that fall inside its scope. These could be government offices, agencies, or other entities with monitoring and enforcement capabilities. The designated market authority has the power to ask for technical documentation from in-scope operators, carry out product recalls, or otherwise limit a specific product from reaching the marketplace if it’s deemed to be out of compliance with the CRA.
In addition, authorities may administer penalties and fines for violators.
Consequences for Not Complying With the CRA
Businesses that fail to comply with the Cyber Resilience Act can face significant fines.
- Violations of the CRA’s Essential Requirements: Fines of up to 15 million euros or 2.5% of a company’s global revenue, whichever is higher.
- Violations of Other CRA Obligations (including documentation requirements and CE marking procedures): Fines of up to 10 million euros or 2% of a company’s global revenue, whichever is higher.
- Supplying False or Incomplete Information to Market Authorities or Notified Bodies: Fines of up to 5 million euros or 1% of a company’s global revenue, whichever is higher.
The Role of Certifying Bodies in the Cyber Resilience Act
Whether a company needs to work with a certifying or notified body to comply with the Cyber Resilience Act depends on the risk classification of the products it manufactures, imports, or distributes. The CRA puts all digital products into one of four different product tiers:
- Default Products: This category covers the majority of digital products in the EU marketplace, including consumer electronics, toys, and most smart devices. Businesses manufacturing, importing, or distributing products in the default category do not need to obtain a third-party assessment.
- Important Products (Class I): This classification covers items that have special security responsibilities, including routers, modems, browsers, and virtual private networks (VPNs). This class of products generally requires a third-party assessment from a notifying body showing CRA compliance, unless the economic operator either demonstrates adherence to a relevant harmonized standard for cybersecurity, or obtains an EU cybersecurity certification approved by the CRA.
- Important Products (Class II): This group is for even more important security infrastructure, including firewalls, hypervisors, and intrusion detection systems. Businesses that manufacture, import, or distribute these products must always obtain a third-party assessment from a notified body to demonstrate CRA compliance.
- Critical Products: This is the highest-risk category, and encompasses products like hardware security modules, smart cards, and smart meter gateways. As with the third category, businesses involved in bringing these goods to the EU marketplace must always obtain a third-party assessment from a notified body.
Key Implementation Dates for the Cyber Resilience Act
The EU is implementing CRA in a staggered fashion. The law will enter into force over roughly 15 months between September 2026 and December 2027.
On September 11, in-scope businesses need to start reporting on actively exploited cybersecurity vulnerabilities and severe cybersecurity incidents. Because the reporting itself must begin on this date, companies will need to have established and implemented internal incident reporting processes well before the deadline.
Fifteen months after the reporting obligations go into effect, businesses will be responsible for adhering to all the other compliance requirements. This includes all 13 requirements for digital products and all eight obligations for product manufacturers.
How Businesses Can Comply With the CRA
One of the major ongoing issues with the CRA is that the regulation’s harmonized standards have not yet been finalized and released (as of fall 2026). Despite this, the EU appears to still be moving forward with its two most important deadlines—vulnerability reporting, in September 2026; and full compliance obligations in December 2027.
Adhere to Existing Cybersecurity Standards
In-scope businesses might reasonably ask themselves, If there are no official harmonized standards for this regulation, how am I supposed to prepare for it right now? While there’s some validity to this viewpoint, organizations are not completely helpless. It’s widely known that the EU committee responsible for drafting CRA standards is drawing from several established frameworks, standards that companies can leverage right now as they work to adhere to a regulation that still isn’t totally clear in its concrete requirements. The standards the CRA is leveraging include:
- IEC 62443
- ISO 30111
- ISO/IEC 27001
- IEC 62443-4-1
Establish an Incident Response Protocol
If there’s one thing that covered organizations know for certain, it’s that, beginning on September 11, 2026, they’re expected to start reporting on actively exploited vulnerabilities or other severe cybersecurity incidents.
Suffice it to say, companies need to have an incident reporting process in place before that date in order to effectively comply with the Cyber Resilience Act. Part of this obligation includes the requirement that businesses create a product security incident response team (PSIRT) that responds to cyber incidents, swiftly identifies vulnerabilities, assesses their threat level, and creates security patches that are then deployed to all users.
Covered businesses should be putting together the professional teams, digital tools, processes, and documentation requirements for this obligation now.
Carefully Document Everything
Once all CRA obligations enter into force in December 2027, in-scope entities will be responsible for an extensive documentation file that’s used for the conformity assessment (whether that assessment is conducted internally or by a third-party notified body). This file will need to include a bill of materials, cybersecurity risk assessment, design decisions informed by security requirements, and an explanation for what standards were followed, among other facets.
Businesses don’t need the CRA’s harmonized standards to start collecting all this information. They can begin pulling together all the directive’s documentation requirements right now.