CRA
Cyber Resilience Act
EU-Cyberresilienz-Verordnung (Verordnung 2024/2847)
The CRA is EU Regulation (EU) 2024/2847 setting horizontal cybersecurity requirements for „products with digital elements“ — from industrial controllers and software to connected consumer devices. For the first time manufacturers must ensure security across the entire product lifecycle, handle vulnerabilities and provide security updates. The CE marking is thereby extended with a cybersecurity dimension.
History. For a long time connected products sat in a de-facto liability vacuum: security flaws were the operator's problem, not the manufacturer's. The CRA was adopted on 23 October 2024 and entered into force in late 2024. It closes the gap between product-safety law and cybersecurity and complements NIS2 (operator duties) with the manufacturer's perspective.
Facts. The CRA applies in stages: core obligations take effect from 11 December 2027, while reporting duties for actively exploited vulnerabilities and severe incidents apply earlier, from 11 September 2026. Manufacturers must demonstrate „security by design“, vulnerability handling with defined update windows, a software bill of materials (SBOM) and conformity assessments. Particularly critical product classes face stricter procedures; free and open-source software is treated separately and largely privileged.
Outlook & recommendation. The CRA affects anyone placing hardware or software on the EU market — including machine and plant builders who never saw themselves as software vendors. Product developers should bake SBOM generation, a coordinated vulnerability disclosure (CVD) process and update mechanics into development now, rather than retrofitting them in 2027. The reporting duty from September 2026 is the first hard deadline.