AI EU Act

AI EU Act: What do companies need to tell users when using AI?

31. July 2026.

Cyber Resilience Act (CRA): A New Standard for the Security of Digital Products in the European Union

Published by: boost, 21. September 2026.

The Cyber Resilience Act (CRA), officially Regulation (EU) 2024/2847, is the European Union’s first horizontal regulatory framework introducing harmonized mandatory cybersecurity requirements for products with digital elements.

Its objective is to ensure that hardware and software remain secure throughout the entire product lifecycle, from development and manufacturing to maintenance and market withdrawal.

 

Objectives

Tha CRA aims to:

  • Ensure security by design and by default
  • Reduce the number of vulnerabilities in products
  • Introduce mandatory vulnerability management
  • Ensure timely distribution of security patches
  • Increase transparency for users
  • Establish a single set of rules across the EU market

 

Who Is Subject to the CRA?

The CRA applies to almost all Products with Digital Elements (PDEs) placed on the EU market.

  1. Manufacturers

This includes:

  • Hardware manufacturers
  • Software manufacturers
  • SaaS solutions when they form an integral part of a product
  • OEM manufacturers
  • IoT device manufacturers
  1. Products Within the Scope of the CRA

Examples include:

  • Hardware manufacturers
  • Software manufacturers
  • SaaS solutions when they form an integral part of a product
  • OEM manufacturers
  • IoT device manufacturers
  1. Economic operators

The CRA also applies to:

  • Authorized representatives
  • Importers
  • Distributors
  • Entities placing products on the EU market

 

Key obligations of Manufacturers

  • The Cyber Resilience Act introduces a range of new responsibilities for manufacturers. Organizations developing or placing products on the EU market must:
  • Conduct cybersecurity risk assessments
  • Implement security according to the secure-by-design principle
  • Maintain vulnerability management processes
  • Provide security updates throughout the expected support period
  • Prepare technical documentation related to product security
  • Carry out appropriate conformity assessment procedures
  • Issue an EU Declaration of Conformity
  • Affix the CE marking once all applicable requirements have been met

 

Reporting Vulnerabilities and Security Incidents

One of the most significant innovations introduced by the CRA is the obligation to report actively exploited vulnerabilities and serious security incidents.

As of 11 September 2026, manufacturers must report such events through the system managed by ENISA (European Union Agency for Cybersecurity).

Reporting Deadlines:

  • Initial warning within 24 hours of becoming aware of the issue
  • More detailed notification within 72 hours
  • Final report no later than 14 days after a corrective measure becomes available for an actively exploited vulnerability, or within one month for a serious security incident

This approach enables faster coordination between manufacturers, national authorities, and cybersecurity experts while reducing the risk of cybersecurity threats spreading further.

 

Important Dates

The CRA entered into force on 10 December 2024, but its provisions are applied gradually.

  • Incident reporting obligations apply from 11 September 2026
  • The full set of requirements, including mandatory product compliance and CE marking, will apply from 11 December 2027

 

Impact on Organizations

The Cyber Resilience Act will affect more than just technology manufacturers. Organizations that purchase or use digital products will also benefit from improved security and transparency.

The CRA is expected to:

  • Increase user trust in digital products
  • Reduce costs associated with cybersecurity incidents
  • Improve risk management within organizations
  • Encourage the development of more secure products and services

 

CE Marking

Once compliance with the CRA has been demonstrated, products must bear the CE marking, through which the manufacturer declares that the product meets the requirements of the Regulation.

 

Most Important CRA Articles

Article 13 – Obligations of Manufacturers

Article 13 requires manufacturers to:

  • Conduct cybersecurity risk assessments
  • Develop products according to the secure-by-design principle
  • Provide security updates
  • Maintain vulnerability management processes
  • Keep technical documentation

Article 14 – Vulnerability Management and Incident Reporting

Article 14 defines:

  • Reporting of actively exploited vulnerabilities
  • Reporting of serious incidents
  • 24-hour / 72-hour reporting timelines
  • Communication with ENISA and national CSIRT authorities

Annex I

Part I: Essential Cybersecurity Requirements

  • Secure configuration
  • Protection against unauthorized access
  • Authentication
  • Data integrity
  • Minimization of the attack surface

Part II: Vulnerability Handling Requirements

  • Vulnerability monitoring
  • Coordinated Vulnerability Disclosure (CVD)
  • Patch management
  • Security updates throughout the product lifecycle

Annex III

Defines Important Products, such as:

  • Network equipment
  • Password managers
  • VPN devices
  • Security tools

Annex IV

Defines Critical Products, such as:

  • Smart card devices
  • Secure elements
  • Certain cryptographic components

 

Conclusion

The Cyber Resilience Act represents one of the most important European cybersecurity regulations of recent years.

By introducing mandatory cybersecurity requirements throughout the entire lifecycle of digital products, the European Union aims to strengthen the resilience of the digital ecosystem and protect citizens, businesses, and public institutions from growing cyber threats.

Organizations that begin preparing for CRA compliance in a timely manner will gain not only regulatory compliance but also a significant competitive advantage in an increasingly demanding digital marketplace.

 

Source: The Cyber Resilience Act – Summary of the legislative text | Shaping Europe’s digital future