The Cyber Resilience Act (CRA) is a European regulation designed to strengthen the cybersecurity of digital products sold within the European Union. Its aim is to ensure that software, connected devices and other products containing digital components are designed with an appropriate level of security from the moment they are placed on the market and throughout their entire lifecycle.
Until now, the security of a product depended largely on the choices made by its manufacturer. With the CRA, cybersecurity becomes a legal requirement. Manufacturers must now integrate security from the design stage (Security by Design), address newly discovered vulnerabilities promptly and provide security updates for several years after their products are placed on the market.
The regulation applies to a wide range of products, including software, network equipment, industrial systems, connected devices (IoT), electronic devices, cloud solutions and many other technologies used every day by both businesses and consumers.
The CRA also requires manufacturers to document cybersecurity risks, manage vulnerabilities on an ongoing basis and report actively exploited vulnerabilities to the competent authorities within defined timeframes. Importers and distributors also have responsibilities to ensure that only compliant products are made available on the European market.
The Cyber Resilience Act should not be confused with the NIS2 Directive. While NIS2 imposes cybersecurity obligations on organisations providing essential or important services, the CRA is primarily aimed at manufacturers and suppliers of digital products.
For businesses, this regulation represents a major step forward. By introducing common security requirements across the European market, the CRA helps reduce the number of vulnerabilities in digital products and strengthens user trust. Companies that develop or market products falling within the scope of the regulation therefore have every reason to anticipate these new obligations in order to ensure compliance and reduce cybersecurity risks.