Know the Facts: EU Cyber Resilience Act (CRA)
Official Source Link: Read Here
Status & Jurisdiction: Enacted - European Union & Ireland
Target Organisations: Hardware Manufacturers, Software Developers, IoT Device Makers & Industrial Tech Providers
Compliance Ranking: 🔴 Level 3 (see here)
1. Key Takeaways
‘CE Marking’ for Cybersecurity: Introduces mandatory cybersecurity requirements for all ‘products with digital elements’ sold in the EU.
‘Security by Design’: Demands ‘vulnerability handling’ throughout a product's minimum 5-year support lifecycle.
Market Access Prohibition: Non-compliant hardware and software products will be banned from the EU market.
2. What is the Cyber Resilience Act?
It fills legislative gaps in hardware and software supply chains. It establishes hardware-to-software baseline security requirements to prevent unpatched digital products from entering the EU market.
The CRA applies horizontally to any device or software connected directly or indirectly to a device or network.
3. Regulatory & Financial Impact on Businesses
Direct Obligations: Manufacturers must perform risk assessments, issue Software Bills of Materials (SBOMs), repair vulnerabilities automatically via free updates and notify the European Union Agency for Cybersecurity (ENISA) of exploited vulnerabilities within 24 hours.
Indirect Supply Chain Pressures: Tech distributors and cloud resellers must verify that third-party component software aligns with CRA conformity standards before resale.
Penalties for Non-Compliance: Non-compliance leads to fines up to €15 million or 2.5% of total worldwide annual turnover, alongside market product recalls.
4. Implementation Timeline & Key Dates
2024 - Official publication and entry into force.
2026 - Mandatory vulnerability reporting obligations take effect.
2027 - Full enforcement of all product design and CE marking rules.