Prepare your product for the Cyber Resilience Act with easyCE.
Regulation (EU) 2024/2847 introduces cybersecurity requirements for products with digital elements sold on the EU market.
The Cyber Resilience Act (CRA) covers product security throughout design, development and the support period. Manufacturers need to assess cybersecurity risks, address vulnerabilities and document how their products meet the applicable requirements. The rules concern consumer and industrial products, with specific exclusions and assessment routes.
easyCE reviews the requirements for your product and turns them into a practical documentation plan. We assess risks, identify gaps in the available evidence and prepare the agreed technical documentation with your development team.
Your CRA questions answered
Which products are covered by the Cyber Resilience Act?
The CRA covers hardware and software products made available on the market whose intended purpose or reasonably foreseeable use involves a direct or indirect data connection to a device or network. This can include separately marketed components and remote processing essential to a product's functions. The product's scope and any exclusions must be checked individually.
Why does the CRA matter for your product?
Cybersecurity becomes part of the product's conformity assessment, rather than an optional extra after development. Manufacturers need evidence of secure design and a process for handling vulnerabilities. Compliance does not guarantee that a product can never be attacked, but it makes security responsibilities and supporting evidence explicit.
When does the Cyber Resilience Act apply?
The CRA entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Most other requirements apply from 11 December 2027. These are separate milestones, so preparations should distinguish reporting readiness from the broader product conformity work.
How can you prepare now?
Identify the products and versions in scope, review their cybersecurity risks and establish a clear process for receiving, assessing and addressing vulnerability reports. Gather design records, component information and test evidence, and document the planned support period. easyCE identifies the documentation gaps and helps your team prioritise the agreed preparation work.
How does the CRA relate to the Machinery Regulation?
The Machinery Regulation (EU) 2023/1230 addresses risks to machinery safety, including corruption of safety-related software and data. The CRA addresses the cybersecurity of products with digital elements. Where both apply, assess their requirements together and keep the supporting records consistent. Compliance with one act does not automatically demonstrate compliance with the other.
Which products do not fall within the scope of the Cyber Resilience Act?
Article 2 provides exclusions for products covered by the MDR or IVDR, certain motor-vehicle legislation, certified civil aviation products and marine equipment legislation. Other exclusions include products developed exclusively for national security or defence. Applying ISO/SAE 21434 alone is not an exemption: the relevant legislation and the product's actual scope determine the outcome.
Which other requirements may apply?
Check the product against every applicable EU product law, which may include electrical safety, electromagnetic compatibility or radio equipment requirements. Standards can provide technical methods for demonstrating conformity, but they are not all mandatory. The applicable laws, product functions and intended use determine what needs to be assessed.
What belongs in the technical documentation?
The documentation identifies the product and relevant software versions, explains its design and vulnerability-handling processes, and records the cybersecurity risk assessment. It also brings together the applied specifications, test evidence, user information and the basis for the support period. Annex VII sets out the required content; the records must reflect the assessed product and remain current where required.
How do harmonised standards help?
Harmonised standards can provide a presumption of conformity for the requirements they cover once their references are published in the Official Journal of the European Union. Standardisation work is under way. Check the current published references and their scope rather than treating every draft or cybersecurity standard as harmonised.
What is needed before affixing CE marking?
The manufacturer must follow the applicable conformity assessment procedure, prepare the technical documentation and issue the EU declaration of conformity before affixing CE marking. Internal control is available for many products, while important or critical product categories can require another route or third-party assessment. The appropriate route depends on the product category and the assessment provisions in the CRA.
Discuss your CRA requirements
Talk to an easyCE expert about your product, the available evidence and the next steps.
Your product compliance experts
easyCE is an engineering consultancy specialising in product safety and compliance. We assess risks, identify applicable requirements and prepare technical documentation for an agreed scope. Our experts work with your team to resolve gaps in the evidence and coordinate the next steps.