The Cyber Resilience Act — what it means for product sellers

The EU's first cybersecurity law for everyday connected products. Which products are in scope, why own-brand sellers are the manufacturer, the key obligations, and the 2026 and 2027 deadlines.

REVIEWED BY THE REGONANCE EDITORIAL TEAM

The Cyber Resilience Act — Regulation (EU) 2024/2847, usually shortened to the CRA — is the EU's first law that sets mandatory cybersecurity requirements for ordinary products. Not for banks, power grids or hospitals, which already had their own rules, but for the smart plug, the baby monitor, the fitness tracker and the Bluetooth speaker you sell on Amazon.de or ship from your Shopify store.

It entered into force on 10 December 2024. One part of it — reporting actively exploited vulnerabilities — has applied since 11 September 2026. Everything else applies from 11 December 2027. After that date, a connected product that does not meet the CRA cannot legally be placed on the EU market.

This guide explains what the CRA is, which products it covers, who carries the obligations, what those obligations are, and how the CRA sits alongside GPSR, the Radio Equipment Directive and CE marking.

Why the CRA exists

Before the CRA, EU product law said almost nothing about cybersecurity. A camera could be electrically safe, radio-compliant and CE marked while shipping with a default password, unpatched open-source libraries and no way to receive updates. When those devices were compromised — and pulled into botnets, used to spy on households or used as a way into home networks — there was no product-level rule that the manufacturer had broken.

The CRA fixes that gap with a horizontal regulation: one set of cybersecurity rules that applies across product categories, instead of a separate rule for each kind of device. It follows the familiar New Legislative Framework model — essential requirements, conformity assessment, technical documentation, a Declaration of Conformity and the CE mark — so if you already CE mark electronics, the structure will be recognisable.

Which products are in scope

The CRA covers products with digital elements: hardware or software whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. In plain terms: if it has a chip that talks to anything, it is almost certainly in scope.

Typical consumer products caught by the CRA:

  • Smart home devices — smart plugs, bulbs, thermostats, locks, cameras, video doorbells
  • Wearables — fitness trackers, smartwatches, health monitors
  • Connected toys and children's devices
  • Bluetooth and Wi-Fi accessories — speakers, headphones, keyboards, mice, game controllers
  • Networking equipment — routers, modems, mesh systems, range extenders
  • Smart appliances — connected fridges, ovens, washing machines, robot vacuums
  • Trackers — GPS trackers, key finders, pet trackers, vehicle accessories with connectivity
  • Anything with firmware that receives updates, plus standalone software sold in the EU

A quick self-check: does the product connect over Wi-Fi, Bluetooth, NFC, Zigbee, Z-Wave, cellular, or a wired data link? Does it run software or firmware? If the answer to either is yes, assume the CRA applies until you have confirmed an exclusion.

What is excluded

The CRA does not apply to products already covered by their own sector cybersecurity rules — medical devices, in-vitro diagnostics, motor vehicles, civil aviation and marine equipment — nor to products developed exclusively for national security or defence. Spare parts supplied to replace identical components are also excluded. For the typical consumer-goods seller, these exclusions rarely help: a smart speaker or a connected toy is squarely in scope.

Who carries the obligations — and why private label matters

The CRA puts the heaviest obligations on the manufacturer. For private-label and own-brand sellers, the critical point is who counts as the manufacturer.

The CRA defines a manufacturer as anyone who develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under their own name or trademark. On top of that, Article 21 says that an importer or distributor who places a product on the market under their own name or trademark, or who carries out a substantial modification of a product already on the market, is treated as the manufacturer and takes on the manufacturer's obligations.

The result is simple: if your brand is on the box, you are the manufacturer under the CRA — not the factory in Shenzhen or the ODM that designed the circuit board. This is the same principle as GPSR Article 8(1), where putting your name or trademark on a product makes you its manufacturer for safety purposes. The two obligations stack: you are responsible for both the product's safety and its cybersecurity.

We cover this in depth in Article 21 — why the CRA treats private-label sellers as manufacturers.

Importers and distributors who are not deemed manufacturers still have duties: importers must check that the manufacturer carried out the conformity assessment, that the technical documentation exists and that the product carries the CE mark; distributors must check the CE mark and accompanying information before selling. Neither can place a product on the market that they know, or should know, does not comply.

Product classification: default, important and critical

The CRA sorts products into categories. The category decides which conformity assessment route you must use.

CategoryWhat it coversConformity assessmentTypical examples
DefaultEvery product with digital elements not listed in Annex III or IVSelf-assessment (internal control, Module A)Bluetooth speakers, headphones, smart plugs, most smart appliances
Important — Class IAnnex III, Part ISelf-assessment only if you fully apply harmonised standards or a certification scheme; otherwise third-partyRouters, password managers, smart home products with security functions (smart locks, security cameras, baby monitors, alarm systems), connected toys with social-interaction or location-tracking features, health-tracking wearables
Important — Class IIAnnex III, Part IIMandatory third-party assessmentHypervisors, firewalls and intrusion detection systems, tamper-resistant microprocessors and microcontrollers
CriticalAnnex IVEuropean cybersecurity certification, where a scheme is requiredHardware devices with security boxes, smart meter gateways, smartcards and secure elements

The Commission has estimated that around nine in ten products with digital elements fall into the default category, and most ordinary consumer electronics do. But check the Annex III list carefully: several popular smart-home and children's categories — security cameras, smart locks, baby monitors, connected toys with location tracking — are named as Class I. For those, self-assessment is only available if you fully apply the relevant harmonised standard, and those standards are still being finalised.

The key obligations

From 11 December 2027, the manufacturer of a product with digital elements must be able to show all of the following.

1. A cybersecurity risk assessment

Before placing the product on the market, you must assess its cybersecurity risks and design, develop and produce it to address them. The assessment feeds the technical documentation and must be updated during the support period. You can use your factory's design and test data, but the assessment is yours.

2. The Annex I essential requirements

The product must meet the essential cybersecurity requirements in Annex I. For consumer products, the practical ones are: no known exploitable vulnerabilities at release; a secure-by-default configuration (no shared default passwords); protection against unauthorised access; protection of the confidentiality and integrity of data; data minimisation; the ability to receive security updates, automatically by default where appropriate; and the ability for users to securely remove their data.

3. A Software Bill of Materials (SBOM)

You must identify and document the software components in the product, including by drawing up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies. SPDX and CycloneDX are the widely used formats. An SBOM is kept in the technical documentation — it does not have to be published — but market surveillance authorities can ask for it.

4. Vulnerability handling

You must have a process for receiving, assessing and fixing vulnerabilities for the whole support period: a published contact point for vulnerability reports, a coordinated vulnerability disclosure policy, and security updates delivered without delay and free of charge.

5. Reporting to authorities

Actively exploited vulnerabilities and severe incidents must be notified — with an early warning within 24 hours — through the single reporting platform run by ENISA. This is the part that already applies. See CRA vulnerability reporting — the 24-hour obligation that's already live.

6. A support period of at least five years

You must set a support period — the time during which you will handle vulnerabilities and provide security updates — that reflects how long the product is expected to be used. It must be at least five years, unless the product is expected to be in use for less than that. The end date must be shown to buyers at the time of purchase.

7. Conformity assessment, documentation and CE marking

You must complete the conformity assessment route for your product's category, draw up technical documentation, issue an EU Declaration of Conformity, and affix the CE mark. Documentation must be kept for ten years after the product is placed on the market, or for the support period if longer.

The timeline

DateWhat applies
10 December 2024CRA enters into force
11 June 2026Rules on notified bodies (conformity assessment bodies) apply
11 September 2026Reporting of actively exploited vulnerabilities and severe incidents applies — to all in-scope products on the market, including those placed before 2027
11 December 2027All other obligations apply — essential requirements, risk assessment, SBOM, support period, conformity assessment, technical documentation, CE marking

Products placed on the market before 11 December 2027 do not have to be re-certified, unless they are later substantially modified. But the reporting duty is not limited to new products: it already applies to connected products you sell today.

How the CRA stacks with GPSR, RED and CE marking

None of these replace each other. A private-label Wi-Fi camera sold into the EU in 2028 will typically need:

  • GPSR — general product safety, your name and address on the product, an EU responsible person if you are established outside the EU, and GPSR listing information on every marketplace offer.
  • The Radio Equipment Directive (RED) — radio performance, EMC and electrical safety. Since 1 August 2025, a RED delegated act has also required cybersecurity protections for many internet-connected radio products; that delegated act is expected to be superseded by the CRA as the CRA's requirements take over.
  • The Low Voltage and EMC directives, RoHS and WEEE — where they apply to the product.
  • The CRA — cybersecurity by design, SBOM, vulnerability handling, reporting and security updates.

The CRA adds cybersecurity to the CE marking picture: your EU Declaration of Conformity must reference the CRA alongside the other legislation, and the CE mark signals conformity with all of it. If you already work through CE marking with Module A self-assessment, the CRA default route will feel familiar — but the evidence it needs (risk assessment, SBOM, update pipeline) comes from your software supply chain, not a test lab.

What to do now

  1. List every product with digital elements in your catalogue — anything with firmware, an app, or a radio.
  2. Classify each one — default, or does it appear in Annex III?
  3. Set up vulnerability monitoring and a reporting route now. This is the only obligation already live.
  4. Talk to your factories. Can they provide an SBOM, fix vulnerabilities and commit to at least five years of security updates? If a supplier cannot, that product may not be sellable in the EU after December 2027.
  5. Plan the December 2027 work — risk assessment, documentation and an updated Declaration of Conformity, product by product.

CRA in Regonance

Regonance is adding the Cyber Resilience Act to the platform. Today the platform assesses products across the nine EU regulations it already covers. In the meantime, the EU Cyber Resilience Act Playbook (€49) gives you the scope test, classification table, Article 21 analysis, SBOM template, reporting workflow and a complete checklist.

This guide is general information based on the published text of Regulation (EU) 2024/2847. Implementing and delegated acts, and harmonised standards, are still being developed — check current requirements before relying on any single date or template. It is not legal advice.

More on the Cyber Resilience Act

Need hands-on help? Our team can handle your compliance — from a €499 single-product scan to full catalogue management. Book a consultation →

CRA platform support coming soon — start with the 9 regulations we cover today

A free workspace checks your first three products against GPSR, CE marking, the Battery Regulation and six more EU regulations. CRA assessments join the platform next.

Start free workspace
Free · no account

Every EU deadline, on one page.

Nine mandates, each with dates attached between now and 2030. Get the calendar, plus a note when the guidance behind an article like this one changes.

  • → Every applicable EU compliance date
  • → Which mandate hits your category first
  • → An alert when a rule or guidance changes

No account needed. One-click unsubscribe. Or browse every deadline now →

Compliance guidance based on published EU regulatory texts. Not legal advice. Consult qualified counsel for your specific situation.