Cyber Resilience Act for Product Teams: What Changes for Connected Device Makers

The Cyber Resilience Act (CRA) requires manufacturers of products with digital elements placed on the EU market to address cybersecurity across the product lifecycle, including secure development, vulnerability handling, security updates, risk management, and conformity requirements. The regulation entered into force in December 2024, with its main obligations applying from December 11, 2027, while certain requirements already apply earlier.

For product teams, the biggest change is that cybersecurity becomes part of the product-development and product-lifecycle process rather than a security activity performed only before launch.

Cyber Resilience Act for Product Teams What Changes for Connected Device Makers

What is the cyber resilience act draft?

The Cyber Resilience Act is no longer merely a draft: it is Regulation (EU) 2024/2847, the EU’s horizontal cybersecurity regulation for products with digital elements.

The regulation covers hardware and software products that are made available on the EU market and establishes cybersecurity requirements covering their design, development, production, placement on the market, and vulnerability handling.

For product teams, this means cybersecurity requirements need to be considered much earlier than the final compliance review.

A connected-device company should therefore build CRA considerations into:

  • Product requirements
  • Threat modeling
  • Architecture reviews
  • Secure coding
  • Dependency management
  • Vulnerability management
  • Security testing
  • Release processes
  • Security-update mechanisms
  • Product documentation
  • Incident response
  • End-of-support planning

The Commission published practical CRA guidance in July 2026 specifically addressing questions around scope, remote data processing, open-source software, substantial modifications, support periods, reporting, and risk assessment.

When is the cyber resilience act release date?

The Cyber Resilience Act entered into force on December 10, 2024, and its main requirements will apply from December 11, 2027.

However, the CRA is already affecting manufacturers because some provisions have earlier application dates. In particular, Article 14 reporting obligations for actively exploited vulnerabilities and severe security incidents apply from September 11, 2026. Requirements concerning conformity-assessment bodies began applying on June 11, 2026.

That creates three practical milestones for product teams:

  1. June 11, 2026: Certain conformity-assessment provisions begin applying.
  2. September 11, 2026: Manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents begin.
  3. December 11, 2027: The main CRA obligations apply.

The September 2026 milestone is especially important for manufacturers already selling covered products in the EU. The European Commission says manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform, with an early warning within 24 hours and a subsequent notification within 72 hours.

What is the cyber resilience act directive?

The Cyber Resilience Act is not an EU directive; it is an EU regulation.

That distinction matters because a regulation is directly applicable across EU Member States, whereas a directive generally requires national implementation through domestic legislation.

The CRA is formally Regulation (EU) 2024/2847. EUR-Lex states that it is binding in its entirety and directly applicable in all Member States.

Product teams should therefore avoid describing their CRA obligations as something each EU country will separately transpose into national law before the requirements exist.

The practical compliance work is instead based on the regulation itself, supplemented by European Commission guidance, harmonized standards as they become available, conformity-assessment requirements, and national market surveillance.

Cyber resilience act who does it apply to, and does it cover my product?

The Cyber Resilience Act generally applies to products with digital elements that are made available on the EU market and are connected directly or indirectly to a device or network. This can include both physical products and software.

Examples can include:

  • Smart home devices
  • Industrial connected equipment
  • Routers and network equipment
  • Connected sensors
  • Smart appliances
  • Computer programs
  • Mobile applications
  • Security products
  • IoT devices
  • Embedded software

The critical question is not simply whether a company calls something a “device.” Product teams need to determine whether the product meets the CRA definition of a product with digital elements and whether an exemption or special category applies.

The European Commission’s 2026 guidance specifically provides examples and flowcharts intended to help companies determine whether particular products fall within scope.

Product teams should also identify whether their product falls into one of the CRA’s more sensitive product categories, because conformity-assessment requirements can differ depending on the product’s cybersecurity characteristics and classification.

Does the cyber resilience act software as a service scope cover my SaaS product?

The Cyber Resilience Act does not automatically regulate every SaaS product simply because the service is accessed through software.

The scope analysis depends on whether the SaaS functionality constitutes a product with digital elements under the CRA and, in particular, how remote data-processing solutions relate to a covered product.

This is one area where product teams should not rely on a simple rule such as “SaaS is excluded” or “all cloud software is covered.” The European Commission’s July 2026 guidance specifically addresses remote data-processing solutions and provides clarification on when they can fall within the CRA framework.

A useful product-team analysis asks:

  1. What exactly are we placing on the EU market?
  2. Is there a product with digital elements?
  3. Is our cloud component supporting or integral to that product?
  4. Does another manufacturer place the connected product on the market?
  5. Are we providing a standalone service or software component?
  6. Are there applicable exemptions?
  7. Who is legally considered the manufacturer for the relevant product?

For borderline SaaS architectures, the company should document its scope analysis rather than making an informal assumption based solely on the word “SaaS.”

What changes for connected device product teams?

The CRA changes product development by making cybersecurity a lifecycle responsibility.

A connected-device team should expect to formalize processes for:

Risk assessment: Identify cybersecurity risks associated with the product and its intended use.

Secure development: Incorporate cybersecurity into design, implementation, and testing.

Vulnerability handling: Establish processes for identifying, documenting, addressing, and communicating vulnerabilities.

Security updates: Provide appropriate security updates throughout the required support period.

Technical documentation: Maintain evidence demonstrating how the product meets applicable requirements.

Incident reporting: Be prepared to report actively exploited vulnerabilities and severe incidents within the required timelines.

Conformity assessment: Determine which assessment procedure applies before placing the product on the EU market.

The regulation requires products with digital elements to be designed and developed according to an appropriate level of cybersecurity based on risk and to be made available without known exploitable vulnerabilities, subject to the regulation’s requirements and exceptions.

How should product teams prepare for the CRA?

Product teams should start by creating a product-level CRA inventory rather than waiting for December 2027.

For each connected product, document:

  1. Product scope: What hardware, software, firmware, and cloud components make up the product?
  2. EU exposure: Is the product available or intended to be available in the EU?
  3. Architecture: What systems, interfaces, APIs, devices, and external services does it depend on?
  4. Vulnerabilities: How are vulnerabilities discovered, prioritized, fixed, and disclosed?
  5. Dependencies: What third-party and open-source components are embedded in the product?
  6. Updates: How are security updates delivered and verified?
  7. Support: How long will security support be provided?
  8. Evidence: What technical documentation and testing evidence will be retained?
  9. Reporting: Who is responsible for the 24-hour and 72-hour reporting processes?
  10. Conformity: Which conformity-assessment route applies?

This preparation is particularly important because the reporting requirements are already active. Manufacturers must use the CRA Single Reporting Platform operated by ENISA for the applicable vulnerability and incident notifications.

Turn CRA requirements into product requirements now

The biggest mistake for a connected-device manufacturer is treating the Cyber Resilience Act as a certification project that starts shortly before December 2027.

The better approach is to turn the regulation into product-development requirements now.

Create a CRA scope assessment for every relevant product, identify cybersecurity requirements during architecture and design, establish vulnerability-management ownership, maintain software-component inventories, define the security-support period, and build an incident-reporting process capable of meeting the new deadlines.

The CRA’s main obligations do not apply until December 11, 2027, but reporting obligations are already active as of September 11, 2026.

For product teams, the practical goal is therefore straightforward: know which products are covered, know who owns each obligation, and make cybersecurity evidence part of the product lifecycle before compliance becomes a launch blocker.

Popular on OTW Right Now!

Add a Comment

Your email address will not be published. Required fields are marked *