With the Cyber Resilience Act (CRA), the EU aims to significantly improve the cybersecurity of connected products in the internal market. Manufacturers, importers and distributors are required to systematically consider security aspects from the outset. This applies both during development and throughout the entire product lifecycle.

Two key dates are particularly relevant for manufacturers of products with digital elements. Since 11 September 2026, reporting obligations have applied to severe cybersecurity incidents and actively exploited vulnerabilities. From 11 December 2027, the technical and organisational requirements of the CRA must be met.
The increasing complexity of software and the growing connectivity of products are leading to security vulnerabilities being identified more frequently. This is not necessarily the result of poorer development practices. Contributing factors include increasingly complex technologies, more intensive testing and analysis, and the growing number and sophistication of attacks.
Such vulnerabilities can have far-reaching consequences. These include the theft of data and know-how, manipulation, and disruption to systems and infrastructure.
The CRA is therefore intended to ensure that security vulnerabilities are identified and addressed before products are placed on the market. At the same time, cybersecurity does not end when a product is delivered. Manufacturers must continue to monitor their products for new vulnerabilities and provide security updates throughout the product lifecycle.
The CRA therefore establishes, for the first time, an overarching framework that applies across product groups. Its aim is to create a level playing field for market participants and a consistent level of protection across the EU internal market.
The CRA applies to products with digital elements that are made available on the EU internal market for the first time. This applies where their intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Products with digital elements include hardware and software products as well as their remote data processing solutions where they enable physical or logical data exchange with other products or networks.
In simple terms, the CRA applies to standalone software products as well as hardware products with communication interfaces such as Ethernet, USB, SD cards or PCIe. This includes products intended for end users as well as products integrated into other products.
The requirements apply to European providers as well as international manufacturers wishing to supply products to the EU internal market. Only a limited number of exceptions are provided for.
The CRA requires manufacturers to take a comprehensive approach to the cybersecurity of their products. This includes both technical and organisational measures.
Key requirements include:
In addition, manufacturers must address incident reporting and maintain appropriate product documentation.
The CRA does not prescribe specific security measures. Instead, manufacturers must define suitable measures based on a threat and risk assessment. This includes considering both the likelihood and the potential impact of threats.
The objective is to reduce the remaining residual risk to an acceptable level. The measures taken must be appropriate, traceable and documented.
Since 11 September 2026, reporting obligations have applied to severe cybersecurity incidents and actively exploited vulnerabilities.
From 11 December 2027, all CRA requirements will become mandatory. This includes conformity assessment, documentation and the required security measures.
From that date, a product with digital elements may only bear the CE marking and be placed on the EU internal market if it complies with the requirements of the CRA.

Violations of manufacturer obligations or reporting requirements can result in fines of up to EUR 15 million or 2.5% of the company’s total worldwide annual turnover, whichever is higher.
Market surveillance authorities may also remove or recall products from the market, prohibit them from being made available, or require corrective measures for products that have already been delivered.
The CRA does not prescribe specific measures. Manufacturers must define suitable security measures based on a threat and risk assessment. These measures must be appropriate, traceable and documented.
There is no one-size-fits-all solution. Implementation must be tailored to the respective products, customers and existing processes. Existing structures should be systematically extended to include relevant security aspects.
External expertise can help define appropriate security measures in line with the state of the art and support robust risk assessments. It can also help organisations implement the necessary changes efficiently and effectively.
With the CRA, cybersecurity becomes now a mandatory quality attribute of products in the European market. In a world that is ever so interconnected, with consumers, companies and critical infrastructure being targeted by hackers and state agencies, the CRA ensures that manufacturers take responsibility and that at least some bare minimum of cyber hygiene is implemented.
The transparency and support period that the CRA mandates from manufacturers towards its customers will help in making more security aware decisions and ultimately will hopefully make the EU a more secure place.
The CRA levels now the playing field. For us it is positive to see that the efforts of our previous and existing customers pay off, being now well prepared, and we are happy to continue help many others on their journey here now as well to conduct threat and risk assessment and establish secure development processes to ultimately develop secure products.
As a leading OT security expert in the DACH region, Limes Security supports companies in the secure development of industrial products and solutions.
Their support ranges from initial orientation to technical implementation and training. This includes information workshops and guidelines, threat analyses and security concepts, secure product development processes, security testing, as well as workshops and training. The Limes experts bring many years of experience supporting manufacturers of medical devices, embedded and IoT solutions, industrial components and machinery.
These services complement one another and enable a structured, traceable and practical implementation of CRA requirements, tailored to individual product and organisational needs.
The main goal is to provide the best possible support as a partner in the efficient development of secure, CRA-compliant products.
By Florian Gerstmayer at Limes Security GmbH

Understanding the requirements is an important first step. In our upcoming webinar on October 8th, experts from Westermo and Limes Security share practical insights into CRA readiness, including risk assessments, secure development practices and vulnerability management.
The Cyber Resilience Act (CRA) introduces new requirements for how connected products are designed, maintained and secured over time.
At Westermo, we take a structured approach to cybersecurity and compliance – focusing on practical implementation, long-term support and secure, reliable network operation.
Explore Westermo’s approach to CRA
This course builds essential cybersecurity understanding for employees working with operational technology.

This course creates common understanding of OT security and provides guidance on how to work with it.
Nuri Shakeer
International Sales
Pour toute demande d’assistance, cliquez ici pour contacter le support technique