Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) establishes a harmonized cybersecurity framework for products with digital elements placed on the European Union market. It introduces mandatory requirements covering secure product design, cybersecurity risk management, vulnerability handling, security updates, and post-market obligations throughout the product lifecycle. Manufacturers must not only implement appropriate cybersecurity measures but also demonstrate compliance through technical documentation and objective evidence. As a prerequisite for CE marking of affected products, the CRA raises the importance of repeatable security engineering practices and evidence-based cybersecurity validation across the entire product lifecycle.

Who is affected?


cyber resilience act industry

Manufacturers

cyber resilience act IoT

IoT Products

cyber resilience act software

Software Vendors

cyber resilience act automotive

Automotive Suppliers

cyber resilience act industry

Industrial Equipment

cyber resilience act importer

Importers, Distributors

Key Requirements


  • Secure by Design & by Default: Products must be designed with cybersecurity as a core engineering principle. Appropriate security controls should be integrated throughout development and enabled by default.
  • Cybersecurity Risk Assessment: Manufacturers are required to identify, assess, and mitigate cybersecurity risks throughout the product lifecycle, considering both intended use and reasonably foreseeable misuse.
  • Security Validation & Testing: Appropriate security verification activities must be performed to demonstrate that implemented security measures effectively address identified risks.
  • Vulnerability Handling: Organizations must establish coordinated vulnerability handling processes, including monitoring, remediation, and responsible disclosure of security vulnerabilities.
  • Security Updates & Lifecycle Support: Manufacturers are responsible for providing security updates and maintaining cybersecurity throughout the supported lifetime of the product.
  • Technical Documentation & Compliance Evidence: Technical documentation must demonstrate compliance with the CRA, including cybersecurity risk assessments, testing activities, implemented safeguards, and supporting evidence.
  • Product Classification: Depending on the product category, the CRA may require either manufacturer self-assessment or the involvement of a notified body during the conformity assessment process.
  • Conformity Assessment: Before placing a product on the EU market, manufacturers must complete the applicable conformity assessment procedure and issue an EU Declaration of Conformity.
  • CE-Marking: Compliance with the CRA is a prerequisite for CE marking and placing affected products on the European Union market.

Common Challenges

The CRA defines what must be achieved, but not how organizations should implement it. Translating legal requirements into practical engineering processes, security testing activities, and compliance workflows remains a significant challenge – especially when integrating cybersecurity into established development environments.

Implementing cybersecurity measures alone is not sufficient. Organizations must demonstrate compliance through objective evidence, including documented risk assessments, security testing results, technical documentation, and other verifiable records required during conformity assessment.

The CRA introduces a continuous cybersecurity responsibility that extends beyond product release. Manufacturers must monitor vulnerabilities, provide security updates, and respond to emerging threats throughout the supported lifetime of their products while maintaining ongoing compliance.

Related Regulations

  • DIN EN 40000
  • EU New Machinery Regulation
  • prEN 50742
  • RED

Official Resources

FAQ

Does the CRA apply to my product?

The CRA applies to products with digital elements that are placed on the European Union market and whose intended or reasonably foreseeable use includes a direct or indirect data connection. This covers both hardware and software products across consumer and industrial markets.


Who is responsible for CRA compliance?

The primary responsibility lies with the manufacturer. However, importers and distributors also have obligations to ensure that only compliant products are made available on the EU market.


Are software-only products covered by the CRA?

Yes. The CRA applies to both hardware and software products with digital elements. However, standalone SaaS is generally outside the CRA unless it qualifies as a remote data processing solution necessary for the product’s functionality.


What is the difference between default, important and critical products?

The CRA distinguishes between defaultimportant (Class I & II) and critical products. The product classification determines the applicable conformity assessment procedure and whether manufacturer self-assessment is sufficient or a notified body must be involved.


Do I need CE marking under the CRA?

Yes. Products within the scope of the CRA must demonstrate conformity before being placed on the EU market. Compliance with the CRA becomes part of the CE marking process for affected products.


What happens if vulnerabilities are discovered after product release?

Manufacturers must maintain coordinated vulnerability handling processes, provide security updates where necessary, and report actively exploited vulnerabilities and severe incidents according to the CRA requirements.


When does the CRA become applicable?

he CRA entered into force in December 2024. Vulnerability reporting obligations apply earlier, while the majority of cybersecurity requirements become fully applicable from 11 December 2027


How does HydraVision support CRA compliance?

HydraVision supports CRA compliance by automating security validation, generating objective compliance evidence and reports, and providing traceable test results. CRA-related requirements can be mapped to test cases, enabling teams to verify security measures repeatedly across releases, product variants, and development stages.


How is HydraVision deployed?

HydraVision is available both on-premise and as a private-cloud (PaaS) solution, allowing organizations to choose the deployment model that best fits their security and compliance requirements. Its scalable licensing model supports projects ranging from individual products to large development portfolios.


Will HydraVision fit my products and security requirements?

Yes. HydraVision ships with around 100 preconfigured test cases covering common cybersecurity scenarios. They can be reused, adapted, or extended to efficiently validate product-specific security requirements.