Cyber Resilience Act (CRA)
European Union Product Cybersecurity Regulation
The Cyber Resilience Act (CRA) establishes a harmonized cybersecurity framework for products with digital elements placed on the European Union market. It introduces mandatory requirements covering secure product design, cybersecurity risk management, vulnerability handling, security updates, and post-market obligations throughout the product lifecycle. Manufacturers must not only implement appropriate cybersecurity measures but also demonstrate compliance through technical documentation and objective evidence. As a prerequisite for CE marking of affected products, the CRA raises the importance of repeatable security engineering practices and evidence-based cybersecurity validation across the entire product lifecycle.
Jurisdiction: European Union
Type: Regulation
Scope: Products with digital elements
Status: In force, fully applicable 12/27
Who is affected?

Manufacturers

IoT Products

Software Vendors

Automotive Suppliers

Industrial Equipment

Importers, Distributors
* if your product connects, processes, transmits or stores data, it is likely falling within scope
Key Requirements
- Secure by Design & by Default: Products must be designed with cybersecurity as a core engineering principle. Appropriate security controls should be integrated throughout development and enabled by default.
- Cybersecurity Risk Assessment: Manufacturers are required to identify, assess, and mitigate cybersecurity risks throughout the product lifecycle, considering both intended use and reasonably foreseeable misuse.
- Security Validation & Testing: Appropriate security verification activities must be performed to demonstrate that implemented security measures effectively address identified risks.
- Vulnerability Handling: Organizations must establish coordinated vulnerability handling processes, including monitoring, remediation, and responsible disclosure of security vulnerabilities.
- Security Updates & Lifecycle Support: Manufacturers are responsible for providing security updates and maintaining cybersecurity throughout the supported lifetime of the product.
- Technical Documentation & Compliance Evidence: Technical documentation must demonstrate compliance with the CRA, including cybersecurity risk assessments, testing activities, implemented safeguards, and supporting evidence.
- Product Classification: Depending on the product category, the CRA may require either manufacturer self-assessment or the involvement of a notified body during the conformity assessment process.
- Conformity Assessment: Before placing a product on the EU market, manufacturers must complete the applicable conformity assessment procedure and issue an EU Declaration of Conformity.
- CE-Marking: Compliance with the CRA is a prerequisite for CE marking and placing affected products on the European Union market.
Common Challenges
Adapting Regulatory Requirements

The CRA defines what must be achieved, but not how organizations should implement it. Translating legal requirements into practical engineering processes, security testing activities, and compliance workflows remains a significant challenge – especially when integrating cybersecurity into established development environments.
Generating Compliance Evidence

Implementing cybersecurity measures alone is not sufficient. Organizations must demonstrate compliance through objective evidence, including documented risk assessments, security testing results, technical documentation, and other verifiable records required during conformity assessment.
Managing Lifecycle Cybersecurity

The CRA introduces a continuous cybersecurity responsibility that extends beyond product release. Manufacturers must monitor vulnerabilities, provide security updates, and respond to emerging threats throughout the supported lifetime of their products while maintaining ongoing compliance.
Typical Compliance Process
A. Define Product Scope

Determine whether your products fall within the CRA’s scope and identify the applicable product classification. This defines the regulatory obligations and conformity assessment route.
Our seasoned cybersecurity experts support product classification, CRA applicability assessments, and the definition of an efficient compliance strategy.
B. Assess Readiness

Perform a gap analysis to identify missing processes, security controls, and documentation. Use the findings to define your implementation roadmap and cybersecurity strategy.
Start faster with 100+ test case templates mapped to common regulations and technologies, providing an efficient entry point for compliance activities.
C. Validate Security Controls

Verify that implemented security measures effectively mitigate identified cybersecurity risks. Perform repeatable security testing to demonstrate the effectiveness of technical safeguards.
Automate security testing across ECUs & embedded systems. HydraVision generates scalable, traceable test results while significantly reducing manual testing effort.
D. Document Compliance

Prepare technical documentation and collect objective evidence demonstrating compliance with the CRA. Ensure testing activities and implemented safeguards are fully documented.
Automatically generate customizable reports and objective compliance evidence for different stakeholders. AI-assisted reporting reduces effort and speeds up communication across development teams.
E. Complete Market Approval

Complete the applicable conformity assessment procedure and prepare the EU Declaration of Conformity. Apply CE marking before placing products on the European Union market.
Reduce time-to-market by reusing validated security test cases across your whole product portfolio. Our generic test case approach enables organizations to validate multiple products using the same testing methodology.
F. Maintain Product Security

Monitor vulnerabilities, validate security updates, and maintain cybersecurity throughout the supported product lifetime. Continuously verify the effectiveness of implemented security measures.
Continuously validate security updates and regression tests throughout the supported product lifetime. HydraVision helps organizations maintain cybersecurity as products, vulnerabilities, and regulations evolve.

HydraVision is a cybersecurity automation platform that enables organizations to integrate continuous security validation throughout the entire lifecycle of connected products. Combining a centralized security test platform, automated security testing, reusable test case templates, AI-assisted reporting, and Agentic Engineering, it transforms cybersecurity requirements into repeatable engineering workflows.
Manufacturers gain complete transparency into the cybersecurity status of their connected products, enabling confident market approval, informed release decisions, and continuous security validation throughout the product lifecycle.
Related Regulations
- DIN EN 40000
- EU New Machinery Regulation
- prEN 50742
- RED
Official Resources
FAQ
Does the CRA apply to my product?
The CRA applies to products with digital elements that are placed on the European Union market and whose intended or reasonably foreseeable use includes a direct or indirect data connection. This covers both hardware and software products across consumer and industrial markets.
Who is responsible for CRA compliance?
The primary responsibility lies with the manufacturer. However, importers and distributors also have obligations to ensure that only compliant products are made available on the EU market.
Are software-only products covered by the CRA?
Yes. The CRA applies to both hardware and software products with digital elements. However, standalone SaaS is generally outside the CRA unless it qualifies as a remote data processing solution necessary for the product’s functionality.
What is the difference between default, important and critical products?
The CRA distinguishes between default, important (Class I & II) and critical products. The product classification determines the applicable conformity assessment procedure and whether manufacturer self-assessment is sufficient or a notified body must be involved.
Do I need CE marking under the CRA?
Yes. Products within the scope of the CRA must demonstrate conformity before being placed on the EU market. Compliance with the CRA becomes part of the CE marking process for affected products.
What happens if vulnerabilities are discovered after product release?
Manufacturers must maintain coordinated vulnerability handling processes, provide security updates where necessary, and report actively exploited vulnerabilities and severe incidents according to the CRA requirements.
When does the CRA become applicable?
he CRA entered into force in December 2024. Vulnerability reporting obligations apply earlier, while the majority of cybersecurity requirements become fully applicable from 11 December 2027
How does HydraVision support CRA compliance?
HydraVision supports CRA compliance by automating security validation, generating objective compliance evidence and reports, and providing traceable test results. CRA-related requirements can be mapped to test cases, enabling teams to verify security measures repeatedly across releases, product variants, and development stages.
How is HydraVision deployed?
HydraVision is available both on-premise and as a private-cloud (PaaS) solution, allowing organizations to choose the deployment model that best fits their security and compliance requirements. Its scalable licensing model supports projects ranging from individual products to large development portfolios.
Will HydraVision fit my products and security requirements?
Yes. HydraVision ships with around 100 preconfigured test cases covering common cybersecurity scenarios. They can be reused, adapted, or extended to efficiently validate product-specific security requirements.


