Last updated: July 2026
The Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements made available on the European Union market. The regulation covers not only software, but also devices whose intended or reasonably foreseeable use includes a direct or indirect connection to a network or another device.
For electronics manufacturers, this means greater control over the entire product lifecycle: from design and component selection through manufacturing to handling vulnerabilities discovered after the device has been placed on the market.
The first significant obligations will apply from 11 September 2026. From that date, manufacturers will be required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
The CRA covers hardware and software defined as products with digital elements that are made available on the EU market and whose intended or reasonably foreseeable use includes a direct or indirect connection to a device or network. The regulation applies both to end products and to components placed on the market separately.
In practice, this may include controllers, measurement devices, sensors, communication gateways, automation systems and Industrial IoT solutions.
Most CRA requirements will apply from 11 December 2027. Earlier, from 11 September 2026, requirements related to reporting actively exploited vulnerabilities and severe security incidents will apply.
European Commission – Cyber Resilience Act
When a vulnerability is discovered, it is necessary to determine which products and device versions are affected.
Over the course of long-term production, the following may change:
If a problem is discovered several years after production started, the current design documentation may not be sufficient. What also matters is what was actually used in specific production batches of the device.
The CRA requires cybersecurity risk assessment to be taken into account during the planning, design, development, production, delivery and maintenance of a product. This means that product security is not solely the responsibility of software teams.
The CRA applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect connection to another device or network.
In practice, the regulation may apply to:
A device does not have to be permanently connected to the internet. The CRA also refers to direct and indirect logical or physical data connections to other devices and networks.
Yes, if its product is made available on the EU market.
What matters is the market on which the product is offered, not only the location of the company headquarters or manufacturing facility. A manufacturer based outside the EU may therefore be subject to CRA requirements for devices sold on the EU market.
No.
The CRA does not automatically apply to every product containing electronics. Certain products are excluded due to existing sector-specific regulations.
Therefore, the scope of the CRA should be assessed for the specific product and the way it is placed on the market, rather than solely on the basis of the industry in which the manufacturer operates.
European Commission – Cyber Resilience Act: scope, obligations and key information
From 11 September 2026, manufacturers of products with digital elements will be required to report actively exploited vulnerabilities and severe incidents affecting product security. Reports are expected to be handled through the Single Reporting Platform prepared by ENISA.
Preparations should not, however, begin with the reporting process itself. The first step is to ensure access to the information needed to assess the scope of a problem.
The company should know who:
With short reporting deadlines, responsibilities and information flows need to be established in advance.
Information about a component vulnerability is useful only when it is possible to determine which products actually contain that component.
It is therefore worth verifying access to:
For a product manufactured over many years, different production runs may contain different components or configurations. Without version control, it is difficult to determine the actual scope of a problem quickly.
Some of the required data may be held outside the organisation: by the component manufacturer, software supplier or electronics manufacturing partner.
It is worth establishing in advance:
Access to reliable data when a problem occurs is critical.
Responsibility for meeting CRA requirements remains with the manufacturer placing the product on the market under its own name or trademark. Outsourcing production to an external EMS provider does not transfer this responsibility to the contractor.
However, the EMS partner may hold a significant part of the data needed when an issue involving a component or a specific product version is discovered.
This may include:
Long-term electronics manufacturing often involves component EOL, availability issues and the need to introduce alternative components.
If a vulnerability is discovered in a specific module several years later, it becomes important to determine:
when it was used, in which production series and when it was replaced.
For example, a manufacturer may use one communication module for several years. Due to availability issues, part of the production is later switched to an approved alternative. Two years later, a vulnerability is discovered in the original module.
If the change history is linked to production batches or serial numbers, the analysis can be limited to specific devices. Without this data, a much larger number of products already on the market may need to be investigated.
The quality of production data therefore directly affects the ability to determine the scope of a problem quickly.
The CRA increases the importance of processes that are already part of well-managed electronics manufacturing: version control, change documentation and access to production history.
Traceability has long been one of the fundamental elements of electronics manufacturing control. The CRA adds another context: vulnerability management throughout the period in which the product remains in use and is supported by the manufacturer.
It is therefore not enough to know which component appears in the current BOM.
It may also be necessary to determine:
The more accurately production data is linked to specific batches and devices, the faster the actual scope of a problem can be determined.
In practice, an EMS partner can support this process through:
This does not mean that the EMS provider assumes responsibility for product compliance with the CRA. The role of the EMS provider remains to control the manufacturing process and provide access to reliable data on what was actually produced.
For products that remain in operation for many years, traceability, version control and change documentation become elements not only of manufacturing quality, but also of long-term product security management.
The CRA entered into force on 10 December 2024, but its requirements are being introduced in stages.
From 11 September 2026, requirements concerning the reporting of actively exploited vulnerabilities and severe security incidents will apply. Most of the remaining obligations will apply from 11 December 2027.
No. The CRA applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect connection to another device or network.
There are also exclusions for products covered by certain sector-specific regulations. The scope should be assessed for the specific product.
No. The CRA refers to direct and indirect logical or physical data connections to a device or network. A permanent connection to the public internet is therefore not a condition for the regulation to apply.
Responsibility lies with the manufacturer, meaning the entity placing the product with digital elements on the market under its own name or trademark.
Outsourcing production to an external EMS provider does not transfer the manufacturer’s responsibilities under the CRA. The EMS provider may, however, provide production data needed to identify specific components, versions and device batches.
When a vulnerability is discovered, it may be important to determine:
Traceability and change control can significantly reduce the time needed to determine which devices are actually affected by a problem.
This material is provided for informational purposes only and does not constitute legal advice or an interpretation of applicable regulations. The obligations arising from the Cyber Resilience Act should be assessed individually in relation to the specific product and the way it is placed on the market.