CRA: new EU requirements for software and connected products

The CRA sets new security requirements for digital products. See whether you may be affected, how to start, and how to track future regulatory changes.

If your company manufactures, imports, or sells software or connected products, the CRA may apply to you. CRA stands for Cyber Resilience Act, an EU regulation on cybersecurity requirements for products with digital elements. It sets security requirements for product development and for handling vulnerabilities, security updates, and incidents after a product has been placed on the market.12

The requirements primarily apply to manufacturers, but importers and distributors also have responsibilities. Two dates are particularly important for most affected companies. Manufacturers must comply with the reporting requirements from 11 September 2026. Most product requirements apply from 11 December 2027.3

Map which products may be covered and your company’s role for each product. This shows which requirements you need to address next.

Find out which products are covered

The CRA applies to products made available on the EU market that are intended to connect to another device or a network. It also applies when such a connection can reasonably be expected, even if the connection is indirect. Hardware, software, and components sold separately may all be covered. Check the specific exclusions before deciding whether the regulation applies to a product.1

Review your role for each product, as the responsibilities differ between manufacturers, importers, and distributors. If you sell a product under your own name or trademark, you may be considered the manufacturer even if someone else developed it.4

For each product, record whether you believe the CRA applies and why, whether you are the manufacturer, importer, or distributor, and which information you used in the assessment. Ask the product owner and someone familiar with the requirements to review the product together. Seek legal advice where you are unsure.

Compare the requirements with how you work today

Once you know which products and roles to address, compare the requirements with your current procedures. Split the review into two parts: reporting from 2026 and product requirements for 2027. Start with reporting because those requirements apply first.

Make sure you can report on time

First, check whether your incident procedure captures the events identified by the CRA. An actively exploited vulnerability is a security flaw that an attacker has exploited without the permission of the system owner. There must be reliable evidence that the flaw has actually been exploited. Manufacturers must report such vulnerabilities. They must also report severe incidents that affect the security of the product. An incident may be severe if it can lead to malicious code being executed in the product or in the user’s IT system.5

The manufacturer reports through a single reporting platform. The report goes to the European Union Agency for Cybersecurity, ENISA, and the national computer security incident response team responsible for the case. An early warning must first be submitted without undue delay and no later than 24 hours after the manufacturer becomes aware of the event. A more detailed notification must normally follow within 72 hours, measured from the same point in time. A final report follows later. Affected users must also be informed.5

Then test whether the procedure works in practice.

If you become aware of a potentially severe incident on a Friday afternoon, someone must be able to assess the information and report it on time when necessary, even if the usual person responsible is away. Decide who may act and who replaces that person. Test the procedure with a product you sell and check that the required product information is available.

Include older products covered by the CRA because the reporting requirements apply to them as well. The other CRA requirements only apply if a product placed on the market before 11 December 2027 is substantially modified from that date.6

Prepare your product work for 2027

Next, compare the product requirements with how you develop, document, and maintain products today. Among other duties, the manufacturer must assess the product’s cybersecurity risks and review components from suppliers. Also check how you plan security updates during the period in which the manufacturer must support the product, known as the support period. This period must reflect how long the product is expected to be in use and must be at least five years, or match the expected use time if that is shorter.2

The manufacturer must also prepare technical documentation and assess whether the product meets the requirements before placing it on the market. Once the requirements are met, the manufacturer must draw up an EU declaration of conformity, a document in which the manufacturer declares that the product complies with the requirements. The product must then carry the CE marking. The assessment procedure depends on the product.2 Ask the product owner to show which requirements you already meet and which will require more time or money.

Track the next change in time

Appoint someone to monitor information from relevant authorities, such as the Swedish National Cyber Security Centre’s guidance on the CRA.7 Decide how often you will review changes. Conduct a new assessment when you develop new products, modify existing products, or change how you sell them.

For each new requirement, document whether it applies to you, what you need to do, who is responsible, and when the work must be complete. Follow up to make sure it gets done. Ask a colleague to test the procedure so that you know the monitoring works even when the person who usually tracks changes is unavailable.

Use your existing information security work

ISO 27001 is a standard for information security management systems, covering how you assign responsibilities, manage risks, and follow up the work. It provides a structure that can help you identify new requirements and include them in ongoing work: determine what applies to you, assess the risks, assign responsibility, implement actions, and follow up the results. Control A.5.31 covers identifying and documenting legal, statutory, regulatory, and contractual requirements and keeping information about them up to date.8

If you already work according to the standard, you can use this structure for the CRA. Check which parts of the organization are included in your information security management system. If product development and maintenance are outside its scope, you must either include them or manage the CRA requirements separately. Select controls based on the risks. For example, an incident procedure may need to be updated with the CRA reporting deadlines.8

The CRA does not require ISO 27001 certification, and certification does not show that a product complies with the CRA. The management system does not replace product work and does not guarantee that you will identify every regulatory change.8

Would you like help with ongoing monitoring? AmpliFlow’s Midi and Maxi packages include legislative monitoring within the agreed areas. You can then use AmpliFlow to assess which requirements apply to you, document how you handle them, assign responsibility, and follow up the work. Learn more about legal and other requirements or book a meeting.

Your company’s obligations must be assessed based on your products and your role. This article provides general information.

Footnotes

  1. Regulation (EU) 2024/2847, Cyber Resilience Act, Articles 2–3. 2

  2. Regulation (EU) 2024/2847, Article 13, in particular Articles 13(2)–13(5), 13(8), and 13(12), Articles 28–32, and Annex I. 2 3

  3. Regulation (EU) 2024/2847, Article 71. Article 14 applies from 11 September 2026 and most of the Regulation from 11 December 2027. Chapter IV applies from 11 June 2026.

  4. Regulation (EU) 2024/2847, Articles 3(13), 3(16)–3(17), and 21–22.

  5. Regulation (EU) 2024/2847, Articles 3(42), 14, and 16. The early warning and detailed notification must be submitted without undue delay and no later than 24 and 72 hours respectively after becoming aware; the detailed notification is not required if the information has already been provided. Unless the information has already been provided, the final vulnerability report must be submitted no later than 14 days after a corrective or risk-mitigating measure becomes available. Unless the information has already been provided, the final incident report must be submitted within one month of the incident notification. Article 14(8) covers affected users and, where appropriate, all users, including information about measures they can take when necessary. 2

  6. Regulation (EU) 2024/2847, Articles 69(2)–69(3).

  7. Swedish National Cyber Security Centre, How the Cyber Resilience Act works (in Swedish). The monitoring procedure in this article is practical advice, not a prescribed review frequency or a guarantee that your company will identify every relevant change.

  8. ISO/IEC 27001:2022, Clauses 4.2–4.3, 5.3, 6.1.3, and 9.3, and Annex A, controls A.5.24–A.5.26 and A.5.31. Annex A is a reference set used in risk treatment, not a list in which every control must always be implemented. See ISO’s ISO/IEC 27001 overview. The CRA’s separate product requirements and conformity assessment procedures are set out in, among other provisions, Articles 13 and 28–32. 2 3

Share this article

LinkedIn

This article is also available in Swedish.

Related articles

Eight AmpliFlow updates from summer 2026

Eight AmpliFlow updates from summer 2026

Migration is included when you switch to AmpliFlow

Migration is included when you switch to AmpliFlow

Quality culture in ISO 9001: what management should prepare

Quality culture in ISO 9001: what management should prepare