The Cyber Resilience Act (CRA) sets European cybersecurity requirements for products with digital elements.

These are not just physical products such as routers, IoT devices and network equipment. The CRA can also cover software.

Many organisations are looking at 11 December 2027, when the general product requirements become fully applicable.

But an important part starts earlier.

As from 11 September 2026, manufacturers will be required to report any active exploitable vulnerabilities and serious security incidents.

For Dutch manufacturers this means that vulnerability management and incident management should be operational already.

What is the Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847 and is also the Cyber-reliability Regulation mentioned.

The European Regulation aims to ensure that products with digital elements:

  • be designed and developed more securely;
  • are placed on the market without any known unacceptable vulnerabilities;
  • be kept safe for their support period;
  • receiving security updates;
  • and that manufacturers deal with vulnerabilities structurally.

Cybersecurity is thus part of the full product life cycle.

Who is the CRA for?

The CRA has obligations for:

  • manufacturers;
  • Importers;
  • distributors.

The manufacturer is in many cases the most difficult obligation.

The Regulation applies to products with digital elements made available on the European market.

What are products with digital elements?

Think of, for example:

  • software;
  • operating systems;
  • mobile apps;
  • IoT equipment;
  • routers;
  • firewalls;
  • network equipment;
  • smart devices;
  • Industrial digital components;
  • other hardware or software that can be directly or indirectly connected to a network or device.

There are exceptions and sector-specific regimes. Therefore, always perform a scope assessment first.

Which product categories does CRA know?

The CRA shall distinguish in general between:

  • regular products;
  • major products class I;
  • major products class II;
  • critical products.

The product category shall also determine the conformity assessment requirements and the extent to which a manufacturer may assess whether a product meets the requirements.

For the current format, use the official CRA documentation and RDI guide.

What requirements does CRA have?

The CRA contains both: Product requirements if process requirements.

Product requirements

A manufacturer must include cybersecurity in design and development. This includes a cybersecurity risk analysis.

Process requirements

After market introduction, responsibility does not end. Manufacturers shall organise processes for:

  • Vulnerability Handling;
  • receiving and investigating vulnerability notifications;
  • security updates;
  • documentation;
  • monitoring;
  • incidents;
  • and reporting where necessary.

That also makes the CRA a Governance and lifecycle issues.

The first major deadline: 11 September 2026

From 11 September 2026 manufacturers shall report when they become aware of:

  • one active exploited vulnerability in a product with digital elements;
  • or a serious incident that has an impact on product security.

For Dutch organisations this notification is made via the NCSC.

The first notification must be made according to the NCSC without undue delay and within 24 hours of discovery take place.

This raises a practical question:

Can your organisation recognise, assess, escalate internally within 24 hours and report that a vulnerability is actively exploited?

What do you need to have arranged before the notification?

Minimum:

  1. Scope . Which products are likely to be covered by CRA?
  2. Product ownership . Who is responsible for cybersecurity during the product life cycle?
  3. Vulnerability intake . Where can researchers, customers and suppliers report problems?
  4. Assessment . Who determines severity, impact and operating status?
  5. Escalation . When are boards and executive management and legal functions involved?
  6. Reporting process . Who can report on behalf of the organisation within the legal deadline?
  7. Customer communication . How are affected users informed?
  8. Security updates . How is an update quickly developed, tested and distributed?
  9. File formation . What decisions, risk analyses, fixes and communication are recorded?

The full CRA as from 11 December 2027

From 11 December 2027 the general CRA requirements shall be fully applicable.

From that point on, products with digital elements falling within scope and offered on the EU market should meet the relevant essential cybersecurity requirements.

For manufacturers with long design and development cycles, 2027 is close. A product that will be on the market in 2027 may be being designed today.

Security by design must therefore be in the development process before the deadline.

The CRA goes beyond a pen test for release

A single pen test just before market introduction is not a complete version of the CRA.

Also read how security by design security from design to management is part of the process.

Cybersecurity shall be part of:

  • requirements;
  • architecture;
  • secure development;
  • risk analysis;
  • testing;
  • release and change management;
  • component and dependency management;
  • Vulnerability management;
  • update processes;
  • Lifecycle management.

The product should not only be developed safely. It should be safe to be kept safe.

Vulnerability management becomes a product responsibility

The notification obligation from September 2026 makes this concrete.

A manufacturer shall know:

  • which versions of products are in use;
  • the components and dependencies contained therein;
  • the vulnerabilities that are relevant;
  • or operating;
  • which customers may be affected;
  • which update should be made available;
  • how quickly this can be communicated.

This directly affects CRA vulnerability management.

CRA and NIS2/Dutch Cybersecurity Act: What's the difference?

Dutch Cybersecurity Act / NIS2

Focus on the Digital resilience of organisations and services which fall within the legal sectors and criteria.

Cyber Resilience Act

Focus on the cybersecurity of products with digital elements which are made available on the European market.

A manufacturer may have to deal with both boxes. One obligation does not automatically replace the other. Read the practical explanation about the Dutch Cybersecurity Act and NIS2.

One Cbw training for board members assists in board-level responsibility under the Dutch Cybersecurity Act. For an open discussion on risks, responsibilities and priorities, a boardroom cyber session be appropriate. Both do not replace separate CRA scope and product compliance assessments.

CRA and supplier chains

Organisations that are not manufacturers themselves are also indirectly affected by CRA.

For buyers and supplier management questions become more relevant such as:

  • How long does the product receive security updates?
  • how does the supplier report vulnerabilities?
  • how quickly critical fixes are released?
  • Which versions are supported?
  • how is end-of-life communicated?
  • which components of third parties are incorporated into the product?

A practical CRA roadmap

Step 1 — Define Scope

Map products, roles and markets.

Step 2 — GAP Analysis

Compare existing product security processes with CRA requirements.

Step 3. — Capture Governance

Assign product security ownership, responsibilities and escalation routes.

Step 4. — Integrate Security by Design

Record security in requirements, development, testing and release decisions.

Step 5. — Set up Vulnerability Management

Provide intake, analysis, prioritisation, updates and monitoring.

Step 6 . . Practice the reporting process

Test whether an active exploited vulnerability can be effectively assessed and reported within the required time limit.

Step 7. — Organise evidence

Identify risk analyses, test results, decisions, vulnerabilities, fixes and communication.

Five questions for management and product management

  1. Do we know which of our products may be covered by the CRA?
  2. Who owns cybersecurity during the product life cycle?
  3. Can we identify, assess and escalate an active exploitable vulnerability within 24 hours?
  4. Can we demonstrate how security has been incorporated into design, development, testing and maintenance?
  5. Are we in time for the full requirements from December 11, 2027?

When these answers are not yet available, it is 2027 not the starting point. The preparation should begin now.

Summary

The Cyber Resilience Act makes cybersecurity an explicit product responsibility.

The most important dates are:

  • 11 September 2026: reporting obligations for active exploitable vulnerabilities and serious security incidents;
  • 11 December 2027: general CRA requirements fully applicable.

For manufacturers, this means that vulnerability management, incident management and product security must already be operationally set up.

A safe product is not only safe under the CRA on the day of delivery. It shall be reliably designed, maintained and supported throughout its life cycle.

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View NCSC - Cyber Resilience ActView State Inspection Digital Infrastructure - Cyber Resilience ActView EUR-Lex - Regulation (EU) 2024/2847
CRA ExploratoryDo you know what the CRA means specifically for your products?

Kynexis helps to translate digital risks, governance, product processes and vulnerabilities management into a practical improvement plan.

Discuss a CRA/GAP exploration