THINK SAFE. THINK ICS.

The Cyber Resilience Act Explained: Am I Affected? What Are the Rules, and What Should I Do?

The Cyber Resilience Act (CRA) is an EU regulation on the cybersecurity of digital products with hardware and software functionality. The goal is to ensure that products are developed, documented, and operated “secure by design” in the future.

The Cyber Resilience Act requires manufacturers to:

ics_gmbh_explain_eu_cra
Systematically Analyze Cyber Risks
Address Vulnerabilities
Ensure the safety of products throughout their entire life cycle
 Demonstrate compliance 
shadow_video

What is the Cyber Resilience Act?

The Cyber Resilience Act is a European regulation designed to improve the cybersecurity of digital products. In the future, manufacturers must ensure that their products are protected against cyber risks from the development stage through their entire lifecycle.

This includes, among other things:

  • Secure development of digital products
  • Systematic assessment of cyber risks
  • Addressing and documenting vulnerabilities
  • Provision of security updates

The CRA is thus shifting a greater focus on cybersecurity toward product development and product responsibility.

Does my product fall under the Cyber Resilience Act?

The Cyber Resilience Act generally applies to products with digital elements. This includes products that contain software, process data, or are connected to networks.

Typical examples include:

  • Devices with software or embedded systems
  • Software products and applications
  • Machines or devices with digital controls
  • IoT products or networked systems
  • Products with cloud or remote connectivity

In addition to manufacturers, other companies in the supply chain may also be affected, such as:

  • OEMs
  • Suppliers
  • Distributors
  • Importers or integrators

To which products does the CRA not apply?

Clear distinction: These products and areas are not covered by the Cyber Resilience Act, with important caveats regarding the details.

The following are excluded from the scope of the CRA:

  • Medical devices under Regulation (EU) 2017/745
  • In vitro diagnostic medical devices under Regulation (EU) 2017/746
  • Motor vehicles under Regulation (EU) 2019/2144
  • Civil aviation pursuant to Regulation (EU) 2018/1139
  • Marine equipment under Directive 2014/90/EU
  • Products intended exclusively for military or intelligence purposes

Important Note Regarding Ship Equipment:

Not all equipment on ships is automatically exempt. The exemption applies only to equipment covered by Directive 2014/90/EU. The decisive factor here is an exhaustive list in Implementing Regulation (EU) 2025/1533. This includes, among other things:

  • Life-saving equipment
  • Fire protection equipment
  • Navigation and radio equipment
  • Equipment for the prevention of marine pollution

Equipment not included in this list (e.g., certain propulsion systems) is not covered by the exception and is therefore subject to the CRA.

Other exceptions:

  • Replacement parts that substitute identical components meeting the same specifications
  • Products that were already provided before the CRA took effect
    (Reporting requirements may still apply)

Which products are considered “important” or “critical”

The Cyber Resilience Act distinguishes between different categories of products with digital elements. The rationale is that certain products may pose a higher risk to security, the economy, or society. Among other things, the regulation distinguishes between:

CRA Readiness Check - Clarity in 30 Minutes!

Book a free, no-obligation consultation with our CRA experts now. In 30 minutes, we’ll clarify:

  • Which requirements apply to your products

  • How our gap analysis provides quick clarity

  • What your next steps will be

Common Questions from Real-World Situations

Is a method like STRIDE sufficient for risk analysis?

No. What matters is not the method, but whether risks are fully identified within the specific system context.

Is ISO 27001 sufficient for CRA implementation?

No. For products, standards such as IEC 62443 are much closer to the requirements.

Do products without a network connection fall under the CRA?

Other interfaces, such as USB or Bluetooth, may also be relevant. The key factor is whether data can be transferred.

How is the system context taken into account in the first place?

Risks often do not arise from the product itself, but rather from interfaces, dependencies, and usage.

Why the Cyber Resilience Act Is a Challenge for Businesses

The Cyber Resilience Act does not merely address individual security functions of a product. The regulation requires a structured assessment of the entire system, including interfaces, dependencies, and potential vulnerabilities.

Blue Line

Among other things, companies must determine:

  • What are the system boundaries of a product?
  • What cyber risks does the system face?
  • Which vulnerabilities are accessible or exploitable?
  • How are security measures documented?
  • How is the conformity assessment prepared?
Implementation can quickly become challenging, especially with complex or networked products.

How Companies Can Implement the Cyber Resilience Act

Implementing the Cyber Resilience Act is rarely a one-time project, but rather a step-by-step process that is guided by the product, the organization, and existing evidence.

Typical steps include:

  1. Assess impact and product classification
  2. Conduct a risk analysis for the product
  3. Integrating security measures into development and operations
  4. Establish vulnerability management
  5. Prepare technical documentation and conduct a conformity assessment

A structured approach helps companies efficiently implement the requirements.

Why the Cyber Resilience Act Affects the Entire Product Lifecycle

The Cyber Resilience Act does not view cybersecurity as a one-time task during product development. Instead, the regulation requires that security risks be taken into account throughout a product’s entire lifecycle.

This includes, among other things:

  • secure development of digital products
  • cyber risk assessment
  • Addressing vulnerabilities
  • provision of security updates
  • Continuous monitoring of the security situation

This lifecycle approach is designed to ensure that products remain protected against cyber riskseven after they are launched on the market.

Which Companies in the Supply Chain Are Affected by the CRA

The Cyber Resilience Act is not limited to manufacturers. Other companies along the supply chain may also be affected by its requirements.

These include, for example:

  • Manufacturers of digital products
  • OEMs and system integrators
  • Software or component suppliers
  • Distributors and retailers
  • Importers who bring products to the European market

As a result, companies often need to work together to clarify who is responsible for what aspects of cybersecurity and how security requirements are implemented throughout the supply chain.

The Role of CE Conformity Assessment

The Cyber Resilience Act will become part of the European CE conformity assessment for products with digital elements. Manufacturers must therefore be able to demonstrate that their products meet the security requirements of the regulation.

These include, among other things:

  • a traceable risk analysis
  • technical documentation on security measures
  • processes for addressing vulnerabilities
  • security updates throughout the product lifecycle

For many companies, this means that cybersecurity will becomean integral part of product development and product documentationin the future .

Frequently Asked Questions About CRA Implementation

Do I have to disclose my risk analysis to clients?

Not necessarily required by the CRA, but often due to contractual requirements.

How do I handle multiple products?

Products with a common basis can be considered as a group. Differences must be evaluated separately.

When should I start?

As early as possible. The risk analysis serves as the foundation. Changes to the product require lead time.

Support for Implementing the Cyber Resilience Act

Not sure where to start with the CRA? We help you assess your products, identify gaps and risks, and turn the requirements into concrete next steps.

Questions from Real-World CRA Projects

What requirements apply to service providers who only install updates?

That depends on the specific case. Depending on the role, responsibilities, and terms of the contract, a service provider may assume some of the manufacturer's liability. The key factors are who makes changes to the product and under whose name those changes are made available.

What is considered a replacement part under the CRA?

A replacement part restores the product to its original condition. As soon as changes are made to the software or functionality, it is no longer considered a simple replacement part, but rather a relevant change as defined by the CRA.

Which is more important: the time of use or the time of provision?

The key factor is when a product is made available on the EU market. Products that were made available before the effective date are not subject to the CRA unless changes are made to them afterward.

Does the scope (intended use) need to be defined?

Yes. The manufacturer must specify the intended use of the product and the conditions under which it will be used. This context forms the basis for the risk analysis.

FAQ

Does the CRA apply to us even though we are not a traditional IT company?

Yes, very likely. The CRA applies not only to software companies—but to all manufacturers, importers, and distributors of “products with digital elements.” These include, for example, machines with embedded software, IoT devices, networked control units, and digital medical devices. The key factor is whether your product can be connected to the internet or contains software that processes data.

What exactly is a “product with digital elements” according to the CRA?

A product with hardware or software components that is directly or indirectly connected to other devices or networks.
The CRA distinguishes between:

  • Software (e.g., applications, operating systems, apps, middleware)

  • Hardware with digital functionality (e.g., sensors, control units, networked machines)
    Even open-source components may be affected if they are provided commercially.

Do we also have to adapt existing products to comply with CRA—or does this only apply to new developments?

In general, the CRA applies only to products introduced to the market after it takes effect.
HOWEVER: If an existing product undergoes significant changes or further development (e.g., through major software updates), the CRA may apply retroactively. In addition, the obligation to provide updates also applies to products that have already been shipped throughout their planned service life.

How does the CRA differ from NIS2 or the IT Security Act 2.0?

CRA = Product Safety. NIS2 = Operational Safety.

  • CRA applies to manufacturers, importers, and distributors of digital products.

  • NIS2 applies to operators of “critical infrastructure” (e.g., energy, healthcare, transportation), i.e., the IT/OT systems in operation.
    The goal of both laws is cyber resilience, but at different levels and with different obligations.

Learn more about NIS2 and our services

What specific responsibilities do developers and product managers have?

The following CRA obligations directly affect product teams:

  • Conducting a risk analysis prior to market launch

  • Integrating security by design and by default

  • Establishing a vulnerability management system

  • Creating and maintaining technical documentation

  • Preparing for a potential conformity assessment (e.g., CE)

What exactly does “security by design” mean—and how can we implement it?

"Security by Design" means that security is an integral part of the product development process from the very beginning—not just at the end.
In practice, this means:

  • Threat modeling (e.g., attack tree)

  • Risk-based architectural decisions

  • Documentation of protective measures

  • Continuous testing and vulnerability management
    Tools such as VISCURITY systematically support this process.

Specifically, what documents and supporting evidence does the CRA require?

The following are required, at a minimum:

  • a risk assessment of the product

  • a threat analysis

  • technical documentation of the protective measures

  • a description of the vulnerability management process

  • if applicable, test results, test certificates, or external audits. VISCURITY automatically documents this evidence in a traceable manner.

CRA Risk Analysis in Practice: How Products Are Assessed Throughout Their Lifecycle

How can CRA risk analyses be automated across the entire product lifecycle? Insights into digital twins, attack trees, and VISCURITY case studies.

READ THE ARTICLE

CRA Vulnerability Assessment & Exploitability Explained

When Is a Vulnerability in the CRA Exploitable? Why Product Context, Operational Environment, and Real-World Attack Vectors Are Critical for Risk Analysis.



READ THE ARTICLE

CRA or IEC 62443—which standard applies to which product and when?

Does your product fall under CRA, IEC 62443, or both? Find out quickly and easily with our questionnaire and concrete examples.



READ THE ARTICLE

Recent Posts

Book a consultation now!

During the initial consultation, we’ll determine whether CRA, IEC 62443, or both apply to you, and whether a GAP analysis or our Basic Implementation Package is the right place to start. We’ll show you live how VISCURITY accelerates your implementation.