The EU Cyber Resilience Act (CRA) makes cybersecurity a prerequisite for access to the EU market, not only for hardware products with digital elements, but also for software placed on the market independently. Its core requirements are far-reaching: conformity assessments, European Conformity (CE) marking, and a duty to supply security updates free of charge throughout a defined support period. For some providers, meeting them might mean rethinking established go-to-market processes and pricing models from the ground up.
This issue is particularly relevant right now: While software and other products with digital elements do not need to comply with these obligations until Dec. 11, 2027, the process required for a first CE conformity assessment may require significant lead time. The requirements also apply to products developed or manufactured before Dec. 11, 2027, if they are placed on the market after that date. In addition, reporting requirements for actively exploited vulnerabilities and severe security incidents have already taken effect.
