The Cyber Resilience Act (CRA) is a new EU regulation that sets cybersecurity-requirements for companies that produce, import, or distribute products with digital elements. While cybersecurity was previously often handled reactively, the CRA establishes a new starting point: Security must be integrated from the beginning and maintained throughout the product’s entire lifecycle (typically 5 years).
The Cyber Resilience Act (CRA) aims to ensure that hardware and software products are resilient to cyber threats. This applies from the early design phase and all the way through the product’s lifespan. For many organisations, this is an extensive transformation that requires time, structured processes, and the right competencies.
Although the final deadline is not until December 2027, there are multiple reasons to act now. First of all, the obligation to report actively exploited vulnerabilities and incidents takes effect earlier from 11. September 2026. Secondly, companies that lay out a compliance strategy will have a greater chance of achieving funds from the EU-compliance project, SECURE.
Investing in CRA compliance is a must-have, as the financial consequences of non-compliance are significant. The regulation defines two levels of administrative fines:
- Fines of up to EUR 15 million or 2.5% of global annual turnover for the most serious breaches of the essential cybersecurity requirements.
- Fines of up to EUR 10 million or 2% of global annual turnover for other failures related to obligations and documentation.
Beyond financial consequences, companies also risk losing market access. Products that are not correctly CE marked and do not demonstrate verified compliance may not be placed on the EU market after December 2027.

What companies are subject to the CRA?
The regulation applies to all products with a digital component, ranging from small components and IoT devices to complex systems.
A core principle of the CRA is that responsibility is not placed solely on the manufacturer, but shared across the entire supply chain.
- Manufacturers must be able to demonstrate that security is integrated by design and by default. This includes maintaining a software bill of materials (SBOM) to keep track off all third-party components and having processes for vulnerability management in place (to name a few).
- Importers are responsible for ensuring that products from third countries meet the same requirements.
- Distributors must verify that products are correctly CE marked and accompanied by the required documentation before they are placed on the market.
The CRA imposes not only technical requirements, but also organisational requirements related to governance, documentation, and collaboration between the involved actors. However, the workload required to fulfil the technical and organisational requirements depends on the status of the company.

Unsure about your CRA obligations? Navigating the complexities of the CRA can be challenging. At Devoteam, we have developed a specialised CRA Readiness Assessment platform designed to provide clarity fast. We help you identify your specific legal role (Manufacturer, Importer, or Distributor), determine if your products are covered, and estimate the workload required to ensure full compliance before the December 2027 deadline.
Risk categories: Good news for many SME’s
The regulation adopts a risk-based approach, under which products are categorised according to their relevance to cybersecurity.
- Default category (low risk): Most products (approx. 90%) fall into this category. This includes, e.g. smart consumer devices, games, software, and standard IoT gadgets. The good news for SMEs is that for these products, you can perform a “Self-Assessment”. You do not necessarily need an external auditor to approve the product, provided you document that you follow the harmonised standards.
- Important & critical categories (class I & II): Products with a higher risk profile, such as network interfaces, identity management systems, industrial firewalls, and operating systems. These are subject to stricter requirements and will often require assessment by a third-party “Notified Body”.
This means that companies must have a clear understanding of which product categories they operate with. In practice, this is often a complex task that requires both technical and regulatory expertise.
The EU recognises that the new requirements are challenging for small and medium-sized enterprises (SMEs). To help companies adapt, the EU-funded project SECURE (Cyber Resilience for SMEs) offers financial support. Businesses can apply for grants of up to EUR 30,000, covering 50% of approved costs, such as product classification, employee training, and support with documentation. Companies can already apply in january 2026.
Devoteam helps SMEs apply for EU funding to ensure compliance with CRA regulations.
What should my organisation do now?
Devoteam strongly recommends the following actions to be taken by companies that manufacture, import and/or distribute hardware and/or software in the EU to ensure compliance before September 2026 and December 2027.
1. Define your company role: First and foremost, determine your legal role under the CRA: Are your company a Manufacturer, Importer, or Distributor? Be aware that many companies act as multiple entities simultaneously. For instance, if you manufacture your own software but also import hardware from outside the EU to sell under your brand, you must comply with the responsibilities of both a Manufacturer and an Importer.
2. Apply for EU SME funding: The EU offers grants to help SMEs cover the costs of becoming compliant with the CRA. Applying early ensures you get financial support for the transition.
3. Review your product pipeline: Assess products currently in development that are scheduled to launch after December 2027. You must integrate CRA requirements into the development phase now. If these products are not developed according to CRA standards from the start, they cannot legally be placed on the EU market when the regulation is fully enforced, potentially wasting years of R&D efforts.
4. Classify your product portfolio: Map your existing and upcoming products to the CRA risk categories (Default, Class I, or Class II). This is a critical step to determine the compliance activities needed.
5. Prepare for early reporting (2026): While full compliance is due in 2027, establish your incident reporting processes as a priority. By September 11, 2026, you must be ready to report actively exploited vulnerabilities and severe incidents to authorities within 24 hours.
Conclusion
Overall, the Cyber Resilience Act marks a clear shift in how digital products are regulated in the EU. Cybersecurity is no longer a matter of best practice or voluntary standards, but a fundamental requirement for market access. For companies, this means that cybersecurity is increasingly becoming an integral part of product development, business strategy, and collaboration across the value chain. Companies that begin their efforts early are better positioned to both comply with the regulation and meet the expectations of customers, partners, regulators and to receive funding from SECURE. In this sense, the CRA is not only about compliance, but about building more resilient digital products in a market where trust and security are becoming increasingly important.
The full regulation, along with guidance on available support, can be found in the EU’s official documentation on the Cyber Resilience Act.
Secure AI, Sustainable Value: Your CISO’s Guide to AI Risk Management

Get your free Whitepaper if you want to:
- Learn to identify and manage unique AI security challenges
- Implement Devoteam’s AI Cyber Trust Cube – our framework for trusted and secure AI deployments
- Align AI with your organisation’s sustainability goals
- Gain insights from Devoteam’s leading AI security experts.
