On October 23, the EU Parliament and Council signed the final text of the new Cyber Resilience Act (CRA), which aims to strengthen cybersecurity for what the CRA defines as “products with digital elements.” These are essentially products that include hardware or software, interconnected or connected to a network, and are used to process data remotely (i.e., Internet of Things).
This includes mobile apps, wearables, smart cars, and other “smart” products, and may extend to cloud systems connected to these products if they provide essential functionalities for the device or distributed software. Similar to the GDPR and the upcoming Artificial Intelligence Act, the CRA applies to any product with digital elements marketed within the European market, regardless of where it is manufactured—meaning non-European operators are also covered.
The CRA’s objective is to increase the protection of digital devices and networks against increasingly recurrent and sophisticated cyberattacks by requiring manufacturers to meet a set of security requirements before marketing a product. These requirements include conducting a technical risk analysis, documenting management, support, and vulnerability and incident reporting processes, as well as informing users about technical characteristics and product usage instructions.
Additionally, the CRA extends these obligations across the entire supply chain (i.e., importers and distributors), ensuring that, throughout the product’s lifecycle, sufficient security updates are offered to counter cyber threats and that users gain a better understanding of the “digital” risks associated with using the product. CRA compliance will require these hardware and software products to bear the “CE” marking as evidence of high security standards. Therefore, it becomes essential to have a full understanding of everything a product with digital elements entails—not only proprietary software but also open-source components used and their maturity and risk profile.
Some exceptions include products whose specific regulatory framework already demands high security levels, such as medical, aeronautical, and automotive products, or open-source software technologies that are not directly monetized by their developers. However, open-source components are covered if incorporated into a commercial product, and it will be the responsibility of the product manufacturer and/or distributor to ensure compliance for these components.
In the coming weeks, the CRA will be published in the Official Journal of the EU (OJ) and will come into effect 20 days after publication. However, full material application will not occur until 36 months post-publication. Nevertheless, certain obligations related to vulnerability notifications by manufacturers will apply within 21 months, allowing for coordinated management and disclosure between CSIRT and ENISA.
Finally, it is worth noting that the CRA introduces a sanctioning regime for non-compliance, with penalties reaching up to EUR 5,000,000 (or, if the offender is a company, up to 1% of the total annual turnover) for non-compliance with information and notification requirements, and up to EUR 15,000,000 (or, if the offender is a company, up to 2.5% of the total annual turnover) for obligations related to essential cybersecurity requirements specified in Annex I of the CRA.
At Across Legal, we have participated in conferences on the CRA and are already advising our clients on compliance with this new regulation. Although the application deadlines may seem distant, the design and development cycle of digital technologies can be lengthy, making it crucial to integrate “security by design” from the outset, in the same way that the GDPR mandates “privacy by design.”




