CRA

The EU's Cyber Resilience Act for products with digital elements

The Cyber Resilience Act sets security requirements for products with digital elements sold in the EU, hardware and software alike. It's the next regulatory wave after NIS2, phasing in through 2027, and it reaches product companies that NIS2 never touched.

Who it applies to

Manufacturers, importers, and distributors of products with digital elements sold in the EU: connected devices, software products, and components. If your product runs code and is sold in the EU, assume you're in scope until the gap analysis says otherwise.

What OptiTech provides

  • Product scoping: which of your products are covered, and whether they fall into a critical class with stricter conformity requirements
  • Security requirements as controls: secure-by-default configuration, update mechanisms, and vulnerability handling as verifiable checks
  • Vulnerability handling process: coordinated disclosure, reporting duties, and patching timelines with deadline tracking
  • Conformity documentation: the technical file and declaration drafted from your product data
  • Timeline tracking: obligations activate as the phase-in dates arrive

Sanctions

Up to 15 million euros or 2.5 percent of global revenue, plus the ability for market surveillance authorities to pull non-compliant products from the EU market.

Cross-mapping

CRA's organizational requirements overlap with NIS2 and ISO 27001. Product companies with either in place start CRA from a working foundation.

Get started

CRA is available on every plan. Book a free gap analysis to scope your products, or compare plans.

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?

On this page

Copy neon init command