Katharina Bisset, Nerds of Law/Netz, Austria: “The Cyber Resilience Act makes cybersecurity a prerequisite for EU market access”
Posted on Jul 24, 2026

“As the Cyber Resilience Act’s initial obligations take effect this September, cybersecurity effectively becomes mandatory for companies in 2026”
Leaders League: What is the purpose of the Cyber Resilience Act?
Katharina Bisset: The Cyber Resilience Act (CRA) is the first horizontal EU regulation to establish essential cybersecurity requirements for products with digital elements. It applies directly in all EU member states and, with specific exceptions, covers products with digital elements. Products with digital elements means a software or hardware product and its remote data-processing solutions, including software or hardware components being placed on the market separately.
Examples are smartphones, smart home gadgets, industrial controllers, apps, software and other connected hardware or data-processing systems. Under the CRA digital products are risk-based classified into the categories of products with digital elements, important products with digital element and critical products with digital elements.
Why is the CRA more than just another cybersecurity regulation?
Because it not only supplements individual security measures but fundamentally changes the approach to digital security in product law. First, the CRA is not a voluntary standard, but a binding market requirement. In the future, products may only be placed on the market in the EU if they comply with its essential cybersecurity obligations. This makes security a prerequisite for market access. Second, the CRA significantly shifts responsibility, as it is no longer just users who are responsible for security, but manufacturers throughout the entire lifecycle of a product.
For whom is the CRA particularly relevant?
For manufacturers, but also for importers, authorized representative and distributors of products with digital elements. Manufacturers bear primary responsibility throughout the entire product lifecycle. Importers and distributors, on the other hand, have no development responsibility, but rather duties of examination and due diligence. Importers verify that products coming from outside the EU meet the cybersecurity standards. Distributors ensure that only compliant products reach users.
What are the key obligations?
Manufacturers are required to implement cybersecurity by design and by default. Additionally, they must perform and document cybersecurity risk assessments. They must demonstrate compliance with the essential cybersecurity obligations through technical documentation and conformity assessment procedures. This is a self-certification for “normal” products with digital elements. They must address and remediate vulnerabilities throughout the support period. In parallel, they must ensure effective vulnerability handling and security updates. They are further required to report actively exploited vulnerabilities and significant incidents.
What does this mean specifically for product development?
Products must be designed according to the principles of “secure by design” and “secure by default.”
Security by Design means that cybersecurity is integrated into the development process from the beginning. Security is therefore not an afterthought, but an integral part of the architecture, design and overall product development. This includes identifying risks early, applying secure coding practices, addressing known vulnerabilities proactively and planning update mechanisms before the product is launched. Security by Default means that a product is delivered in the most secure configuration possible by default. Users do not need to make any additional settings to achieve an adequate level of security. Insecure features are either disabled or can only be enabled in a deliberate and controlled manner. Together, these principles ensure that security does not depend on user competence. It shifts responsibility significantly toward manufacturers.
Prior to placing on the market the technical documentation of cybersecurity is required, also manufacturers must draw up a declaration of conformity and apply an appropriate conformity assessment procedure in accordance with the product’s risk classification. For most products, the conformity assessment may be carried out by the manufacturer through internal control. For products presenting higher cybersecurity risks as important or critical products, stricter conformity assessment procedures apply and, where required, involve a notified body.
What role will the CE marking play in the future in the context of the CRA?
The CE marking plays a central role in the context of the CRA because it will also encompass cybersecurity in the future. The CRA will therefore become another component of the CE conformity assessment procedure. This means that digital products may only be placed on the market in the EU if they meet the obligations of the CRA and bear a CE marking accordingly. The CE marking thus becomes visible proof that a product also complies with cybersecurity requirements.
What obligations apply throughout the entire product lifecycle?
The CRA does not end with CE conformity but requires security updates and vulnerability management throughout the entire support period. This also includes establishing a process for vulnerability management. Manufacturers must specify a clearly defined period during which security updates will be provided for the expected useful life. Within this period, manufacturers bear primary responsibility for the product’s security. In the event of actively exploited vulnerabilities and serious incidents, there is an obligation to report.
When do the new obligations take effect?
Implementation will be phased. From September 11th, 2026, manufacturers will be subject to reporting obligations for certain vulnerabilities to designated authorities, in particular actively exploited vulnerabilities and security incidents with significant impact. These deadlines include an initial report within 24 hours, a follow-up report within 72 hours, and, depending on the case, a subsequent final report. By December 11th, 2026, member states must ensure that sufficient notified bodies are available so that conformity assessments can be carried out, where required. This is particularly important for companies that rely on third-party assessments. As of December 11th, 2027, all CRA obligations must be met.
What are the potential financial penalties for failing to comply with CRA obligations?
It is important not to neglect the obligations, as the fines for violations, depending on the nature of the violation, are quite high. For example, violations of essential obligations, such as reporting obligations, can result in fines of up to €15 million or 2.5 percent of global annual turnover, whichever amount is higher. For less serious violations, the fines can be up to €10 million or 2% of global annual turnover. In addition, the market surveillance authority may prohibit the sale of the digital product. Warnings based on the unfair competition are also possible.
A wide range of legal advisory needs to be given, therefore, ranging from defining the scope of application and structuring contractual liability and recourse arrangements to providing support for conformity and certification processes.
What measures should companies now take?
Companies should start by determining which of their products fall within the scope of the CRA and what role they have in the supply chain, as this affects their obligations. Based on this assessment, they should implement or adapt processes for cybersecurity risk management, technical documentation, conformity assessment procedures, vulnerability handling, security updates and incident reporting. In practice, the CRA affects multiple business areas, including development, quality management, compliance, procurement and sales, requiring an early and interdisciplinary approach.
Sophie Stevenard