What is the EU Cyber Resilience Act (CRA)?
For the first time, manufacturers must prove their products are cyber secure before selling them in Europe, and most don’t yet know they’re in scope
The EU Cyber Resilience Act requires all digital products (including software, loT devices, and industrial hardware) to meet defined cybersecurity standards before they can be placed on the EU market.
The first mandatory obligations come into force in September 2026, with broader requirements following through to December 2027, giving teams a limited window to implement the processes, tooling, and documentation needed to comply.