How Ignoring the CRA Could Cost You More Than €15 Million
Fines of up to €15 million, or 2.5% of global annual turnover, have made the EU Cyber Resilience Act one of the most talked-about regulations facing connected product manufacturers.
The number gets attention for good reason. It represents one of the toughest enforcement regimes the industry has seen.
But it is not the risk most leadership teams should be focused on.
Ask Patricia, CEO and Co-Founder of Cyber Cert Labs, what concerns her most for connected product manufacturers, and fines are far from the top of the list.
“I’d be worried about my brand. I’d be worried about how it’s perceived in the market. I’d be worried about my reputation if my products were deemed insecure. I’d be worried about trust, trust with the consumer and trust in my brand.”
Lost procurement opportunities, damaged customer trust, weakened market position, and products that can no longer compete are likely to have a far greater impact on revenue than any financial penalty.
The CRA Makes Cybersecurity a Product Safety Issue

Patricia Shields – CEO Cyber Cert Labs
Patricia often describes the CRA as the ‘CE mark for cybersecurity’, reflecting its role in bringing cybersecurity into the same regulatory framework as product safety.
For years, cybersecurity has largely been treated as a technical discipline. Organisations invested in it according to risk appetite, customer requirements, or internal priorities. Product security was important, but there was significant flexibility in how manufacturers approached it.
The CRA changes that.
By linking cybersecurity to the EU’s New Legislative Framework, cybersecurity now sits alongside traditional product safety requirements.
“It’s being coupled with the New Legislative Framework, which means that it’s very much in the product safety, health and safety space.”
Manufacturers already understand what happens when a product creates physical harm. Product safety failures create liability, reputational damage, recalls, and regulatory scrutiny.
The CRA applies similar thinking to cybersecurity.
“If the product is not secure and causes harm, if there’s a vulnerability in the product and somebody is a victim of an attack due to that vulnerability, they can legally have recourse to sue the manufacturer, just like you would if you bought an electrical appliance and you got electrocuted.”
For leadership teams, this represents a new reality. Cybersecurity is no longer simply an engineering concern or a technical investment decision. It is becoming a core requirement for bringing connected products to market.
Patricia believes manufacturers who continue to treat cybersecurity as optional will quickly find themselves struggling to compete.
“Cybersecurity and securing digital products is no longer something that’s optional. It’s actually foundational.”
Responsibility for product security is moving back to manufacturers, customers increasingly expect secure products by default, and regulators increasingly expect secure products by design. The CRA formalises those expectations.
The Costs That Arrive Before CRA Fines
The €15 million penalty dominates headlines because it is easy to quantify. However, the commercial consequences are harder to measure, but often much more significant.
Trust Becomes A Competitive Asset
Most CEOs understand the value of brand trust.
The challenge is that trust can take years to build and a single security incident to undermine.
Customers are far more aware of cybersecurity than they were even a few years ago. Whether they are consumers purchasing connected devices or businesses evaluating suppliers, buyers increasingly understand the risks associated with insecure products and are factoring those risks into purchasing decisions.
“Consumers, whether they’re businesses or end consumers, understand cybersecurity and security much more. They’re more aware of the risks, and they’re willing to pay a premium, most of them, to have security in a product.”
That willingness to pay more for secure products changes the commercial equation for manufacturers.
Manufacturers that can demonstrate strong security practices are more likely to earn customer confidence, protect their reputation, and command premium pricing. Those that cannot may find themselves competing primarily on cost.
Trust is what wins the purchase, defends the price, and keeps the customer.
Procurement Requirements Will Arrive Before Regulators
One of the strongest ROI arguments Patricia makes has nothing to do with fines.
It centres on procurement.
The CRA exists alongside NIS2, which places cybersecurity obligations on critical and important entities across sectors including healthcare, energy, utilities, finance, and digital infrastructure.
Those organisations are increasingly expected to understand and manage cybersecurity risk across their supply chains.
That responsibility inevitably influences procurement decisions.
“Their procurement processes are going to mandate that they purchase CRA-compliant or certified products.”
For manufacturers selling into regulated sectors, this matters enormously.
Many organisations are focused on whether they can achieve compliance before the deadline.
A more pressing question is whether procurement teams will continue considering suppliers who cannot demonstrate alignment with CRA requirements.
Market pressure often arrives long before regulatory enforcement.
Security Creates Pricing Power
Compliance is often framed as pure cost. The evidence from comparable markets suggests otherwise. Voluntary cybersecurity labelling schemes in other regions have already shown that buyers will differentiate between products based on visible security credentials, and the CRA is likely to accelerate that trend across the EU.
“We’ve seen this in other parts of the world. It does get competitive between manufacturers themselves. From a marketing point of view, my product is more secure, therefore it’s more premium.”
Manufacturers that can demonstrate strong security practices gain a positioning story their competitors cannot match, and in competitive markets that translates directly into margin and market share.
Why Most Manufacturers Are Further Behind Than They Think
One of the most surprising observations from Patricia’s work with manufacturers is how many organisations still have limited awareness of the CRA. Some have not assessed whether they fall within scope, others assume existing cybersecurity activities will be sufficient, and the reality is more complicated than either position suggests.
Most manufacturers are already doing cybersecurity. They are implementing security controls, testing products, and fixing vulnerabilities. Yet, the CRA requires evidence, process, and organisational discipline that most engineering teams have never been asked to produce.
“Manufacturers are doing cybersecurity. They are implementing security features in their products and testing their products. Where we see the gaps are they’re not doing it to a level that will reach the CRA essential requirements.”
Three gaps come up repeatedly.
The documentation gap
Security work happens every day inside most engineering teams, yet organisations struggle to demonstrate it consistently when asked. Engineers fix vulnerabilities, review code, and apply security controls without leaving the evidence trail an auditor or market surveillance authority will expect. Under the CRA, work that cannot be evidenced is work that did not happen.
The process gap
Many companies still treat security testing as a pre-launch activity. A product gets penetration tested before it ships, then runs in the field for years with new releases going out untested. The CRA closes that loop and demands ongoing rigour across the full product lifecycle.
“It’s not a one-off thing. You have to continuously and on an ongoing basis monitor the product for risks and vulnerabilities.”
The organisational maturity gap
The CRA expects manufacturers to monitor vulnerabilities, maintain documentation, manage reporting obligations, and build security into product development from the earliest stages. That is a different operating model from ad hoc engineering effort, and it cannot be retrofitted in the final months before a deadline.
Most manufacturers who run a serious readiness assessment discover the same thing. The technical capability often exists. The governance, evidence, and operating model frequently do not.
The Three Decisions Every Leadership Team Must Make
The manufacturers making the strongest progress are treating the CRA as a business objective. That starts with three leadership decisions:
Which products survive?
Patricia recommends starting with a review of the product portfolio, sorting every connected product into one of three categories.
Products to retire, where the security uplift is not technically feasible or commercially worthwhile. Products to upgrade, where the remaining commercial life justifies the investment. Products still in development, which can be designed around CRA requirements from the architecture stage.
The exercise sounds straightforward. In practice, it determines where engineering investment, security resources, and future growth opportunities are directed for the rest of the decade.
What knowledge needs to live in-house?
External consultants can provide valuable support, but manufacturers cannot outsource accountability. The declaration of conformity is signed by the manufacturer, and the legal exposure stays with the manufacturer.
“There is a legal attestation involved. You have to feel quite comfortable that you know the CRA and that you’re not missing anything.”
That is why Patricia advocates building internal capability. Manufacturers need people who understand vulnerability handling, reporting obligations, risk assessments, and security by design as a practical discipline. Knowledge that disappears when a consultancy engagement ends is not knowledge the business actually owns.
How fast are you moving?
Many organisations still view December 2027 as a distant deadline. Patricia disagrees.
“You should have started last year or yesterday.”
Manufacturers with multiple products, legacy technology, and limited security resources face a significant amount of work. Portfolio assessment, documentation, process improvements, training, security testing, and vulnerability handling all take time, and most of that work cannot be parallelised in the final months.
Companies that begin early gain the breathing room to do the work properly, and the option of announcing CRA readiness before their competitors do.
What separates the winners from the losers
The manufacturers making real progress on the CRA share a few consistent characteristics. The CEO or CTO actively sponsors the work. The board treats CRA as a governance issue rather than a technical project. Cross-functional teams pull together across engineering, product, quality, and security. Most importantly, leadership understands the commercial value behind the effort.
“This is something that has to become embedded. It has to become part of your everyday process. Security by design has to happen from the design phase, so you’re architecting the security into your products from the beginning. That’s a whole change in the way you develop your products.”
The organisations making the most progress are asking how they can use the CRA to strengthen products, deepen trust, and pull ahead of slower competitors. The ones that struggle most will not be those lacking technical talent, they will be the ones that left preparation too late.
“The winners will be the ones who have been preparing for at least a year and a half.”
Companies that start early have time to mature processes, train teams, build documentation, and bring CRA knowledge into the business rather than renting it. Companies that wait will spend 2027 producing rushed paperwork while their competitors are already in the market announcing readiness.
How Cyber Cert Labs helps you move first on CRA
Cyber Cert Labs is a European cybersecurity company focused exclusively on CRA compliance for manufacturers of connected products. The team behind Attestra, an AI-powered platform that takes connected product manufacturers from scope assessment through risk assessment, vulnerability handling, documentation, and attestation, handling the heavy lifting inside a single system rather than spreading it across consultants and spreadsheets.
Attestra Academy sits alongside it, structured online CRA training that gives your team the depth of understanding needed to sign off on conformity with confidence.
Patricia’s advice to every manufacturer she meets is the same.
“Start now. Don’t wait. There’s not enough time. It sounds like it’s far away, but it’s not. Just make that start.”
Try Attestra free for 7 days >
Check out Attestra Academy >