logo

The EU Cyber Resilience Act: Securing Digital Products | UpGuard

ID: 9b4978f3-d90c-5124-9717-7515eb79affa

STIX ID: report--9b4978f3-d90c-5124-9717-7515eb79affa

Feed Name: UpGuard Blog

Date Published: 2024-04-11

Date Updated: 2026-05-01

...
...

The document explains the EU Cyber Resilience Act (CRA), passed in 2024, which mandates baseline cybersecurity for products with digital elements across the EU, using a risk-based model (Default, Critical Class I/II) and requiring secure-by-design development, lifecycle patching, vulnerability/incident reporting to ENISA within 24/72 hours, and clear technical documentation and risk assessments. It details conformity assessments (self-assessment vs third-party), CE marking, in-scope entities (manufacturers, developers, suppliers, EU and non‑EU), penalties up to €15M or 2.5% of global turnover (and fines for false information), and enforcement by member-state market surveillance authorities. The act’s interplay with NIS2 and GDPR is highlighted, and concerns around open-source software are addressed with exemptions for non-profit OSS while noting practical challenges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.