Historically, software and digital devices have operated under 'buyer beware' legal assumptions. Vendors could ship insecure software, disclaim liability in end-user license agreements, and leave remediation costs to consumers and enterprises. The EU Cyber Resilience Act brings an abrupt end to this era by establishing legally enforceable product liability for cybersecurity defects.
1. Scope: What Qualifies as a 'Product with Digital Elements'?
The CRA defines products with digital elements broadly: any software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. Products are categorized into three risk tiers:
Default Products (Class 0)
~90% of Software & Connected Hardware
- General business applications
- Word processors and ERP tools
- Connected smart home sensors
- Computer games and consumer electronics
Assessment: Self-assessment of conformity under internal manufacturing control.
Important & Critical Products (Classes I & II)
Security-Sensitive Infrastructure
- Class I: Identity management systems, password managers, VPNs, network interfaces
- Class II: Firewalls, intrusion detection systems, secure cryptoprocessors, industrial hypervisors
Assessment: Mandatory third-party conformity assessment by a notified body.
2. Core Manufacturer Obligations Across the Product Lifecycle
The CRA imposes obligations that begin during initial architecture design and continue throughout the operational life of the product:
Security by Design and Default
Products must be delivered without known exploitable vulnerabilities, with secure default configurations, automatic updates enabled, and protection against unauthorized access.
Software Bill of Materials (SBOM) Generation
Manufacturers must create and maintain an inventory of software components, including open-source libraries and transitive dependencies, in machine-readable formats (CycloneDX, SPDX).
Lifetime Vulnerability Handling & Patching
Security patches must be provided promptly and free of charge throughout the declared support period, distributed separately from functional feature updates.
24-Hour Mandatory Vulnerability Reporting
If an actively exploited vulnerability or severe security incident is identified in a product, the manufacturer must report it to the EU Computer Security Incident Response Team (CSIRT) network and ENISA within 24 hours.
3. Penalties and Single Market Enforcement
Violating CRA requirements carries severe statutory penalties: administrative fines up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Crucially, national market surveillance authorities have the power to order the immediate recall or complete withdrawal of non-compliant products from the European market.
4. Strategic Preparation for Software and Hardware Vendors
Organizations developing digital products must integrate automated dependency tracking, static and dynamic security scanning, and documented vulnerability intake programs directly into their engineering workflows today. Compliance with the CRA will separate trusted enterprise vendors from those barred from the European single market.