Historically, software and digital devices have operated under 'buyer beware' legal assumptions. Vendors could ship insecure software, disclaim liability in end-user license agreements, and leave remediation costs to consumers and enterprises. The EU Cyber Resilience Act brings an abrupt end to this era by establishing legally enforceable product liability for cybersecurity defects.

1. Scope: What Qualifies as a 'Product with Digital Elements'?

The CRA defines products with digital elements broadly: any software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. Products are categorized into three risk tiers:

Default Products (Class 0)

~90% of Software & Connected Hardware

  • General business applications
  • Word processors and ERP tools
  • Connected smart home sensors
  • Computer games and consumer electronics

Assessment: Self-assessment of conformity under internal manufacturing control.

Important & Critical Products (Classes I & II)

Security-Sensitive Infrastructure

  • Class I: Identity management systems, password managers, VPNs, network interfaces
  • Class II: Firewalls, intrusion detection systems, secure cryptoprocessors, industrial hypervisors

Assessment: Mandatory third-party conformity assessment by a notified body.

2. Core Manufacturer Obligations Across the Product Lifecycle

The CRA imposes obligations that begin during initial architecture design and continue throughout the operational life of the product:

01

Security by Design and Default

Products must be delivered without known exploitable vulnerabilities, with secure default configurations, automatic updates enabled, and protection against unauthorized access.

02

Software Bill of Materials (SBOM) Generation

Manufacturers must create and maintain an inventory of software components, including open-source libraries and transitive dependencies, in machine-readable formats (CycloneDX, SPDX).

03

Lifetime Vulnerability Handling & Patching

Security patches must be provided promptly and free of charge throughout the declared support period, distributed separately from functional feature updates.

04

24-Hour Mandatory Vulnerability Reporting

If an actively exploited vulnerability or severe security incident is identified in a product, the manufacturer must report it to the EU Computer Security Incident Response Team (CSIRT) network and ENISA within 24 hours.

3. Penalties and Single Market Enforcement

Violating CRA requirements carries severe statutory penalties: administrative fines up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Crucially, national market surveillance authorities have the power to order the immediate recall or complete withdrawal of non-compliant products from the European market.

4. Strategic Preparation for Software and Hardware Vendors

Organizations developing digital products must integrate automated dependency tracking, static and dynamic security scanning, and documented vulnerability intake programs directly into their engineering workflows today. Compliance with the CRA will separate trusted enterprise vendors from those barred from the European single market.