EU Cyber Resilience Act: What Buyers of Connected Hardware Need to Know Now
The CRA doesn't just regulate the companies that make rugged computers, gateways and embedded modules — it can make you a manufacturer too, the moment you integrate them into your own product.
The EU Cyber Resilience Act (CRA) is the first EU wide law that sets mandatory cybersecurity requirements for hardware and software products sold into the EU and EEA market. It entered into force in December 2024, with most obligations becoming applicable on 11 December 2027. An earlier deadline matters too: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents under the CRA's reporting requirements. If you buy or integrate connected industrial computers, embedded controllers, IoT gateways, HMIs or communication modules for use in the EU, this regulation may be relevant to you, either when selecting products from suppliers or because your company may itself have manufacturer obligations for a finished product placed on the market.
Who is actually in scope. The CRA covers "products with digital elements", meaning hardware and software products whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. This is a deliberately broad definition. Rugged panel PCs, edge servers, PLCs with Ethernet or wireless interfaces, connected sensors and the software running on them can therefore fall within scope. There are specific exclusions, including certain medical devices, aviation products, motor vehicles and marine equipment covered by the EU Marine Equipment Directive. Products developed or modified exclusively for national security or defence purposes are also excluded. Pure cloud and SaaS services that are not remote data processing solutions of a product generally fall outside the CRA, while free and open source software supplied outside the course of a commercial activity receives separate treatment.
The classification that changes what's required. Most products fall into a default category where the manufacturer can use internal conformity assessment. However, the CRA identifies certain "important" products as Class I or Class II, including categories such as network management systems, routers, VPN products, firewalls and other security related products. Depending on the classification and conformity route, involvement of a third party may be required. The CRA also identifies categories of "critical" products for which European cybersecurity certification may be required under specified conditions. If you're specifying network or cybersecurity components for a rugged deployment, check early how the supplier has classified the product and which conformity assessment route applies.
What this means if you integrate purchased components. Buying a CRA compliant component does not automatically make a finished product compliant. If your company integrates hardware or software into a product that it places on the EU market under its own name or trademark, it may itself be the manufacturer of that finished product and therefore responsible for demonstrating CRA compliance. This can include cybersecurity risk assessment, vulnerability handling, security updates, technical documentation, a Software Bill of Materials (SBOM), conformity assessment, an EU Declaration of Conformity and CE marking. The required support period must reflect how long the product is expected to be used and is normally at least five years. Where the expected use is shorter than five years, the support period may correspond to that shorter lifetime.
What to ask suppliers for. Before selecting a product, check that the supplier can provide or clearly explain:
- Vulnerability reporting and handling process, including how security issues are communicated to customers.
- Security support period, including how long security updates will be provided and how they will be delivered.
- Updated EU Declaration of Conformity, covering the CRA once the requirements become applicable.
- CRA product classification and conformity route, including whether additional third party assessment is required.
- SBOM, confirmation that a Software Bill of Materials is maintained as part of the product's technical documentation.
The manufacturer must create an SBOM covering at least the product's top level dependencies, but the CRA does not generally require the complete SBOM to be provided to every customer. The EU Declaration of Conformity does not need to be a separate CRA specific document. Where several applicable EU laws require an EU Declaration of Conformity, they can be covered by a single declaration. Claims such as "designed to meet" or "CRA ready" should therefore not be treated as equivalent to completed conformity assessment and a formal declaration of conformity.
Practical next steps. Start by identifying the connected products and components you buy and determining which will be placed on the EU market after the CRA becomes fully applicable in December 2027. For important components, ask suppliers now about product classification, conformity assessment, security support periods and vulnerability handling. Remember that the CRA's vulnerability and incident reporting requirements have already applied since 11 September 2026. Don't assume alignment with IEC 62443, ETSI EN 303 645 or ISO 27001 automatically demonstrates CRA compliance. These standards and frameworks may support cybersecurity and conformity work, but the CRA has its own legal requirements and conformity procedures. NIS2 and the CRA also address different areas: NIS2 primarily concerns cybersecurity obligations for organisations within its scope, while the CRA concerns products with digital elements placed on the market.