By 11 December 2027, all products with digital elements placed on the EU market must meet the essential cybersecurity requirements set out in CRA Annex I - covering both product security properties and vulnerability handling processes.
Annex I is divided into two parts: Part I sets out what the product itself must do; Part II sets out the processes manufacturers must maintain throughout the product lifecycle.
Products with digital elements must be designed, developed, and produced in a way that ensures an appropriate level of cybersecurity. The following properties must be demonstrable through conformity assessment.
Products must be placed on the market free of known exploitable vulnerabilities. This requires a thorough vulnerability assessment before release, including review of all components and dependencies.
Products must be delivered in the most secure configuration by default. Default credentials must be unique per device or require user-set credentials on first use. Unnecessary interfaces and features must be disabled by default.
The product must be designed to minimise its attack surface. This includes reducing the number of open ports, disabling unnecessary services, and applying the principle of least privilege throughout.
Data stored or transmitted by the product must be protected against unauthorised access using appropriate cryptography. Sensitive data must be encrypted at rest and in transit.
The product must protect the integrity of its data, configuration, and software. This includes mechanisms to detect and report unauthorised modifications to the product or its data.
The product must be designed to maintain availability and resilience against availability attacks (DoS) to the extent possible. Critical functions must degrade gracefully under attack.
The product must implement appropriate access control mechanisms. This includes authentication, authorisation, and the ability to revoke access for compromised credentials.
The product must collect only the data necessary for its function (data minimisation) and must not expose unnecessary data to external parties or services.
The product must have a mechanism to receive and apply security updates securely. Updates must be authenticated, integrity-checked, and applied without requiring user action where possible.
The product must be capable of recording security-relevant events. Logs must be protected against tampering and available for inspection by authorised users and authorities.
Part II requirements apply throughout the product support lifecycle, not just at the time of placing the product on the market. These process obligations must be maintained for the duration of the support period.
Manufacturers must maintain and publish a coordinated vulnerability disclosure (CVD) policy that allows security researchers and users to report vulnerabilities. The policy must include contact information, timelines for response, and the process followed.
Manufacturers must identify and document vulnerabilities in their products, including in third-party components. This requires maintaining awareness of the vulnerability landscape for all components used.
Manufacturers must maintain a Software Bill of Materials (SBOM) in machine-readable format listing all components including third-party and open source dependencies, their versions, and their known vulnerabilities.
Vulnerabilities must be addressed promptly. Security updates must be distributed without delay once a fix is available, and separately from feature updates where practicable.
Manufacturers must disclose their process for identifying, assessing, and addressing vulnerabilities to users and to competent authorities on request.
Manufacturers must actively monitor for new vulnerabilities in their products throughout the product support period, including monitoring third-party component vulnerability disclosures.
The CRA introduces mandatory SBOM requirements for products with digital elements. This is a significant new obligation for most manufacturers.
Manufacturers must provide security updates for the longer of: the expected product lifetime, or a minimum of 5 years from the date the product is placed on the market.
- Security updates must be free of charge
- Must be clearly separated from feature updates where possible
- Updates must be applied automatically unless user opts out
- End-of-support date must be communicated at least 12 months in advance
- Users must be notified when no further security updates will be available
The CE marking signals that a product meets CRA essential requirements and has undergone the appropriate conformity assessment for its product category.
- Determine product category (default / Class I / Class II)
- Complete appropriate conformity assessment
- Prepare EU Declaration of Conformity (DoC)
- Retain DoC and technical documentation for 10 years
- Affix CE marking to product, packaging, or documentation
- Register product in ENISA database (for Class I and II)
Which conformity assessment applies to your product?
See the CRA scope page for product categories and assessment requirements