CRA6-minute read·Marcin Pajdzik·November 2025

The CRA Makes EU Market Access Conditional on Product Cybersecurity

From 11 December 2027, products with digital elements within the CRA's scope can be placed on the EU market only if they meet the Cyber Resilience Act's essential cybersecurity requirements and carry the CE marking. For manufacturers selling hardware or software into the EU, compliance becomes a condition of EU revenue.

Executive teams need to set the product roadmap, funding and delivery accountability for that work. Boards should scrutinise how much EU revenue is exposed and whether management's readiness plan is credible. The next budgeting cycle needs to cover reporting readiness for September 2026 and the product changes required for December 2027.

What applies from September 2026 and from December 2027

The CRA is an EU regulation and applies directly in every Member State. Its reporting obligations apply from 11 September 2026, when manufacturers must begin to notify actively exploited vulnerabilities and severe incidents affecting the security of their products. The main requirements apply from December 2027.

Individual units placed on the EU market before 11 December 2027 can continue through distribution, and fall under the main requirements only if they are substantially modified from that date, although the reporting obligations cover them from September 2026. Product lines from which new units will be placed on the EU market on or after 11 December 2027 need a readiness plan for those units. The readiness plan must work back from that date to establish design, development and assessment milestones.

Which products and which organisations are in scope

The CRA covers hardware and software whose intended or reasonably foreseeable use includes a data connection to a device or network. Some products sit outside it, including medical devices, motor vehicles and certified aviation products governed by their own EU rules, marine equipment, and products developed exclusively for national security or defence. Free and open-source software supplied outside a commercial activity is also outside scope. Each product needs its own scope assessment.

The assessment route depends on the product's classification and the standards or certification routes available. Some products can be assessed internally; others require external assessment. Management should establish the route for each product early enough to include its cost and lead time in launch plans.

Importers may place on the market only products that comply, and must check that the manufacturer has carried out conformity assessment, drawn up technical documentation and affixed the CE marking. Distributors must verify the CE marking and documentation before making products available. An importer or distributor that places a product on the market under its own name or trademark, or carries out a substantial modification, takes on the manufacturer's obligations.

What each requirement means commercially

Development capacity
Products must meet the CRA's essential cybersecurity requirements, including secure default configuration, protection against unauthorised access and a limited attack surface. For product lines with new units reaching the EU market from December 2027, this work draws on the same development capacity as existing roadmap commitments.
Ongoing support costs
Manufacturers must handle vulnerabilities and provide security updates for a support period of at least five years, or the expected use time if that is shorter. Where a product is expected to be in use for longer, the support period should reflect that. The cost continues after the sale and belongs in pricing and lifecycle plans.
Assessment lead times
Where a product needs a notified body or certification, the timetable depends on their availability and on whether a suitable certification scheme applies. The technical documentation behind the CE marking must be complete before a product is placed on the market.
Supplier dependencies
Manufacturers must exercise due diligence on third-party components, including open-source software, so that they do not compromise the product's security. Supplier contracts may need to cover vulnerability information and updates for the full support period.

What the portfolio readiness assessment should show

The executive team should commission the assessment and own the resulting plan. The board should scrutinise material revenue exposure, funding and delivery confidence.

Exposure
Which products are in scope, in which category, and how much EU revenue depends on them?
Delivery
What must change in each product, who owns delivery, and what funding is required?
Portfolio choices
Which products will be remediated or replaced, and which product lines will stop placing new units on the EU market from December 2027?
Evidence
What supports the conformity timetable, and how will reporting readiness be tested before September 2026?

How this affects your organisation

For manufacturers, the CRA ties EU revenue to decisions on product design, support commitments and supplier terms that need long lead times. The executive team owns the roadmap and funding, and the board needs evidence that the plan matches the exposure.

For importers and distributors, the exposure lies in the products they handle and in any product they rebrand or substantially modify, which brings the manufacturer's obligations with it. Supplier verification and contract terms should reflect that before December 2027.

If you sell products with digital elements into the EU, I can help you assess your portfolio exposure and build a credible readiness plan.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

CRA Self-Assessment

If this briefing is relevant to your organisation, the self-assessment tool gives a fast, no-commitment view of where a specific product stands under the CRA.

Free, self-serve

Answer a short set of questions about the product and your role in the supply chain.

Output: An initial product classification, the obligations most likely to apply, and the questions worth raising internally before committing to a compliance programme.
Start the self-assessment