OTRISK
Regulations · EU Regulation 2024/2847

The CRA makes product security a market-access question.

The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements sold in the EU: hardware and software, consumer and industrial. It is a regulation: directly applicable in every member state, no transposition, CE marking as the gate.

IN FORCE
10 Dec 2024
NOTIFIED-BODY CHAPTER
11 Jun 2026
ART. 14 REPORTING
11 Sep 2026
FULLY APPLICABLE
11 Dec 2027

What it demands

Secure by design
Before the market
A cybersecurity risk assessment before a product is placed on the market, and essential requirements carried through planning, design, development and maintenance.
Vulnerability handling
Through the lifecycle
Identify, document, remediate and update for the support period. Actively exploited vulnerabilities and severe incidents get reported from 11 September 2026, also for products already on the market.
Conformity & documentation
Then CE
Technical documentation and conformity assessment: self-assessed or via notified body, depending on product class. Fines reach €15 million or 2.5% of worldwide turnover.

Who must care

Manufacturers first, wherever they are, if the product reaches the EU market. Importers and distributors carry their own duties. Sectors with equivalent regimes (medical devices, type-approved vehicles, and a few others) are excluded.

Asset owners are reached through procurement: from 11 December 2027 the components you buy must conform. Your purchasing can start asking now.

Where OT comes in

For industrial components and systems, the CRA’s demands read like IEC 62443-4-1 and 4-2: a secure development process, component security capabilities. If you already evidence 4-1 and 4-2, you are building the CRA file.

CRAEssential requirementsIEC 62443-4-1 / 4-2 evidenceTechnical documentationCE marking
Trace it in the map →

How OTRISK helps

4-1 and 4-2 as assessments. Owned requirements, evidence, independent review: the same engine that runs your risk assessment.
One body of evidence, three audiences. CRA documentation, customer RFPs and certification tests draw on the same reviewed evidence.
Honest limit. OTRISK is not a notified body and issues no conformity. We organise the evidence; assessment bodies do their own work.

Questions we hear

Are harmonised standards ready?

Work is ongoing. Until harmonised standards land, follow the essential requirements and document against them.

Does the CRA replace RED 3.3?

From 11 December 2027 the CRA takes over the ground the RED delegated regulation covers today. Until then, RED 3.3 applies to connected radio equipment.

We are an asset owner, not a manufacturer.

Then the CRA reaches you through procurement: conforming components from your suppliers. Put it in your CRS and your supplier assessments.

Is our SaaS in scope?

Remote data processing tied to a product’s function is in; pure services generally are not. Scope questions deserve a lawyer, not a landing page.

SOURCES · FACTS VERIFIED 30 JUL 2026
EUR-Lex · Regulation (EU) 2024/2847European Commission · Cyber Resilience Act policy pageEuropean Commission · CRA legislative summary

From standard to signed-off.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

See supplier assessments in third-party mode →