The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements sold in the EU: hardware and software, consumer and industrial. It is a regulation: directly applicable in every member state, no transposition, CE marking as the gate.
Manufacturers first, wherever they are, if the product reaches the EU market. Importers and distributors carry their own duties. Sectors with equivalent regimes (medical devices, type-approved vehicles, and a few others) are excluded.
Asset owners are reached through procurement: from 11 December 2027 the components you buy must conform. Your purchasing can start asking now.
For industrial components and systems, the CRA’s demands read like IEC 62443-4-1 and 4-2: a secure development process, component security capabilities. If you already evidence 4-1 and 4-2, you are building the CRA file.
Work is ongoing. Until harmonised standards land, follow the essential requirements and document against them.
From 11 December 2027 the CRA takes over the ground the RED delegated regulation covers today. Until then, RED 3.3 applies to connected radio equipment.
Then the CRA reaches you through procurement: conforming components from your suppliers. Put it in your CRS and your supplier assessments.
Remote data processing tied to a product’s function is in; pure services generally are not. Scope questions deserve a lawyer, not a landing page.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.