Security-by-design
Cyber risk assessment and product design with security requirements built in from the very start.
The new European cybersecurity standard for all products with digital elements. We'll explain who it applies to, the deadlines and obligations — and, above all, get you compliant end to end.
The Cyber Resilience Act is an EU regulation that, for the first time, introduces uniform and mandatory cybersecurity requirements for products with digital elements across their entire lifecycle — from design and development to support on the market.
The goal is to reduce systemic cyber risk across the EU. Security can no longer be an add-on; it must be a standard built in "by design" (security-by-design).
Cyber risk assessment and product design with security requirements built in from the very start.
Processes to identify, record and remediate vulnerabilities throughout the support period — at least 5 years.
Conformity assessment (self-assessment or via a notified body) and CE marking with the EU declaration of conformity.
A technical file demonstrating conformity — security tests, threat model, SBOM and patch records.
Reporting actively exploited vulnerabilities and serious incidents via the ENISA platform — early warning within 24 h.
A clear statement of how long you will provide security updates — disclosed already at the point of sale.
Key dates you can't afford to miss
The regulation entered into force; the transition period begins.
Rules for conformity assessment bodies start to apply.
Vulnerability and incident reporting becomes enforceable.
All essential requirements, conformity assessment and CE marking become binding.
From 11 Sep 2026, strict deadlines apply for reporting actively exploited vulnerabilities and serious incidents via the single ENISA platform.
Penalties are tiered by the severity of the breach. The higher of the two values applies.
| Severity | What it covers | Fine |
|---|---|---|
| Highest | Breach of essential cybersecurity requirements and the reporting obligation (Art. 13 and 14) | €15M / 2.5% |
| Medium | Failures around CE marking, declaration of conformity, documentation or cooperation with authorities | €10M / 2% |
| Lower | False, incomplete or misleading information to notified bodies and authorities | €5M / 1% |
The percentage applies to global annual turnover. Micro and small enterprises have exemptions for some deadlines.
We guide you from the first analysis all the way to ongoing operations once the rules take effect.
Start with a free consultation. We'll assess whether and how the CRA applies to you and propose concrete next steps.