The EU Cyber Resilience Act (CRA) is the regulation that places cybersecurity requirements on products with digital elements sold in the EU: hardware and software must be secure by design, receive security updates, and their manufacturers must handle and report vulnerabilities. Where NIS2 regulates organizations, the CRA regulates the products they buy and build. See the European Commission page for the current text and timeline.
Key facts:
- It covers manufacturers, importers and distributors of connected products and software, with CE-marking tied to meeting the requirements.
- Manufacturers get vulnerability handling duties and tight reporting timelines for actively exploited vulnerabilities (verify current specifics against official sources; obligations phase in over several years).
- For buyers, the CRA gradually changes procurement: products without demonstrable security lifecycles lose access to the EU market.
Why it appears in a security glossary
Two reasons. For software companies, including SaaS vendors with product components in scope, the CRA adds product-security and reporting duties on top of organizational rules like NIS2 and DORA. For everyone else, it reshapes the supply chain: the unpatched, abandoned products that zero-day attacks feed on are exactly what the regulation is built to squeeze out. It also sits alongside the EU AI Act as part of the wider EU digital rulebook.
Where email security fits, honestly
The CRA is product regulation, and Sentaro does not make anyone CRA compliant. The adjacency is operational: exploited product vulnerabilities and their patches trigger incident and communication flows that overwhelmingly run through email, where impersonated "security advisories" and fake update notices are an established phishing pattern. Sentaro protects that channel while your product and legal teams handle the CRA itself.
This page is general guidance, not legal advice.