← Glossary

Cyber Resilience Act

The EU regulation placing cybersecurity requirements on products with digital elements: secure by design, vulnerability handling and reporting duties for manufacturers.

Updated

The EU Cyber Resilience Act (CRA) is the regulation that places cybersecurity requirements on products with digital elements sold in the EU: hardware and software must be secure by design, receive security updates, and their manufacturers must handle and report vulnerabilities. Where NIS2 regulates organizations, the CRA regulates the products they buy and build. See the European Commission page for the current text and timeline.

Key facts:

  • It covers manufacturers, importers and distributors of connected products and software, with CE-marking tied to meeting the requirements.
  • Manufacturers get vulnerability handling duties and tight reporting timelines for actively exploited vulnerabilities (verify current specifics against official sources; obligations phase in over several years).
  • For buyers, the CRA gradually changes procurement: products without demonstrable security lifecycles lose access to the EU market.

Why it appears in a security glossary

Two reasons. For software companies, including SaaS vendors with product components in scope, the CRA adds product-security and reporting duties on top of organizational rules like NIS2 and DORA. For everyone else, it reshapes the supply chain: the unpatched, abandoned products that zero-day attacks feed on are exactly what the regulation is built to squeeze out. It also sits alongside the EU AI Act as part of the wider EU digital rulebook.

Where email security fits, honestly

The CRA is product regulation, and Sentaro does not make anyone CRA compliant. The adjacency is operational: exploited product vulnerabilities and their patches trigger incident and communication flows that overwhelmingly run through email, where impersonated "security advisories" and fake update notices are an established phishing pattern. Sentaro protects that channel while your product and legal teams handle the CRA itself.

This page is general guidance, not legal advice.

Questions we get asked.

What is the Cyber Resilience Act in simple terms?

An EU regulation requiring products with digital elements to be secure by design and supported with updates and vulnerability handling throughout their lifecycle, enforced via CE-marking.

Who does the CRA apply to?

Primarily manufacturers of hardware and software with digital elements placed on the EU market, plus importers and distributors. Some categories, like pure SaaS covered by other rules, sit outside or at the edges of scope; assess specifically.

How does the CRA relate to NIS2?

Complementary layers: NIS2 secures organizations and their operations; the CRA secures the products themselves. A company can be covered by both in different roles.

When does the CRA apply?

It entered into force in 2024 with obligations phasing in over the following years; verify the current timeline against official EU sources before relying on dates.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.