Regulation Statutory · EU
Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act).
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe security incidents in stages - the reporting obligations have applied since 11 September 2026, with the regulation's full application from 11 December 2027. For Swiss manufacturers, the CRA applies as soon as they place products with digital elements on the EU market.
01 Triggers
When does CRA apply to you?
CRA may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.
- Activity: Products with software (Likely applies): You state that you manufacture or distribute products with software or digital elements - the CRA requires cybersecurity by design and by default for such products across their entire product life cycle, as soon as they are placed on the EU market.
- Role towards customers: Manufacturer (applies if additionally: Activity: Products with software) (Recommend individual review): As a manufacturer of products with digital elements, you bear the main responsibility under the CRA for conformity assessment, reporting obligations and security updates - distributors and importers have lighter-touch obligations. For manufacturers without digital product components, the CRA does not apply.
- Markets: EU (applies if additionally: Activity: Products with software) (Recommend individual review): The CRA is triggered by placing a product on the EU market, not by the manufacturer's registered seat - if you offer your connectable products with digital elements in the EU, the CRA can apply regardless of your registered seat in Switzerland. Without digital product components, the EU market alone does not trigger the CRA.
- Activity: Medical devices (Recommend individual review): For medical devices, the CRA generally does not apply; instead, the more specific cybersecurity requirements of the Medical Device Regulation (MDR) apply - check case by case whether your product falls under this CRA exemption.
Exceptions
- Medical devices and in-vitro diagnostics already subject to Regulation (EU) 2017/745 or (EU) 2017/746.
- Motor vehicles and vehicle parts with their own sector-specific type approval.
- Aviation and marine equipment with their own sector-specific cybersecurity requirements.
- Products developed exclusively for national security or military purposes.
- Non-commercial open-source software developed and made available by volunteers without direct commercial intent - as soon as paid support or commercial integration into products sold is added, the exemption no longer applies.
- Identical spare parts for products already placed on the market.
02 Obligations
What does CRA require?
- Secure-by-design and secure-by-default: consider cybersecurity from the start of development.
- Draw up a declaration of conformity and apply CE marking for products with digital elements.
- Report actively exploited vulnerabilities and severe security incidents via the central reporting platform (Single Reporting Platform) to the responsible CSIRT - early warning within 24 hours, detailed notification within 72 hours, final report within 14 days of remediation measures becoming available, or within one month for severe incidents.
- Provide free security updates for at least 5 years or the expected product usage period.
- Clearly indicate the end of the support period to customers.
03 Evidence
What evidence is needed?
- Technical documentation and declaration of conformity.
- Evidence of the vulnerability management process.
- Reporting logs via the CRA Single Reporting Platform or to ENISA.
- Documented update and support period.
04 Deadlines
Which deadlines apply?
- Notifying authorities must have established the procedures for conformity assessment bodies.
- Reporting obligations for manufacturers (actively exploited vulnerabilities, severe incidents) become applicable.
- The Cyber Resilience Act applies in full, including conformity assessment obligations for all affected products.
Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).
05 Penalties
What are the consequences of violations?
According to secondary sources, breaches of the essential cybersecurity requirements can be penalised with fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher; the exact scale of fines by type of breach was not verified against the regulation's text itself in this session.
06 Related
What is connected with it?
- Machinery Regulation (EU Machinery Regulation): The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU.
- Regulation (EU) 2017/745 on medical devices: The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021.
07 Open
What is still uncertain?
- The EUR-Lex primary text of Regulation (EU) 2024/2847 (eur-lex.europa.eu/eli/reg/2024/2847/oj) could not be retrieved in this session (empty response); content evidenced via the EU Commission page digital-strategy.ec.europa.eu and the BSI, not via the regulation's text itself.
- The exact date of entry into force of the regulation was not verified in this session and is therefore not listed.
- The exact scale of fines by type of breach is evidenced only via a secondary source, not verified against the regulation's text.
- Whether and how the open-source exemption exactly hinges on article text or a recital was not checked against the primary text.
08 Sources
Sources
Information as of: 24 September 2026.
- Cyber Resilience Act – Reporting obligations, Europäische Kommission (Generaldirektion CNECT), retrieved on 24 September 2026
- Cyber Resilience Act – Übersicht, Bundesamt für Sicherheit in der Informationstechnik (BSI), retrieved on 24 September 2026
- Wichtigste Fragen & Antworten zum Cyber Resilience Act, cyber-regulierung.de, retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about CRA.
Does a Swiss software house without a physical product fall under the CRA?
Yes, potentially: the CRA covers not only hardware but also standalone software with digital elements that is placed on the EU market - for example apps or backend software that connects to devices or networks. What matters is placing it on the market in the EU, not the registered seat.
Is open-source software generally exempt from the CRA?
Only non-commercial open-source software developed and made available by volunteers without a profit motive. As soon as paid support, commercial distribution or integration into a product sold is added, the CRA applies as normal - open-source steward organisations have their own, lighter-touch obligations from December 2027.
How does the CRA relate to the EU Machinery Regulation?
Both frameworks require cybersecurity for connected products but cover different product categories: the CRA regulates products with digital elements in general, while the Machinery Regulation (EU) 2023/1230 specifically regulates machinery and its safety functions. For machinery with digital elements, it must be checked case by case which framework - or whether both - applies; see the separate norm file maschinenverordnung_2023_1230.
Does CRA apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
