Industry · CRA

Industry & CRA: securing connected products placed on the market

The Cyber Resilience Act requires manufacturers of products with digital elements — including many connected machines and industrial equipment — to integrate security by design and manage vulnerabilities throughout the entire lifecycle. This guide details the essential requirements applied to industrial products, the SBOM, patches, notification, and CE cybersecurity marking.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: CRA.
  • Any manufacturer placing a connected machine or piece of equipment embedding software on the European market is, in principle, a manufacturer within the meaning of the CRA.
  • Security by design.
  • Manage vulnerabilities.
  • Establish a SBOM.
  • Up to €15 million or 2.5% of global turnover for breaches of essential requirements, with the possibility of product withdrawal or recall.

Regulatory deadlines

The key dates of this regulation.

December 2024

Entry into force

In force

September 2026

Notification obligation (vulnerabilities & incidents)

Upcoming

December 2027

Full application

Upcoming

What does the CRA cover?

The CRA targets products with digital elements connected directly or indirectly to a network. Many connected industrial devices fall within this scope, with reinforced categories for critical products.

It interfaces with existing sectoral legislation (machinery, product safety); certain categories already covered by equivalent rules benefit from specific accommodations.

Is the 'Industry' sector concerned?

Any manufacturer placing a connected machine or piece of equipment embedding software on the European market is, in principle, a manufacturer within the meaning of the CRA. The level of requirements depends on the product's criticality.

Integrated software components, including open-source ones, fall under the responsibility of the manufacturer placing the product on the market.

Detailed obligations

Security by design

Design secure products by default: minimal attack surface, absence of known exploitable vulnerabilities at the time of delivery.

Manage vulnerabilities

Establish a coordinated vulnerability handling and disclosure process throughout the entire lifecycle.

Establish an SBOM

Maintain a software bill of materials for the product to identify vulnerable dependencies.

Provide patches

Ensure security updates are provided throughout the announced support period.

Notify and label

Notify exploited vulnerabilities to ENISA, establish technical documentation and affix the cybersecurity CE marking.

Sanctions & risks

Up to €15 M or 2.5% of global turnover for breaches of essential requirements, with the possibility of product withdrawal or recall. The cybersecurity CE marking is a prerequisite for market access.

For the industry, the challenge is as much commercial as regulatory: without CRA compliance, the product can no longer be placed on the market in the Union.

Application timeline

  • 1Entry into force. End of 2024.
  • 2Notification obligations. During 2026.
  • 3Full requirements. Horizon 2027.

Common mistakes in the sector

  • 1CRA neglected on the product side. Addressing cybersecurity at the factory level without securing the products sold.
  • 2No SBOM. Ignore the component nomenclature.
  • 3Undefined support. Failing to guarantee patches over time.
  • 4Untracked third-party components. Not monitoring vulnerabilities in integrated components.

Practical case

A machine manufacturer discovers, through its SBOM, that an integrated library contains an actively exploited vulnerability. It publishes a patch under its support policy, notifies ENISA, and informs its industrial customers — a chain of response mandated by the CRA and impossible without a software bill of materials or a vulnerability management process.

Compliance roadmap

  1. 1

    Map the products. Inventory connected products and their software components (SBOM).

  2. 2

    Structuring product security. Implement security by design and vulnerability management.

  3. 3

    Define the support. Setting and communicating the patch supply duration.

  4. 4

    Preparing compliance. Building the documentation and assessment required for CE marking.

  5. 5

    Equip the notification process. Implement notification of exploited vulnerabilities.

Frequently asked questions

If it includes connected digital elements, yes: the manufacturer is within scope, with security by design and cybersecurity CE marking.

Take action on CRA

Free assessment or a chat with an expert dedicated to industry.

They already trust us

See how organisations in the industry sector secured their compliance with DCO.

See testimonials