In brief
- Regulation: CRA.
- Any manufacturer placing a connected machine or piece of equipment embedding software on the European market is, in principle, a manufacturer within the meaning of the CRA.
- Security by design.
- Manage vulnerabilities.
- Establish a SBOM.
- Up to €15 million or 2.5% of global turnover for breaches of essential requirements, with the possibility of product withdrawal or recall.
Regulatory deadlines
The key dates of this regulation.
December 2024
Entry into force
In forceSeptember 2026
Notification obligation (vulnerabilities & incidents)
UpcomingDecember 2027
Full application
UpcomingWhat does the CRA cover?
The CRA targets products with digital elements connected directly or indirectly to a network. Many connected industrial devices fall within this scope, with reinforced categories for critical products.
It interfaces with existing sectoral legislation (machinery, product safety); certain categories already covered by equivalent rules benefit from specific accommodations.
Is the 'Industry' sector concerned?
Any manufacturer placing a connected machine or piece of equipment embedding software on the European market is, in principle, a manufacturer within the meaning of the CRA. The level of requirements depends on the product's criticality.
Integrated software components, including open-source ones, fall under the responsibility of the manufacturer placing the product on the market.
Detailed obligations
Security by design
Design secure products by default: minimal attack surface, absence of known exploitable vulnerabilities at the time of delivery.
Manage vulnerabilities
Establish a coordinated vulnerability handling and disclosure process throughout the entire lifecycle.
Establish an SBOM
Maintain a software bill of materials for the product to identify vulnerable dependencies.
Provide patches
Ensure security updates are provided throughout the announced support period.
Notify and label
Notify exploited vulnerabilities to ENISA, establish technical documentation and affix the cybersecurity CE marking.
Sanctions & risks
Up to €15 M or 2.5% of global turnover for breaches of essential requirements, with the possibility of product withdrawal or recall. The cybersecurity CE marking is a prerequisite for market access.
For the industry, the challenge is as much commercial as regulatory: without CRA compliance, the product can no longer be placed on the market in the Union.
Application timeline
- 1Entry into force. End of 2024.
- 2Notification obligations. During 2026.
- 3Full requirements. Horizon 2027.
Common mistakes in the sector
- 1CRA neglected on the product side. Addressing cybersecurity at the factory level without securing the products sold.
- 2No SBOM. Ignore the component nomenclature.
- 3Undefined support. Failing to guarantee patches over time.
- 4Untracked third-party components. Not monitoring vulnerabilities in integrated components.
Practical case
A machine manufacturer discovers, through its SBOM, that an integrated library contains an actively exploited vulnerability. It publishes a patch under its support policy, notifies ENISA, and informs its industrial customers — a chain of response mandated by the CRA and impossible without a software bill of materials or a vulnerability management process.
Compliance roadmap
- 1
Map the products. Inventory connected products and their software components (SBOM).
- 2
Structuring product security. Implement security by design and vulnerability management.
- 3
Define the support. Setting and communicating the patch supply duration.
- 4
Preparing compliance. Building the documentation and assessment required for CE marking.
- 5
Equip the notification process. Implement notification of exploited vulnerabilities.
Frequently asked questions
If it includes connected digital elements, yes: the manufacturer is within scope, with security by design and cybersecurity CE marking.
Take action on CRA
Free assessment or a chat with an expert dedicated to industry.
They already trust us
See how organisations in the industry sector secured their compliance with DCO.