Cybersecurity law and regulation have been on a steady evolutionary journey, from protecting the “confidentiality, integrity and availability” of certain types of information, such as personal, classified and sensitive, to addressing the operational resilience of organizations as a whole. The latest and most consequential cybersecurity law facing enterprises globally is the EU Cyber Resilience Act, a unique product security law with extraterritorial reach that requires manufacturers of “products with digital elements” to develop those products with security-by-design, and fix and report vulnerabilities for years after placing them on the market.
The CRA has significant teeth: Products that do not conform may not be sold in the EU.
Administrative fines can reach 2.5% of global annual turnover or 15 million euros (USD17 million, 12.7 million GBP), whichever is higher, alongside withdrawal and recall powers and rising exposure to EU representative class actions, a topic explored in part five of this series. But perhaps a more meaningful threat to the balance sheet is the immediate impact on sales, and there is no time to lose when it comes to compliance readiness as regards the CRA.
Most CRA obligations will apply from 11 Dec. 2027. However, reporting obligations on actively exploited vulnerabilities and severe incidents will kick in 11 Sept. 2026, with provisions on notification to conformity assessment bodies already in force since June 2026.
This is the first in a five-part series on the operational impacts of the CRA. The series will cover the CRA’s application to products, best practices for reporting vulnerabilities, conducting conformity assessments, managing compliance across other major EU digital responsibility regulations and more.