Skip to content
Snippets Groups Projects

EU Cyber Resilience Act (CRA) Discussion Topics

What is the CRA?

The EU Cyber Resilience Act (CRA) is an upcoming EU Regulation that aims to safeguard consumers and businesses who use software or products with a digital components. It creates mandatory cybersecurity requirements for manufacturers and retailers that extend throughout the product lifecycle and helps consumers and business identify such products through the CE mark.

Main elements of the law

  • Cybersecurity rules for hardware and software that is placed on the market
  • Obligations for manufacturers, distributors, and importers
  • Cybersecurity essential requirements across the life cycle
  • Harmonised standards to follow
  • Conformity assessment
  • Reporting obligations
  • Market surveillance and enforcement

Scope

  • Hardware products (e.g. laptops, smart appliances, mobile phones, network equipment, CPUs, etc.)
  • Software products (e.g. operating systems, word processing, games or mobile apps, software libraries, etc.)
  • Remote data processing solutions for any of the above

Conformity assessment

Verifying conformity assessment is different for each level of risk.

Category Examples Assessment Type
Open source Web development frameworks, operating systems, database management systems, etc. Self-assessment (unless categorized as "critical products")
Default Memory chips, mobile apps, smart speakers, computer games, etc. Self-assessment
Important products Operating systems, anti-virus, routers, firewalls, etc. Application of standards/3rd-party assessment
Critical products Smart cards, secure elements, smart meter gateways, etc. Potentially certification in the future

CRA Resources

Discussion topics

Active topics

Proposed topics

Proposed discussion topics need the support of 5 people on the mailing list to get started. Any WG member can propose a discussion topic.

WG Resources