The first question manufacturers need to ask themselves is:
Is my product actually covered by the CRA?
The answer is not always as straightforward as one might think. In this article, we break down the criteria defined by the regulation to help you determine whether your product falls within its scope
Who is considered a manufacturer?
Before even looking at the product itself, it is essential to know whether your company qualifies as a manufacturer under the Cyber Resilience Act.
According to the regulation, a manufacturer is:
“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”
In other words, you do not need to manufacture or design all the electronics yourself to be considered a manufacturer.
Example
A company purchases a connected device from an Asian supplier, applies its own logo and sells it under its own brand in Europe.
Even though it did not design the product, it is considered a manufacturer under the CRA and will be required to comply with the obligations set out in the regulation.
Which products are covered?
The Cyber Resilience Act applies to products with digital elements whose intended use includes a direct or indirect data connection to another device or network.
In practice, this covers the majority of electronic products capable of exchanging digital information.
This includes products with wired connections such as USB, Ethernet or RS232, as well as wireless connections such as Wi-Fi, Bluetooth, NFC, Zigbee or LoRa, or any other means of data exchange.
It is important to note that it is not the mere presence of an interface that is decisive, but the product’s ability to transmit or receive digital data. A simple electrical signal used solely to power or trigger a function is not sufficient to bring a product within the scope of the CRA.
Certain products are excluded
The Cyber Resilience Act does not apply to all equipment.
The main exclusions include:
- medical devices
- road vehicles
- products intended for civil aviation
- marine equipment
- products exclusively intended for defence or national security
- products specifically designed to process classified information
These categories are already covered by other sector-specific regulations.
Hardware and software: one single product
One often overlooked point concerns products made up of both hardware and software.
When software is necessary for the product’s intended operation and is provided by the manufacturer, the hardware and software are treated as a single product under the Cyber Resilience Act.
A few examples:
- a network printer and its software driver
- a smartwatch and its mobile application
- a home automation system and its configuration software
Even if the application is downloaded separately from an app store, it forms an integral part of the product when it is essential to its operation.
What are the upcoming deadlines?
The CRA timeline has two key dates.
From 11 September 2026
Manufacturers will be required to have processes in place to report actively exploited vulnerabilities and certain security incidents in accordance with the regulation.
From 11 December 2027
All new products falling within the scope of the Cyber Resilience Act must be compliant before being placed on the European market.
Will already-developed products need to be completely redesigned?
The good news is that the CRA does not systematically require existing products to be redesigned.
For products placed on the market after 11 December 2027 but designed before that date, the manufacturer will need to carry out a cybersecurity risk assessment.
If this assessment demonstrates that the security measures already in place are sufficient to address the identified risks, no changes to the product architecture will be necessary.
The regulation’s objective is to achieve a level of cybersecurity appropriate to the product — not to impose unnecessary security features.
Conclusion
Determining whether a product is covered by the Cyber Resilience Act is the first step in a compliance process. As we have seen, the scope of the regulation is broader than it may appear: a product sold under your brand, equipment combining hardware and software, or a device capable of exchanging digital data may all fall within its scope.
The good news is that the CRA does not necessarily require a complete redesign of your existing products. However, it does require a structured approach, based on a cybersecurity risk assessment and documentation demonstrating that the level of security is appropriate to the product’s intended use.
If you develop or sell electronic or connected products, it is therefore advisable to carry out an initial assessment of your portfolio now. Identifying the products concerned and anticipating the CRA’s requirements will help keep compliance costs manageable and allow you to approach the 2026 and 2027 regulatory deadlines with confidence.