Information and SRC Services for the Cyber Resilience Act
The EU’s Cyber Resilience Act—CRA for short—is intended to fundamentally improve the resilience of IT products used in Europe against attacks. To this end, the Cyber Resilience Act sets out so-called Essential Security Requirements (ESR). These cover product properties that must be ensured, as well as the manufacturer’s processes and the product documentation.
This affects all IT products with connectivity—the Cyber Resilience Act refers to these as products with digital elements. Only a few areas are exempt, such as medical devices and vehicles. Also exempt are all digital products that are manufactured or modified exclusively for the national security or defence of the Member States.
This means the vast majority of all IT products are affected—and with them the manufacturers or, more generally, the economic operators placing products on the market. Meeting the Essential Security Requirements is a prerequisite for a product to be placed on the market at all. In other words, this is a market access requirement—CRA can certainly be described as a game changer.
The four product classes under the Cyber Resilience Act
The legislator has defined four different product categories in the CRA. They reflect the varying risk that arises when vulnerabilities exist. There are important products in Class I, important products in Class II, and critical products. All products not assigned to these three classes fall into the standard, or default, class.
Conformity assessment: Module A, Module B/C, Module H and certification
In addition, the legislator has provided for different types of conformity assessment. These include:
- a manufacturer’s self-declaration (Module A),
- a product assessment combined with a manufacturer’s declaration (Module B/C),
- manufacturer qualification by assessing its quality assurance system (Module H), and
- certification of the product under a scheme pursuant to the Cybersecurity Act (e.g., EUCC).
The CRA now brings the product type classes and the possible conformity assessments together as follows:
- For a product in the default class, at a minimum a manufacturer’s declaration (Module A) must be provided as proof of conformity.
- If it is an important product in Class I, a manufacturer’s declaration (Module A) is sufficient if there are so-called harmonised standards for this product type and the manufacturer has complied with them. Otherwise, a product assessment with a manufacturer’s declaration (Module B/C) is required, or manufacturer qualification (Module H).
- If it is an important product in Class II, a product assessment with a manufacturer’s declaration (Module B/C) or manufacturer qualification (Module H) is required.
- For all critical products, certification under a scheme pursuant to the Cybersecurity Act (e.g., EUCC) is required. However, this still needs to be regulated by a separate implementing act. Until this is in place, the same rules apply to critical products as to important products in Class II.
- In general, any manufacturer can always do more than is actually required. For example, for a product in the standard class, a product assessment with a manufacturer’s declaration (Module B/C) or certification, e.g. under EUCC, can also be carried out. This is at the manufacturer’s discretion.
Which products fall into which Cyber Resilience Act class
The product types in Classes I and II as well as critical products are defined in the CRA annex.
Examples from the very broad Class I include:
- Identity management systems
- Browsers
- Password managers
- Boot managers
- Operating systems
- Routers, modems for internet access, and switches
- Microcontrollers with security-relevant functions
- Smart home products
- Toys with an internet connection
- Wearables
Class II is defined for the following product types:
- Hypervisors and container runtime systems
- Firewalls, IDS/IPS products
- Tamper-resistant microprocessors and microcontrollers
The following are considered critical products:
- Hardware devices with security boxes
- Smart meter gateways
- Chip cards, including security elements
To explain the product types, the European Commission published an additional document last year. See the link further down on this page.
Harmonised standards: status of standardisation work
In connection with the option of a manufacturer’s declaration under Module A for Class I products, the term harmonised standards has come up. To this end, some time ago the Commission asked the European standardisation bodies CEN/CENELEC and ETSI, in a standardisation request, to develop horizontal and vertical standards for all product types and ESR topics. This work is ongoing; publications are expected to be released step by step over the coming period.
Cyber Resilience Act deadlines: September 2026 and December 2027
The CRA will become fully effective in December 2027, when the requirements become mandatory for all new products. However, it should not be underestimated that from September 2026 all affected manufacturers will already be required to report vulnerabilities that are actually being exploited to the supervisory authorities. Affected manufacturers therefore need to have established vulnerability management processes within a very short time in order to meet the legal requirements.
