Meet EU cybersecurity requirements for products with digital elements.The EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements placed on the EU market. It imposes obligations on manufacturers across the product lifecycle — secure design, vulnerability handling, and incident reporting — backed by CE marking.
The CRA applies to manufacturers, importers, and distributors of hardware and software products with digital elements sold in the EU.
Who needs EU Cyber Resilience Act?
Product manufacturers
Makers of connected hardware and software products sold in the EU.
Software vendors
Companies placing software products with digital elements on the EU market.
Key components
Secure by design
Cybersecurity built into products from the design phase.
Vulnerability handling
Processes to identify, document, and remediate vulnerabilities.
Incident reporting
Report actively exploited vulnerabilities and incidents to authorities.
CE marking
Conformity assessment and CE marking for compliant products.
How DSALTA helps with EU Cyber Resilience Act
Activate EU CRA
Select the EU Cyber Resilience Act from the Frameworks page. DSALTA maps requirements to controls.
Frequently asked questions
What products are covered?
What products are covered?
Products with digital elements — connected hardware and software — placed on the EU market, with stricter rules for critical products.
What are the reporting obligations?
What are the reporting obligations?
Manufacturers must report actively exploited vulnerabilities and severe incidents to authorities within defined timelines.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)