Forum Diskusi dan Komunitas Online

Full Version: EU Cyber Resilience Act Checklist: Requirements for Software & Digital Product Manufa
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Most UK manufacturers tracking the EU CRA are watching one deadline. In fact, there are three, and they don’t land the same way. Compliance with the EU Cyber Resilience Act can be managed with the help of a checklist, enabling manufacturers to monitor the key stages and to plan for the compliance requirements in time. Conformity assessment body provisions apply from June 11, 2026. Vulnerability and incident reporting obligations start September 11, 2026, and they apply to products already sitting on shelves, not just new releases. Full compliance, including CE marking, doesn’t land until December 11, 2027. This is the date from which the CRA’s main manufacturer obligations become fully applicable, including the core product cybersecurity, vulnerability-handling, conformity-assessment, technical documentation, and CE-marking requirements. 

Get the sequencing wrong, and you’ll either scramble in September because you thought you had until 2027. Or you’ll over-invest in conformity assessment work eighteen months before authorities actually enforce it. The CRA establishes maximum administrative-fine levels for certain infringements, including fines of up to €15 million or 2.5% of the infringing manufacturer’s total worldwide annual turnover for the preceding financial year, whichever is higher, subject to the regulation’s specific provisions and exemptions. 

What Counts as a Product with Digital Elements Under the EU CRA?

Certain software components placed separately on the Union market can fall within the CRA’s scope where they meet the definition of a product with digital elements. Whether a particular open-source or commercial component is covered depends on how it is made available and the applicable CRA scope rules. 

EU CRA Product Risk Categories: How Will You Be Assessed?

The EU CRA distinguishes ordinary products with digital elements from specified important products in Class I and Class II and certain critical products. Classification depends primarily on whether the product has the core functionality of a category listed in Annex III or Annex IV, rather than simply on the manufacturer’s own assessment of its cybersecurity risk. 

Password managers and firewalls are examples of important products covered by Annex III, with password managers in Class I and firewalls in Class II. Critical products are separately identified under Annex IV and include categories such as certain hardware security devices, smart-meter gateways and smartcards or secure elements. 

Important products in Classes I and II are subject to additional conformity-assessment requirements. The exact route depends on the product class and, for Class I products, on the applicable harmonised standards, common specifications or cybersecurity certification arrangements. 

Ultimately, getting this classification wrong at the start of a product’s development cycle is the single most expensive mistake to unwind later. That’s because the documentation trail differs depending on which tier applies. Consider a team that builds its technical file assuming self-assessment. If a notified body later needs to review it, that team is often looking at months of rework, not a quick reclassification. It’s worth settling this question with legal and engineering input together, early, rather than defaulting to whichever tier seems administratively lighter.

Source: https://qualysec.com/eu-cyber-resilience-act-checklist/