The European Union's Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements placed on the EU market. Its scope extends beyond traditional technology companies to a broad range of manufacturers, importers and distributors.

The Regulation entered into force on 10 December 2024. Its main provisions will apply from 11 December 2027, while reporting obligations for actively exploited vulnerabilities and severe incidents will apply from 11 September 2026.

For organisations affected by the CRA, including manufacturers, importers, and distributors that place such products on the EU market. preparation should begin now.

What does the CRA require?

The CRA introduces cybersecurity requirements across the design, development, production and maintenance of products with digital elements (including hardware and software products, connected devices, IoT products, and products incorporating embedded software). Manufacturers will need to:

  • Assess and manage cybersecurity risks throughout the product lifecycle.
  • Build cybersecurity into product design and development.
  • Establish processes to identify, handle and remediate vulnerabilities.
  • Provide security updates throughout the applicable support period.
  • Maintain technical documentation demonstrating compliance.
  • Maintain a Software Bill of Materials in a commonly used and machine-readable format covering at least the product's top-level dependencies.
  • Report actively exploited vulnerabilities and severe incidents within the required timelines.

These requirements mean that cybersecurity can no longer be treated as a point-in-time exercise. It must be embedded across the product lifecycle, involving product, engineering, cybersecurity, risk and compliance teams.

 

From compliance to product security

The CRA should not be viewed simply as a documentation or certification exercise.

Effective compliance depends on having the right capabilities in place — including secure-by-design development, cybersecurity risk assessment, vulnerability management, software supply-chain visibility, incident response and ongoing product support.

For many organisations, this will require changes to existing processes and governance arrangements.

 

Preparing for the CRA

Organisations should focus on four priorities:

  1. Understand your exposure: Identify products that may fall within the CRA and clarify your role in the supply chain.
  2. Assess readiness: Review current cybersecurity, vulnerability management, incident reporting, product lifecycle and documentation processes against the applicable requirements.
  3. Address key gaps: Prioritise areas such as secure development, vulnerability management, SBOMs, software supply-chain visibility and technical documentation.
  4. Establish a roadmap: Define ownership, resources and milestones well ahead of the December 2027 deadline.

The European Commission has also published practical guidance to support organisations in interpreting and implementing the CRA.

How Grant Thornton Cyprus can help

Our Digital Risk team helps organisations translate the CRA into a practical and sustainable compliance programme.

We can support with:

  • CRA scope and applicability assessments
  • Readiness and gap assessments
  • Cybersecurity risk and secure-by-design reviews
  • Penetration testing
  • Vulnerability and incident-response readiness
  • Supply-chain assessments
  • Technical documentation and conformity-assessment readiness
  • Prioritised implementation roadmaps

Our approach combines regulatory understanding with cybersecurity, risk and implementation expertise — helping organisations understand their CRA obligations, address gaps and build the capabilities needed to demonstrate compliance.

With the first reporting obligations applying from September 2026 and the main requirements following in December 2027, organisations should establish a clear view of their CRA exposure now.

To discuss what the Cyber Resilience Act means for your organisation, get in touch with Grant Thornton Cyprus's Digital Risk team.

 

Author:

Anna Papaonisiforou, Senior Manager, Digital Risk Services