< Back to all clusters
[TECHNOLOGY] · Croatia, EU · 2 sources

started · updated

EU Cyber Resilience Act mandates stricter security for digital products

The European Union's Cyber Resilience Act (CRA) is set to strengthen cybersecurity for hardware and software products, including consumer devices like smartwatches and baby monitors. Under the new regulations, manufacturers must report actively exploited vulnerabilities and serious security incidents. Specifically, an early warning must be issued within 24 hours, followed by a full notification within 72 hours. Final reports are required within 14 days of a fix for vulnerabilities or within one month for serious incidents.

These obligations apply to all digital products available in the EU, including those already on the market. Reporting will be managed through a centralized CRA reporting platform maintained by the European Union Agency for Cybersecurity. To assist with compliance, the Commission has released practical guidelines for developers and businesses. Compliance will be monitored by national market surveillance authorities, and the CE mark will serve as an indicator that products meet CRA requirements.

In the context of these evolving rules, discussions are highlighting the shifting responsibility of cybersecurity toward corporate boards. There is an increasing focus on protecting critical infrastructure—such as hospitals, banks, and energy sectors—and addressing the challenges of digital sovereignty and the growing security threats posed by artificial intelligence.

Entities

Cyber Resilience Act · European Union · European Union Agency for Cybersecurity