Cyber Resilience Act - latest updates from the European Commission
Yesterday the EC Policy team gave an update on the Cyber Resilience Act (CRA) which is set to become the latest cyber security regulation to govern connected products. Points to note are:
- New cyber security standards expected from standards bodies by Dec 2026
- A centralised vulnerability reporting database will be developed by Enisa by Sept 2026 - in time for CRA reporting requirements
- Classifications of "Important" and "Critical" products are to be defined in more detail by Dec 2025
In general the CRA is a new set of cybersecurity rules for placing of products on the EU - it will expand on RED requirements (coming into force Aug 1st 2025) by massively increasing the range of products that fall into its scope - products with "Digital Elements" will include software products, apps, and remote data processing solutions as well as hardware. Another key element is that the CRA is centred around the premise that compliance is maintained throughout the product lifetime.
CRA will come into force in two stages which are:
- Vulnerability reporting obligations: 11th September 2026
- Essential requirements: 11th December 2027
To prepare for CRA - SafeShark is providing product testing against the EC mapping for current standards e.g. EN 303 645 and EN 18031, that can already provide a level of conformity for CRA - helping you get ahead of the legislation.
SafeShark also provides straightforward PSTI and RED compliance testing, that allows you to quickly prove your consumer electronic product is ready for UK or EU market access in order to meet the 1st Aug deadline. Get in touch to find out more from our experts.