Skip to content

EU Cyber Resilience Act (CRA)

The EU Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements sold in the European market.

Key points

  • Applies to all products with digital elements — hardware and software.
  • Introduces four classification tiers: STANDARD, IMPORTANT Class 1, IMPORTANT Class 2, CRITICAL.
  • Manufacturers must perform conformity assessments, maintain technical documentation, and provide security updates.
  • SBOM requirement — manufacturers must identify and document all components.
  • Vulnerability handling — mandatory CSAF advisories, coordinated disclosure, incident reporting within 24 hours.

How TrustSource helps