GRCCopilot
Sign In
European Union

EU Cyber Resilience Act (CRA) — REGULATION (EU)

Mandatory cybersecurity requirements for products with digital elements sold within the European Union

Start Assessment Create Free Account
74
Controls
74
Questions
Active
Status

About this Framework

The Cyber Resilience Act (CRA) establishes a comprehensive cybersecurity regulatory framework for hardware and software products with digital elements placed on the EU market. The regulation introduces mandatory security-by-design requirements, vulnerability management obligations, coordinated vulnerability disclosure processes, security update responsibilities, and incident reporting requirements throughout the product lifecycle. Manufacturers, importers, and distributors must ensure that digital products meet defined cybersecurity requirements before entering the European market.

Key Control Domains

Secure Software Development
Security by Design
Vulnerability Management
Incident Reporting
Product Security
Supply Chain Security
Security Updates
Conformity Assessment
Lifecycle Cybersecurity

Who Needs This?

  • Software manufacturers
  • Hardware manufacturers
  • IoT device vendors
  • SaaS providers
  • Importers and distributors of digital products
  • Organizations selling digital products within the EU

Compliance Benefits

  • Demonstrates CRA compliance readiness
  • Improves product cybersecurity maturity
  • Reduces regulatory and legal risks
  • Strengthens vulnerability management processes
  • Enhances customer trust and product security

Official Reference

EU Cyber Resilience Act (CRA)
https://eur-lex.europa.eu

Assessment Details

Issuer / AuthorityEuropean Union
FrameworkEU Cyber Resilience Act (CRA) — REGULATION (EU)
Controls74
Questions74
StatusActive
Assessment Start03 Jun 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/eu-cyber-resilience-act-cra

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.