About this Framework
The EU Cyber Resilience Act (CRA — EU 2024/2847), adopted in October 2024, introduces mandatory cybersecurity requirements for all products with digital elements placed on the EU market — hardware, software, firmware and connected applications. Manufacturers must ensure security by design and default, provide security updates throughout the product support period (minimum 5 years), maintain a software bill of materials (SBOM), implement coordinated vulnerability disclosure and notify ENISA of actively exploited vulnerabilities within 24 hours. CE marking requirements for cybersecurity take full effect in 2027.
Key Control Domains
Who Needs This?
- Hardware and software product manufacturers selling in the EU
- IoT device and connected product manufacturers
- Commercial off-the-shelf (COTS) software developers
- Open-source foundations with commercial OSS distributions
- Technology importers and distributors in the EU market
Compliance Benefits
- CE marking eligibility — required for EU product market access
- Reduced product liability exposure from cybersecurity vulnerabilities
- Structured vulnerability disclosure and patch management programme
- Competitive advantage through verifiable, certified security assurance
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/eu-cyber-resilience-act-cra-assessment