What is the CRA?

The Cyber Resilience Act (CRA) is a pivotal regulation introduced by the European Commission to ensure the cybersecurity of products with digital elements. This act mandates that manufacturers, importers, and distributors of such products comply with stringent cybersecurity requirements throughout the product lifecycle, from design to disposal. By enforcing these standards, the CRA aims to enhance the overall security of digital products available in the EU market, thereby protecting consumers and businesses from cyber threats. The CRA is a critical step towards building a more secure digital ecosystem, reflecting the EU's commitment to safeguarding its digital infrastructure. 

Key considerations

  • Categorization of products: Products are classified based on their potential impact on society into Default, Important (Class I and Class II), and Critical categories. 
  • Conformity assessment: These classes are based on the level of security assurance required for the products, and they determine the type of conformity assessment procedure that applies to them. 
  • Mandatory cybersecurity measures: All products must meet specific cybersecurity requirements based on their intended purpose, ensuring protection against cyber threats. 
  • European cybersecurity certification: Critical products must obtain a European cybersecurity certificate, demonstrating compliance with the highest security standards. 
  • Lifecycle security: Cybersecurity measures must be implemented throughout the entire lifecycle of the product, from design to disposal. 

What you need to know

  • Understand your obligations: Familiarize yourself with the essential cybersecurity requirements for your product to ensure compliance with the CRA's standards. 
  • Invest in security: Prioritize investment in cybersecurity measures to not only meet regulatory requirements but also enhance the resilience and trustworthiness of your products. 
  • Stay informed: Keep up-to-date with the latest developments in cybersecurity regulations and best practices to maintain compliance and protect your business from potential threats. 

By adhering to the CRA, you not only ensure compliance but also contribute to a safer digital environment, fostering trust and security for all stakeholders. 

Webinar: Preparing for CRA Compliance – From Guidance to Action

Following the publication of the European Commission's CRA guidance and the introduction of CRA manufacturer reporting obligations on 11 September 2026, organizations supplying products with digital elements to the European market are entering a new phase of CRA compliance. In this webinar, we will summarize the most important interpretations from the CRA guidance, discuss the key changes compared to the draft version, and explain what organizations should be doing now to prepare for compliance.

In today's interconnected world, the security of digital products is paramount. The Cyber Resilience Act (CRA) sets the standard for cybersecurity, ensuring that products with digital components are secure throughout their lifecycle. DNV Cyber helps you navigate these requirements, providing expert guidance and solutions to achieve compliance and enhance your product's resilience. By prioritizing your product’s cybersecurity, you not only build trust with your customers but also ensure your products are compliant, competitive, and ready to succeed in the EU market.  

How DNV Cyber can support your CRA journey 
 
Whether you are determining how the CRA applies to your products, assessing your readiness, or implementing the necessary changes, DNV Cyber can support you at every stage of the journey. Our CRA services include:    
 

  • CRA applicability assessment 
    Understand which products are affected by CRA. 
    Identify in-scope products, classifications, and obligations. 
  • Process gap analysis 
    Assess whether your processes support CRA. 
    Identify lifecycle, governance, and evidence gaps.  
  • Product gap analysis 
    Assess whether a product needs changes. 
    Identify security, risk, and technical evidence gaps.  
  • Implementation support 
    Turn plans into practical improvements. 
    Access specialist expertise to close identified gaps.  
  • Certification & independent evidence 
    Build confidence through independent assurance. 
    Demonstrate product security with recognised third-party evidence. 

Why DNV Cyber

We provide expert guidance to help you navigate the complexities of the CRA. Our deep understanding of the CRA's requirements, combined with our proficiency in implementing, developing, and testing products compliant with the IEC 62443 standard, ensures that your products not only achieve compliance but also exhibit resilience and security. By partnering with us, you can confidently bring secure, compliant, and competitive products to the EU market. 

DNV Cyber Compass

DNV Cyber Compass

Which key cybersecurity regulations, directives or regulatory frameworks could apply to your organization’s activities in Europe? Get rapid guidance with this free online tool

IoT and Product Security

Secure your IoT innovations to ensure a competitive edge. DNV Cyber provides a range of IoT & Product Security services to strengthen and keep your economic engine running smoothly by helping you build secure, compliant, and resilient products and software. 

Increasing trust in your product is crucial for success in the EU market. To comply with the Cyber Resilience Act (CRA), it's essential to embed security throughout the product lifecycle. This means starting with secure design principles, conducting thorough risk assessments, and maintaining effective vulnerability management practices.

  • Jukka Leskio, Head of IoT & Product Security, DNV Cyber