
Whether it’s a security incident, a vulnerability or any other CRA-related report: here you’ll find the right way to submit your report to us quickly and easily.
The Cyber Resilience Act (CRA)

From 11 December 2027, products with digital elements in the EU must comply with the requirements of Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements throughout their entire product lifecycle.
Requirements and Objectives
The CRA establishes a mandatory minimum level of cybersecurity for products with digital elements. It requires manufacturers to design these products – from development through to decommissioning – in such a way that they are comprehensively protected against cyber-attacks. The aim is to strengthen cybersecurity in the EU in the long term, thereby minimising economic risks and improving the protection of product users.
Only CRA-compliant products will be awarded the CE mark after 11 December 2027 and may be placed on the EU market from that date onwards. In the long term, the standards thus established will enhance the reliability and security of systems and processes.
The obligation for manufacturers, enshrined in the CRA, to provide information on security features and potential risks enables users to make informed decisions when selecting products, ensuring that their equipment and systems are protected as effectively as possible against cyber-attacks and failures.
The CRA categorises products according to function, intended use and risk level. Specific requirements must be met for each of these categories. Whilst a self-declaration based on the state of the art is sufficient for Category 1, harmonised standards must be applied to products in higher categories. If this is not possible for the manufacturer, notified bodies must be involved.
Requirements and Objectives
The CRA establishes a mandatory minimum level of cybersecurity for products with digital elements. It requires manufacturers to design these products – from development through to decommissioning – in such a way that they are comprehensively protected against cyber-attacks. The aim is to strengthen cybersecurity in the EU in the long term, thereby minimising economic risks and improving the protection of product users.
Only CRA-compliant products will be awarded the CE mark after 11 December 2027 and may be placed on the EU market from that date onwards. In the long term, the standards thus established will enhance the reliability and security of systems and processes.
The obligation for manufacturers, enshrined in the CRA, to provide information on security features and potential risks enables users to make informed decisions when selecting products, ensuring that their equipment and systems are protected as effectively as possible against cyber-attacks and failures.
The CRA categorises products according to function, intended use and risk level. Specific requirements must be met for each of these categories. Whilst a self-declaration based on the state of the art is sufficient for Category 1, harmonised standards must be applied to products in higher categories. If this is not possible for the manufacturer, notified bodies must be involved.
The CRA Regulation sets out clear requirements to achieve these objectives:
Safety throughout the entire life cycle
From planning, through design, development and production, to delivery, maintenance and decommissioning.
Documentation of potential safety risks
Systematic and transparent identification, assessment and documentation of potential threat scenarios throughout the entire product life cycle.
Conformity assessment procedures and CE marking
Depending on the risk class determined and a corresponding conformity assessment, CE marking is applied; this is a prerequisite for EU-wide authorisation and guarantees users the necessary safety standards.
Security updates
To provide users with long-term planning certainty for the products they use, manufacturers are obliged to provide free security updates throughout the entire product life cycle.
Structured vulnerability management
Actively exploited vulnerabilities and security incidents are documented via a central reporting platform.
Practical documentation
Comprehensive, clear and easy-to-understand documentation that provides all the information needed to install, integrate, operate and decommission the products safely. This eliminates the need for paper-based manuals.
ehb electronics supports its customers in complying with the Cyber Resilience Act
The CRA makes products safer and provides planning certainty – but it also presents new challenges for manufacturers. Our experts assist users of our products in carrying out a comprehensive analysis of their machinery and plant. Our staff ensure that bespoke, customer-specific products comply with the CRA, offer the highest level of security and guarantee reliable operation.

Whether it’s a security incident, a vulnerability or any other CRA-related report: here you’ll find the right way to submit your report to us quickly and easily.

![[Translate to Englisch:] Die Grafik veranschaulicht den zeitlichen Verlauf von der am 11.September 2026 in Kraft tretenden CRA-Meldepflicht, dass heißt Unternehmen, die Produkte mit digitalen Elementen herstellen, müssen eine Meldestelle auf ihrer Website einrichten, damit Kunden Cyberangriffe auf Produkte melden können. Am 11. Dezember 2027 ist dann die volle CRA-Pflicht und CE-Kennzeichnung verpflichtend.](/fileadmin/_processed_/d/9/csm_Zeitstrahl_CRA-Meldepflicht-ehb-electronics.de_1a072e2822.png)
