EU Cyber Resilience Act (CRA) Compliance
Introduction
The EU Cyber Resilience Act (CRA) introduces strict cybersecurity standards for all hardware and software products with digital elements sold within the European market. Software creators, MedTech developers, and SaaS providers face legal mandates covering security-by-design, mandatory Software Bill of Materials (SBOM) tracking, and rapid 24-hour vulnerability reporting to ENISA.
The comparison
Mandatory CRA Requirements for Digital Products
The EU Cyber Resilience Act (CRA) establishes hardware and software security rules for products with digital elements sold within the EU market.
- Security by Design: Software products must be delivered without known exploitable vulnerabilities and configured securely by default.
- Vulnerability Handling: Manufacturers must document, patch, and publicly report actively exploited vulnerabilities within 24 hours to ENISA.
- Software Bill of Materials (SBOM): Companies must maintain an up-to-date SBOM covering all third-party and open-source dependencies.
- CE Marking for Software: Compliant products must bear the CE mark to demonstrate conformity before commercial release in the EU.