Cyber Resilience Act
How does an Indian manufacturer meet the EU cybersecurity requirements for connected products?
Answer
Any product with digital elements, from a camera or router to an industrial gateway or a piece of software sold separately, must be designed to the essential cybersecurity requirements and supplied with security updates throughout its support period. Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national authority within twenty-four hours of becoming aware of them.
What has to be done
- Run a cybersecurity risk assessment for the product and document it as part of the technical file.
- Ship secure by default: no universal factory passwords, and attack surface reduced to what the product needs.
- Maintain a vulnerability handling process and a software bill of materials for the whole support period, and state that period plainly to the buyer.
- Provide free security updates for the support period, separately from feature updates.
- Set up the reporting path in advance: early warning within 24 hours, a vulnerability notification, and a final report.
- List the cybersecurity requirements in the declaration of conformity; omitting them invalidates the CE marking.
Citations
- Cyber Resilience Act (EU) 2024/2847Article node
Related questions
Related requirements
China corridor
The same requirement is published for Chinese exporters in simplified Chinese: 网络韧性法案
Source and version
- Sector
- IoT, networking, embedded software
- Read date
- 2026-08-26
- Register version
- in-export-v1.0.0
- Address
- /in/export/cra
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.