Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

Cyber Resilience Act

How does an Indian manufacturer meet the EU cybersecurity requirements for connected products?

Answer

Any product with digital elements, from a camera or router to an industrial gateway or a piece of software sold separately, must be designed to the essential cybersecurity requirements and supplied with security updates throughout its support period. Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national authority within twenty-four hours of becoming aware of them.

What has to be done

  • Run a cybersecurity risk assessment for the product and document it as part of the technical file.
  • Ship secure by default: no universal factory passwords, and attack surface reduced to what the product needs.
  • Maintain a vulnerability handling process and a software bill of materials for the whole support period, and state that period plainly to the buyer.
  • Provide free security updates for the support period, separately from feature updates.
  • Set up the reporting path in advance: early warning within 24 hours, a vulnerability notification, and a final report.
  • List the cybersecurity requirements in the declaration of conformity; omitting them invalidates the CE marking.

Citations

Related questions

Related requirements

China corridor

The same requirement is published for Chinese exporters in simplified Chinese: 网络韧性法案

Source and version

Sector
IoT, networking, embedded software
Read date
2026-08-26
Register version
in-export-v1.0.0
Address
/in/export/cra

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift