Skip to Content
RESOURCE ARTICLEMEMBER

Top 5 operational impacts of the CRA: Product cybersecurity as a market-access requirement

The EU Cyber Resilience Act makes cybersecurity compliance a prerequisite for selling connected products in the EU, requiring security-by-design and conformity assessments.

Published

Contributors:

Jenny Arlington

CIPP/E

Tech and Disputes, Cyber, Privacy, Data, and AI Senior Counsel

Akin

Rita Heimes

CIPP/E, CIPP/US, CIPM

Senior Counsel

Akin Gump Strauss Hauer & Feld

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

Editor's note

Cybersecurity law and regulation have been on a steady evolutionary journey, from protecting the "confidentiality, integrity and availability" of certain types of information, such as personal, classified and sensitive, to addressing the operational resilience of organizations as a whole. The latest and most consequential cybersecurity law facing enterprises globally is the EU Cyber Resilience Act, a unique product security law with extraterritorial reach that requires manufacturers of "products with digital elements" to develop those products with security-by-design, and fix and report vulnerabilities for years after placing them on the market.

The CRA has significant teeth: Products that do not conform may not be sold in the EU. 

Administrative fines can reach 2.5% of global annual turnover or 15 million euros (USD17 million, 12.7 million GBP), whichever is higher, alongside withdrawal and recall powers and rising exposure to EU representative class actions, a topic explored in part five of this series. But perhaps a more meaningful threat to the balance sheet is the immediate impact on sales, and there is no time to lose when it comes to compliance readiness as regards the CRA. 

Most CRA obligations will apply from 11 Dec. 2027. However, reporting obligations on actively exploited vulnerabilities and severe incidents will kick in 11 Sept. 2026, with provisions on notification to conformity assessment bodies already in force since June 2026.

This is the first in a five-part series on the operational impacts of the CRA. The series will cover the CRA's application to products, best practices for reporting vulnerabilities, conducting conformity assessments, managing compliance across other major EU digital responsibility regulations and more. 

Considering if the enterprise is subject to the CRA

Contributors:

Jenny Arlington

CIPP/E

Tech and Disputes, Cyber, Privacy, Data, and AI Senior Counsel

Akin

Rita Heimes

CIPP/E, CIPP/US, CIPM

Senior Counsel

Akin Gump Strauss Hauer & Feld

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership