Cyber Resilience Act 2026

The Cyber Resilience Act (CRA) took effect within the European Union (EU) in December 2024. It is intended to improve cybersecurity within the EU and provide users with more information and transparency regarding the security of their devices. The CRA particularly affects manufacturers of products with digital components. 

However, the text of the law is complex and therefore requires a great deal of time and effort to fully understand its details. For this reason, researchers at the Institute for Innovative Security at the Technical University of Applied Sciences Augsburg have set out to simplify it, particularly for manufacturers. 

Since September 2024, Prof. Dr. Dominik Merli, Professor of IT Security and Director of the Institute for Innovative Security (THA_innos), has been guiding companies through the CRA using THA_innos’s expertise—with easy-to-understand charts, explanations, and checklists. Tailored to the perspective of manufacturers.

Follow Prof. Merli now!

Cyber Resilience Act: Summary


What is the Cyber Resilience Act?

Here you can learn more about the background of the Cyber Resilience Act, its objectives, and the challenges it aims to address within the European Union. 

What are the objectives of the Cyber Resilience Act?

What exactly does the European Union want to change, and where does it want to go in terms of cybersecurity? Learn more about the overarching objectives of the CRA. 

What are the benefits of the Cyber Resilience Act?

Learn more about the projected benefits of the CRA for manufacturers and users in the European Union. And why SMEs could benefit from the CRA.

CRA Timeline—When Will the Cyber Resilience Act Take Effect?

The European Parliament has already adopted the CRA. However, the European Council still needs to approve it. The transition period begins on that date. But how long will it last, and what happens during that time?

What are products with digital elements?

The CRA refers to this term repeatedly. Here, you’ll learn what it means—and which products are covered by the CRA and which are not.

What are the CRA requirements?

What requirements does the Cyber Resilience Act impose on the cybersecurity of products in the European Union?

How to handle vulnerabilities in compliance with the CRA?

Vulnerabilities are inevitable. That’s why the CRA also specifies how manufacturers should respond when vulnerabilities are discovered. 

What product categories does the CRA recognize?

How manufacturers ensure their products comply with the CRA’s requirements also depends on which category their products fall into.

What is a conformity assessment, and how is it conducted?

There are various procedures manufacturers can use to confirm their products’ compliance. This also depends on the product category.

How does the CRA regulate free and open-source software?

FOSS falls under the CRA if it is integrated into a major product and is used commercially. 

How does the CRA regulate third-party components?

No manufacturer builds everything from scratch. Here’s how the Cyber Resilience Act handles third-party components. 

What must manufacturers do under the CRA when they modify their product?

Many modern products are regularly enhanced through software updates. But do these changes also affect whether a product is CRA-compliant?

Support Period—What Must Manufacturers Consider Under the CRA?

Under the CRA, manufacturers must guarantee a certain support period. Read here to find out how long this must be and what exceptions apply. 

Who are the key players under the CRA?

The Cyber Resilience Act doesn’t just affect manufacturers. Many other stakeholders—such as government agencies and testing laboratories—must also comply with the new guidelines. 

How do manufacturers interact with other stakeholders under the CRA?

Manufacturers must adhere to certain processes. Read here about three of these interactions in which the manufacturer is required to take action. 

How do manufacturers report an exploited vulnerability in compliance with the CRA?

Reporting actively exploited vulnerabilities is a key obligation for manufacturers. Here, you can read about how the process works and the deadlines manufacturers must meet. 

How do manufacturers report a cybersecurity incident?

A cybersecurity incident under the CRA occurs at the manufacturer or within its supply chain. Here’s how to report the incident and comply with the relevant obligations. 

How does the CRA support small and medium-sized enterprises in implementation?

The CRA isn’t just a collection of regulations. Rather, it also requires individual EU member states to provide support for small and medium-sized enterprises. Learn more about the planned measures.

What happens if a product no longer complies with the CRA?

A product that previously complied with the CRA’s requirements may, under certain circumstances, no longer comply. Read here to find out how this can happen and what the next steps are. 

What are the BSI’s responsibilities under the CRA?

The BSI is assigned specific tasks under the CRA. In return, it is granted certain powers but also has obligations. Read more here.

More about THA_innos

The Institute for Innovative Safety and Security at the Technical University of Applied Sciences Augsburg (THA_innos) helps organizations of all sizes operate safely and sustainably in an interconnected world. Through the institute’s innovative approaches, systems, products, and personnel become resilient to digital threats to the economy and society.