EU Cyber Resilience Act
October 15, 2024
EU Cyber Resilience ActOctober 15, 2024 The European Union has now adopted the Cyber Resilience Act (CRA) mandating minimum cybersecurity requirements for products with digital elements placed on the European market. The Regulation will come into force this year and obligations will apply in 36 months - with some exceptions applying earlier. The CRA addresses the supply chain of all products, hard- and software, which are capable of a direct or indirect connection to a device or network. Previously, cyber security minimum standards were already mandatory for certain products on a sector-specific basis, but not uniformly for all products. The Regulation addresses manufacturers, producers and importers to make products with digital elements safe to use, resilient against cyber threats and to adequately disclose security features. Impact and actionsObligations under the CRA include “security by design” and specific security safeguards that products must meet. This includes risk assessments, cyber incident reporting, vulnerability management and transparency obligations to ensure a high level of cybersecurity throughout the entire product lifecycle. The European Union Agency for Cybersecurity (ENISA) will be closely involved to provide cybersecurity certification standards, e.g. EUCC, EUCS, EU5G and EUAI, and to monitor large scale vulnerabilities in the European market. For example, software and hardware products will bear the “CE-marking” to indicate that they comply with the regulation’s requirements. Although the CRA harmonises standards across the EU, some member states are taking extra steps. E.g., the German BSI is publishing technical guidelines and Austria has published an implementation law. Practical outlookBusinesses will now need to review which of their products are likely to fall within the scope of the regulation and the extent to which they meet essential security requirements. Especially considering the timeline of product design, manufacturers are now getting ready for Q4 of 2027. In cases of non-compliance, products could be restricted from the EU market. Like pre-existing laws such as the NIS2 or the GDPR, the CRA introduces administrative fines of up to EUR 15 mio or 2.5% of a business's annual worldwide turnover. Please reach out to your Eversheds Sutherland team to discuss any queries around the CRA and its implementation. Our worldwide team is here to assist you and put you in touch with the right contacts. Latest InsightsLatest News
Latest Events
legal updates September 10, 2026 EU WEEE Directive Reform: Tighter Rules, Rising Costs guides and reports September 10, 2026 EU Cyber Resilience Act: Single Reporting Platform Goes Live legal updates September 10, 2026 Hong Kong: PCPD issues further guidance on best practices in the use of age... legal updates September 10, 2026 Global Life Sciences & Healthcare Bulletin client news September 11, 2026 We advised Santa's Holding Oy, Lappset Group Oy and the Länkinen family on ... client news September 10, 2026 We advised Ruby Group on a hotel development project in Helsinki client news September 03, 2026 We advised TMF Finland Oy on its acquisition of Navigator Partners Oy client news September 01, 2026 We advised Ilkka Oyj on its acquisition of Custobar Oy in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States virtual Employment law in the Kingdom of Saudi Arabia September 29, 2026 9.30am - 12.30pm (BST) Virtual in-person Labor relations conference - turning legal change into workplace reality October 08, 2026 10.00am - 4.00pm (BST) London, United Kingdom |