In 2024, the European Union adopted the Cyber Resilience Act (“CRA“). The Regulation will become fully applicable on 11 December 2027. However, certain provisions will start to apply earlier, and timely preparation for compliance with the remaining obligations under the CRA is already advisable.
The CRA applies to so-called products with digital elementsThis broadly defined category encompasses both software and hardware whose purpose or intended use involves a direct or indirect connection to a device or network. Examples include both consumer products, such as smartwatches, smart toys, and smart home devices, as well as industrial software and hardware.
For a product to fall within the scope of the CRA, it must be:
The following categories generally remain outside the scope of the CRA:
The CRA divides products with digital elements into three categories:
In light of the evolving cybersecurity threat landscape, the European Commission may, under certain circumstances, reclassify products between these categories.
Default products will constitute the majority of products falling within the scope of the CRA. These are products that do not present an elevated cybersecurity risk and are not classified as either important or critical products.
For such products, self-assessment of conformity will generally be sufficient. The manufacturer, importer, or distributor will be responsible for verifying compliance with the applicable cybersecurity requirements and issuing the relevant declaration of conformity.
Important products are listed in Annex III to the CRA and are further divided into two classes.
Class I covers products presenting a lower level of risk. In certain cases, self-assessment of conformity may also be available for these products. Examples include:
Class II covers products presenting a higher level of risk. For these products, conformity assessment by an independent third party will always be required. Examples include:
Critical products are listed in Annex IV to the CRA. Examples include:
For certain critical products, the European Commission may require obtaining of a specific European cybersecurity certification. Where such certification is not required, a conformity assessment conducted by an independent third party will nevertheless be mandatory.
Responsibility for ensuring conformity assessment rests primarily with the manufacturer.
Compliance with conformity assessment requirements includes, in particular:
In addition, the manufacturer must ensure product support for a period of at least five years, unless the product’s expected lifetime is shorter. During this period, the manufacturer is required to:
For the purposes of the CRA, a vulnerability means a weakness, reduced resilience, or defect in a product with digital elements that can be exploited as part of a cyber threat.
The obligations under the CRA vary depending on the role a market operator performs.
When selling products on the EU market in the ordinary course of business, a seller will generally act as a distributor. However, where products are imported directly from a non-EU country and placed on the Union market, the seller will be regarded as an importer.
If a person places a product on the market under its own name or trademark, or substantially modifies a product, it may be considered a manufacturer for the purposes of the CRA. In such cases, all obligations applicable to manufacturers will apply, including those relating to conformity assessment, technical documentation, product support, and the remediation of security vulnerabilities.
A manufacturer is required, among other things, to:
Manufacturers will also be required to report actively exploited vulnerabilities and severe incidents to the relevant authorities. This notification obligation will apply as early as 11 September 2026.
An importer may place a product on the EU market only after verifying, in particular, that:
In addition, the importer must:
A distributor is not required to conduct its own cybersecurity assessment of the product. However, it must verify, in particular, that:
Manufacturers, importers, and distributors of products with digital elements should implement appropriate control, record-keeping, and traceability procedures to facilitate compliance with the CRA.
In particular, it is advisable to maintain records of:
In addition, economic operators must be able to identify, for a period of ten years, both:
….
bpv BRAUN PARTNERS has advised IMMOFINANZ on the sale of Brno Business Park office buildings via a share deal to INFOND investment fund. The transaction was closed on March 9, 2018.
Pavel has been working with bpv since 2010, having previously spent several years at a large English law firm.
We would like to congratulate our longtime colleague, Lucie Kalašová, on her promotion to the position of partner. Congratulations!