riki32-scam-7503835

Recent Developments in Cyber Resilience 

2. 9. 2026

Newsletter

bpv BRAUN PARTNERS

In 2024, the European Union adopted the Cyber Resilience Act (“CRA“). The Regulation will become fully applicable on 11 December 2027. However, certain provisions will start to apply earlier, and timely preparation for compliance with the remaining obligations under the CRA is already advisable.

The CRA applies to so-called products with digital elementsThis broadly defined category encompasses both software and hardware whose purpose or intended use involves a direct or indirect connection to a device or network. Examples include both consumer products, such as smartwatches, smart toys, and smart home devices, as well as industrial software and hardware.

For a product to fall within the scope of the CRA, it must be:

  • capable of communicating with another device or network, whether through a wired or wireless connection; and
  • placed on the EU market in the course of a commercial activity.

The following categories generally remain outside the scope of the CRA:

  • certain products subject to specific sectoral regulation (for example, motor vehicles);
  • products intended exclusively for defence and national security purposes;
  • cloud services and software-as-a-service (SaaS) solutions, provided that they do not form part of a specific product; and
  • non-commercial open-source software, subject to certain exceptions.

A.    Categories of Products by Risk Level

The CRA divides products with digital elements into three categories:

  1. default products
  2. important products
  3. critical products

In light of the evolving cybersecurity threat landscape, the European Commission may, under certain circumstances, reclassify products between these categories.

  1. Default Products

Default products will constitute the majority of products falling within the scope of the CRA. These are products that do not present an elevated cybersecurity risk and are not classified as either important or critical products.

For such products, self-assessment of conformity will generally be sufficient. The manufacturer, importer, or distributor will be responsible for verifying compliance with the applicable cybersecurity requirements and issuing the relevant declaration of conformity.

  1. Important Products

Important products are listed in Annex III to the CRA and are further divided into two classes.

Class I covers products presenting a lower level of risk. In certain cases, self-assessment of conformity may also be available for these products. Examples include:

  • routers;
  • smart locks; and
  • wearable electronic devices (wearables).

Class II covers products presenting a higher level of risk. For these products, conformity assessment by an independent third party will always be required. Examples include:

  • firewalls;
  • microprocessors; and
  • tamper-resistant microcontrollers.
  1. Critical Products

Critical products are listed in Annex IV to the CRA. Examples include:

  • smart metering systems for energy consumption; and
  • payment terminals.

For certain critical products, the European Commission may require obtaining of a specific European cybersecurity certification. Where such certification is not required, a conformity assessment conducted by an independent third party will nevertheless be mandatory.

  1. Obligations of Manufacturers

Responsibility for ensuring conformity assessment rests primarily with the manufacturer.

Compliance with conformity assessment requirements includes, in particular:

  • preparation oftechnical documentation;
  • issuance of anEU Declaration of Conformity, through which the manufacturer assumes responsibility for compliance with the requirements of the CRA;
  • affixing theCE marking to the product; and
  • subsequently placing the product on the market.

In addition, the manufacturer must ensure product support for a period of at least five years, unless the product’s expected lifetime is shorter. During this period, the manufacturer is required to:

  • address identified security vulnerabilities; and
  • provide security updates.

For the purposes of the CRA, a vulnerability means a weakness, reduced resilience, or defect in a product with digital elements that can be exploited as part of a cyber threat.

  1. Obligations of Manufacturers, Importers and Distributors

The obligations under the CRA vary depending on the role a market operator performs.

When selling products on the EU market in the ordinary course of business, a seller will generally act as a distributor. However, where products are imported directly from a non-EU country and placed on the Union market, the seller will be regarded as an importer.

If a person places a product on the market under its own name or trademark, or substantially modifies a product, it may be considered a manufacturer for the purposes of the CRA. In such cases, all obligations applicable to manufacturers will apply, including those relating to conformity assessment, technical documentation, product support, and the remediation of security vulnerabilities.

A manufacturer is required, among other things, to:

  • ensure that the product is designed, developed, and manufactured in accordance with the applicable cybersecurity requirements;
  • carry out a cybersecurity risk assessment before placing the product on the market;
  • prepare and maintain up-to-date technical documentation;
  • conduct the required conformity assessment, issue an EU Declaration of Conformity, and affix the CE marking to the product;
  • specify and make available to purchasers the product support period, at least by indicating the relevant month and year in which support will end;
  • effectively remedy vulnerabilities and provide security updates throughout the support period, which will generally be at least five years unless the expected lifetime of the product is shorter;
  • provide users with clear and comprehensible information regarding the secure use of the product, installation of updates, known risks, secure disposal of the product, and removal of user data;
  • establish a contact point for vulnerability reporting and implement procedures for handling reported vulnerabilities; and
  • take appropriate corrective measures and, where necessary, withdraw or recall the product if non-compliance is identified.

Manufacturers will also be required to report actively exploited vulnerabilities and severe incidents to the relevant authorities. This notification obligation will apply as early as 11 September 2026.

An importer may place a product on the EU market only after verifying, in particular, that:

  • the manufacturer has carried out the required conformity assessment and prepared the technical documentation;
  • the product bears the CE marking;
  • an EU Declaration of Conformity accompanies the product;
  • the product includes the required information and user instructions;
  • the manufacturer is properly identified and has specified the end date of the product support period; and
  • the product and the manufacturer’s procedures comply with the requirements of the CRA.

In addition, the importer must:

  • Indicate its identification and contact details on the product, its packaging, or the accompanying documentation;
  • Retain a copy of the EU Declaration of Conformity and ensure the availability of the technical documentation for at least ten years, or for a longer period where the product support period exceeds ten years;
  • Refrain from placing the product on the market where it has reason to believe that the product is not compliant;
  • Take appropriate corrective measures and, where necessary, arrange for the withdrawal or recall of the product after it has been placed on the market; and
  • Inform the manufacturer of any identified vulnerability and, where a significant cybersecurity risk exists, also notify the competent market surveillance authorities.

A distributor is not required to conduct its own cybersecurity assessment of the product. However, it must verify, in particular, that:

  • The product bears the CE marking;
  • The manufacturer and, where applicable, the importer are properly identified;
  • The product is accompanied by the required information and instructions;
  • Users are provided with information regarding the secure use of the product and the availability of updates;
  • At least the expected duration of the product support period is indicated, including the month and year in which support will end; and
  • The necessary documentation has been provided, in particular the EU Declaration of Conformity or a simplified declaration containing a reference to the full text of that declaration.

Manufacturers, importers, and distributors of products with digital elements should implement appropriate control, record-keeping, and traceability procedures to facilitate compliance with the CRA.

In particular, it is advisable to maintain records of:

  1. suppliers and manufacturers;
  2. individual product models and production batches; and
  3. declarations of conformity and related documentation.

In addition, economic operators must be able to identify, for a period of ten years, both:

  • the person or entity from whom the product was obtained; and
  • the person or entity to whom the product was subsequently supplied.

….

This material is for general information on current topics only, it is not advice. It does not take into account any special circumstances, financial situations or special requirements of the addressees. Recipients should therefore always seek appropriate professional services for the information provided. Notwithstanding the careful compilation of this material, bpv Braun Partners s.r.o. advokáti, its partners, associates or co-operating solicitors and tax advisers cannot guarantee the accuracy or completeness of the information contained herein and accepts no responsibility for acting or refraining from acting on the basis of the information contained in this material

Similar news

Press Releases
sign-a-contract
26. 3. 2018 | bpv BRAUN PARTNERS

bpv BRAUN PARTNERS advises IMMOFINANZ in sale of Brno Business Park

bpv BRAUN PARTNERS has advised IMMOFINANZ on the sale of Brno Business Park office buildings via a share deal to INFOND investment fund. The transaction was closed on March 9, 2018.

Press Releases
Pavel Vinbtr ořez-min

Pavel Vintr now a partner at bpv BRAUN PARTNERS

Pavel has been working with bpv since 2010, having previously spent several years at a large English law firm.

Press Releases
LKA_bpv_ctverec
9. 1. 2024 | bpv BRAUN PARTNERS

Lucie Kalašová as a new partner with bpv Braun Partners

We would like to congratulate our longtime colleague, Lucie Kalašová, on her promotion to the position of partner. Congratulations!