Businesses face challenges navigating the broad scope and detailed technical requirements of the EU Cyber Resilience Act for their digital products.
We offer expert guidance, conformity assessment support, and testing services to help businesses understand and meet CRA obligations, ensuring their products can be legally and securely placed on the EU market.
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents under Article 14 of the EU Cyber Resilience Act.
Once an organisation becomes aware of a reportable vulnerability or incident, the first notification may be required within 24 hours, followed by a more detailed notification within 72 hours. Being technically prepared is therefore not enough: organisations also need clear responsibilities, escalation rules, documentation and reporting workflows.
Eurofins Electrical & Electronics can help you assess your current level of readiness and strengthen the processes needed to respond within these regulatory timelines.
We review your existing vulnerability and incident reporting process to determine whether it can support the CRA Article 14 requirements and associated reporting deadlines.
We identify gaps between your current practices and the expected reporting requirements, helping you prioritise the areas that require immediate attention.
We help you clarify who must detect, assess, approve, escalate and report a vulnerability or severe security incident—including the actions to take when key decision-makers are unavailable.
We support the development or improvement of practical documentation, including reporting procedures, responsibility matrices, escalation workflows and evidence-recording templates.
We help your technical, cybersecurity, legal and communications teams understand how information should circulate internally and how reporting decisions can be made within the required timeframe.
Depending on your organisation’s needs and current level of maturity, our support may include:
Article 14 reporting obligations apply from 11 September 2026, ahead of the CRA’s broader application from 11 December 2027. Preparing now can reduce uncertainty, clarify responsibilities and help your teams respond more effectively when a reportable event occurs.
Our services are designed to support manufacturers, importers, and distributors in achieving compliance with the EU Cyber Resilience Act.
Our core services include:
These services help ensure your products meet the stringent cybersecurity standards required for the EU market.
The EU Cyber Resilience Act (CRA), which entered into force on December 10, 2024, establishes a comprehensive framework for cybersecurity requirements for products with digital elements placed on the EU market. Its primary objective is to improve the cybersecurity of hardware and software products throughout their lifecycle, ensuring a higher level of security for consumers and businesses across the European Union.
The CRA introduces mandatory cybersecurity requirements for manufacturers, importers, and distributors, aiming to address the growing threat landscape and the current low level of cybersecurity in many digital products.
The CRA outlines essential cybersecurity requirements that products with digital elements must meet. These include:
The CRA imposes specific obligations on actors in the supply chain:
The CRA applies to a broad range of products with digital elements whose intended or foreseeable use includes a direct or indirect connection to a device or network. This covers most hardware and software products, including IoT devices, software applications, and components. Certain products already covered by existing EU legislation (e.g., medical devices, vehicles, aviation) and specific types of open-source software are generally excluded. Products are categorised based on risk level, which determines the required conformity assessment procedure (self-assessment or third-party evaluation).
The CRA grants market surveillance authorities in EU Member States powers to enforce the regulations, including requesting documentation, conducting checks, and imposing corrective measures. Non-compliance can lead to significant penalties, with maximum fines reaching €15 million or 2.5% of the company's total worldwide annual turnover, whichever is higher.
Eurofins Electrical & Electronics can help manufacturers, importers, and distributors navigate the complexities of the CRA. We offer expert testing, assessment, and advisory services to ensure products meet mandatory security requirements, such as banning default passwords, implementing vulnerability disclosure policies, and providing security update transparency.
This support helps businesses achieve compliance efficiently, access the EU market, and mitigate potential penalties.
Connect with our experts today. We offer comprehensive EU cybersecurity testing and certification services, simplifying compliance and accelerating your market entry.