If you weren’t quite sure about the EU Cyber Resilience Act, this is what it does:
The Cyber Resilience Act (CRA) Regulation establishes mandatory cybersecurity requirements for “products with digital elements” (PDEs) that are placed on the EU market, in the course of commercial activity, whether in return for payment or free of charge. The stated objectives are: 1) ensuring that manufacturers improve the security of PDEs; 2) a coherent cybersecurity framework for hardware and software producers; 3) enhancing transparency; and 4) enabling businesses and consumers to use products with digital elements securely.
What are PDEs?
PDEs are software or hardware products and their remote data processing solutions, including software or hardware components being placed on the market separately. Remote data processing is processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the PDE from performing one of its functions.
The scope is intended to cover products that have the ability to exchange digital information (not just respond or activate in response to a signal) and therefore may put it at risk. Further, software downloaded and installed or supplied to the user and that executes on the user’s system (e.g., a browser extension or mobile app downloaded from an app store) is in scope. Hardware and software provided by the same manufacturer in order for a product to function (e.g., drivers or interface apps), are together a PDE, even if supplied separately. But software that executes remotely and is only accessed by the user, is not necessarily a PDE (e.g., websites, unless they support the functionality of a PDE through remote processing).
From last Friday, manufacturers of PDEs must report actively exploited vulnerabilities and severe security incidents using ENISA’s Single Reporting Platform. This is effectively first CRA deadline for manufacturers. The essential cybersecurity requirements — the ones most compliance programs are built around — don’t arrive until December 11, 2027, so we will not bore you with those here.
Continue Reading The EU Cyber Resilience Act’s Reporting Started last Friday, September 11. Here’s a Very, Very Brief Primer


