The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for digital products sold in the EU, including software, hardware, and connected devices. It establishes security-by-design and security-by-default as legal obligations.
Manufacturers must identify vulnerabilities, apply secure development practices, and provide timely security updates. Products that process personal data must align CRA obligations with GDPR requirements, creating a new compliance layer for technology vendors.
This regulation significantly expands the role of compliance professionals beyond organizational processes to product lifecycle governance.
Official source:
European Commission – Cyber Resilience Act
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act