Frequently Asked Questions about the CRA
The second phase of the regulations will come into force on September 11, 2026, and companies must prepare to modify their practices based on the legal requirements for this period. From this date, the critical obligation for manufacturers to report actively exploited vulnerabilities and serious incidents will begin to be applied.
The regulation will be fully implemented on December 11, 2027. From this date, all products with digital components marketed in the EU must comply with all cybersecurity requirements (including CE marking).

EU Cyber Resilience Act: For safer and more secure digital products
This section aims to address the most common questions among manufacturers of connected products, mostly related to Articles 13, 14, 32, and 69 of the regulation.
Doubt about design
Would products designed before the implementation of the CRA that do not comply with the regulations need to be redesigned?
Not always. A product designed before the CRA can remain on the market without redesign, but only if the manufacturer can demonstrate, through risk assessment and technical documentation, that it achieves an adequate level of cybersecurity (meeting the applicable essential requirements).

Doubt about vulnerability notification
Should ENISA and customers be notified of vulnerabilities found in an integrated library?
Yes, if the vulnerability is present and exploitable in your product.
You don't have to wait until it has already been exploited on a customer's machine.

Doubt about stock
Can stock placed on the market before 11/12/2027 continue to be sold if it violates the regulations?
Yes, but only while stocks last. Stock already placed on the market before December 11, 2027, may be sold out in 2028, but new units manufactured after that date must comply with the CRA before being sold.

ZIUR Acceleration Program for CRA Implementation
As you know, we have launched a special support program for companies in this area, called the ZIUR Acceleration Program. This program aims to help companies implement the CRA, facilitating the product evaluation process, among other aspects. To this end, we work in collaboration with various companies in the Basque Country's cybersecurity ecosystem, who participate both in promoting the services available under this initiative and in the evaluation processes related to the implementation of this law.
Check our agenda to find out what training sessions and workshops we have planned on CRA implementation, and feel free to contact us to the email address cra@ziur.eus with any questions.
