Frequently Asked Questions about the CRA

The second phase of the regulations will come into force on September 11, 2026, and companies must prepare to modify their practices based on the legal requirements for this period. From this date, the critical obligation for manufacturers to report actively exploited vulnerabilities and serious incidents will begin to be applied.

The regulation will be fully implemented on December 11, 2027. From this date, all products with digital components marketed in the EU must comply with all cybersecurity requirements (including CE marking).

EU Cyber Resilience Act: For safer and more secure digital products

EU Cyber Resilience Act: For safer and more secure digital products

This section aims to address the most common questions among manufacturers of connected products, mostly related to Articles 13, 14, 32, and 69 of the regulation.

Doubt about design

Would products designed before the implementation of the CRA that do not comply with the regulations need to be redesigned?

Not always. A product designed before the CRA can remain on the market without redesign, but only if the manufacturer can demonstrate, through risk assessment and technical documentation, that it achieves an adequate level of cybersecurity (meeting the applicable essential requirements).

Articles 13 and 32 and Annex I of the regulations

Doubt about vulnerability notification

Should ENISA and customers be notified of vulnerabilities found in an integrated library?

Yes, if the vulnerability is present and exploitable in your product.

You don't have to wait until it has already been exploited on a customer's machine.

Article 14 of the regulations

Doubt about stock

Can stock placed on the market before 11/12/2027 continue to be sold if it violates the regulations?

Yes, but only while stocks last. Stock already placed on the market before December 11, 2027, may be sold out in 2028, but new units manufactured after that date must comply with the CRA before being sold.

Article 69 of the regulations

ZIUR Acceleration Program for CRA Implementation

As you know, we have launched a special support program for companies in this area, called the ZIUR Acceleration Program. This program aims to help companies implement the CRA, facilitating the product evaluation process, among other aspects. To this end, we work in collaboration with various companies in the Basque Country's cybersecurity ecosystem, who participate both in promoting the services available under this initiative and in the evaluation processes related to the implementation of this law.

Check our agenda to find out what training sessions and workshops we have planned on CRA implementation, and feel free to contact us to the email address cra@ziur.eus with any questions.

We set up the email address cra@ziur.eus, through which interested companies can send their questions and queries related to the Cyber Resilience Regulation (CRA).