# EU Cyber Resilience Act: What Connected Hardware Must Do

The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for any product with digital elements — that means hardware with software, firmware, or network connectivity. It's not a voluntary framework. From late 2027, products that don't meet baseline security requirements cannot carry the CE mark and cannot be sold in the EU. Here's what hardware companies need to understand now.


## Transcript

### CRA applies to almost every connected product

If your hardware runs software, connects to a network, or receives firmware updates, it falls under the EU Cyber Resilience Act. This isn't a voluntary certification — it's a prerequisite for CE marking from late 2027, and obligations start earlier than that.

### What CRA actually requires

The CRA covers any product with digital elements — software, network connectivity, or remote updates. "Critical" products like routers face mandatory third-party assessment; "default" products self-declare. Either way you need no universal passwords, a disclosure process, and 24-hour ENISA reporting.

### What to do before 2027

Start by confirming your product is in scope — almost all connected hardware is — then classify it default or critical. Map your update process and disclosure policy against the essential requirements. 2027 sounds distant, but products in development now will be certified under CRA.

Tags: EU Cyber Resilience Act, CRA, IoT security, CE marking, connected hardware