The Cyber Resilience Act in 5 Steps
- Press
The EU aims to improve the security of hardware and software and encourage customers to consider security when making purchasing decisions. Although the EU estimates that up to 90% of products will be subject to self-assessment, manufacturers, suppliers and distributors need to take action now.
How should organisations approach the implementation of the CRA in practice, according to Michal Srnec, Head of Information Security at Aliter Technologies?
1. Product inventory and categorisation
The first step is to create an accurate inventory of products placed on the EU market and classify them into three categories based on their level of risk:
Standard products: All other products outside the categories below.
Important products: Divided into Class I and Class II (e.g. routers, firewalls and password managers).
Critical products: The highest security category (e.g. smart cards and hardware with security storage).
CRA exemptions: The regulation does not apply to products already covered by other legislation or standards (e.g. in the automotive or healthcare sectors) or to products intended exclusively for national security or the processing of classified information.
2. Meeting the substantive security requirements
The security requirements are the same for all categories and require a change in mindset. Security is no longer a one-time milestone, but an ongoing process.
Product security: Security by design and by default, risk analysis, attack surface minimisation, delivery without exploitable vulnerabilities, encryption and the collection of only essential data.
Vulnerability management: Maintaining an inventory of components, establishing a coordinated vulnerability disclosure policy, and providing free and timely security updates throughout the support period.
3. Demonstrating conformity
While the security requirements are the same, the method of demonstrating conformity (Conformity Assessment) depends on the product category:
Standard products: Internal self-assessment is sufficient, together with technical documentation, an EU Declaration of Conformity and CE marking.
Important products (Class I): Self-assessment is possible only if harmonised standards are fully applied. Otherwise, a notified body is required.
Important products (Class II) and Critical products: These require the involvement of a notified body (EU-type examination and comprehensive quality assurance). Critical products will also require European certification (e.g. EUCC).
4. Meeting key deadlines
Waiting for the final harmonised standards or the appointment of notified bodies is a risk. Technical product preparation takes months, and third-party assessments may create capacity bottlenecks.
Key dates:
11 September 2026: Reporting obligations begin to apply, including the reporting of actively exploited vulnerabilities and serious incidents, also for products already on the market.
11 December 2027: The CRA becomes fully applicable, making compliance with the essential requirements and conformity assessment mandatory.
5. Preparing for and monitoring updates
Implementing the CRA in practice requires a review of products and components, regardless of the specific legislative details.
It is recommended to continuously monitor official publications and the website of the National Security Authority (NBÚ), where implementing acts and standards will be gradually published. The sooner you start reviewing your products, the smoother the transition to the new requirements will be.
Read the full article: HN Special