The digital landscape is evolving rapidly, and with it comes the escalating threat of cyberattacks. To counter this, the European Union is taking a significant step forward with the development of the Cybersecurity Resilience Act (CRA). The CRA aims to establish stringent cybersecurity standards for products with digital elements manufactured and sold within the EU, enhancing user protection and harmonising regulations across member states.

As the CRA moves closer to finalisation, businesses need to start preparing now to meet these new requirements and ensure their products are compliant. This article provides an overview of the CRA, detailing its core requirements and the proactive measures companies should take to align with the upcoming regulations.

Qu'est-ce que le CRA ?

Le Cyber Resilience Act (CRA) est un cadre législatif, actuellement en cours d'élaboration par l'Union européenne, visant à renforcer la normes de cybersécurité pour certains produits comportant des éléments numériques fabriqués et vendus au sein de l'UE.

The CRA aims requires manufacturers to design and produce these devices in accordance with cybersecurity standards. The overarching goal is to enhance user protection. These products might be vulnerable to cyberattacks, allowing hackers to enter the user’s home network and access other devices in the network to steal their personal data. The CRA will also help harmonise regulations across different member states.

Quelles sont les exigences énoncées par le CRA ?

Le CRA énonce des exigences de sécurité spécifiques que tous les produits comportant des éléments numériques doivent respecter et met l'accent sur une approche proactive mesures de cybersécurité. Ceux-ci incluent la conception sécurisée, le développement sécurisé et les processus de production sécurisés, garantissant que la cybersécurité est intégrée tout au long du cycle de vie du produit. Voici quelques-uns d'entre eux :

Sécurité dès la conception

The CRA emphasises the principles of security by design and by default, meaning that products must be designed and configured with security features from the outset. This approach includes conducting risk assessment to identify potential threats and vulnerabilities that could be exploited by cybercriminals. Risk assessment will help manufacturers better protect their products, and thus the users.

Mises à jour de sécurité régulières

Manufacturers will be required to monitor for new cyber threats and methods of cybercrime, and provide regular security updates to address any identified vulnerabilities. These updates must be made available for a specified period, ensuring that products remain secure over time.

Gestion des vulnérabilités

The CRA mandates the implementation of processes for handling vulnerabilities, including procedures for identifying, reporting, and mitigating vulnerabilities in a timely manner. This includes a requirement for manufacturers to establish vulnerability disclosure policies.

Évaluations de conformité et de compliance

Les produits doivent faire l'objet d'évaluations de conformité pour garantir qu'ils répondent aux exigences de cybersécurité énoncées dans le CRA. Ces évaluations peuvent inclure des auto-évaluations par les fabricants ou des évaluations par des tiers, selon le niveau de risque du produit.

Déclaration des incidents

Manufacturers will be required to report significant cybersecurity incidents and vulnerabilities to a centralised EU database. This enables authorities to track and respond to emerging threats more effectively and helps in the dissemination of information about known vulnerabilities.

Surveillance du marché et application des règles

Le CRA donne aux autorités nationales le pouvoir de mener des actions de surveillance du marché et d'application de la loi. Cela garantit que les produits non conformes sont identifiés et retirés du marché, maintenant ainsi des normes de cybersécurité élevées dans toute l'UE.

Partage d'informations

The CRA facilitates information sharing between manufacturers, authorities, and other stakeholders about cybersecurity threats, vulnerabilities, and incidents. This collaborative approach helps to enhance the overall cybersecurity posture of the digital ecosystem. The question of which manufacturers should report incidents to the appropriate authorities is governed by the NIS2 Directive.

Sensibilisation des utilisateurs et transparence

Le CRA exige des fabricants qu'ils fournissent des informations claires et accessibles sur les fonctionnalités et les limites de cybersécurité de leurs produits. Cela aide les utilisateurs à prendre des décisions éclairées et encourage

assembly hall

Quand le CRA entrera-t-il en vigueur ?

The exact date when the Cybersecurity Resilience Act (CRA) will come into force can vary depending on legislative processes and implementation timelines in different jurisdictions. Typically, once a law or directive like the CRA is passed, there may be a transition period before full enforcement begins. The anticipated timeframe for enforcement is likely around the year 2026 or 2027.

Quelles mesures les entreprises devraient-elles commencer à prendre pour se préparer au CRA ?

Firstly, businesses should conduct a comprehensive assessment of their current cybersecurity practices and capabilities to identify any gaps in meeting CRA requirements. This includes reviewing their product development processes to ensure integration of security-by-design principles.

Deuxièmement, les entreprises devraient établir ou améliorer leurs plans de réponse aux incidents afin de détecter, répondre et se remettre efficacement des cyberincidents, comme l'exige le CRA.

Thirdly, they should initiate training programs for employees to increase awareness of cybersecurity risks and best practices. Additionally, businesses should engage with regulatory authorities and industry groups to stay informed about CRA updates and guidelines.

Lastly, they should begin implementing robust cybersecurity measures, such as regular security assessments and updates, to ensure ongoing compliance with the CRA’s standards. These proactive steps will help companies mitigate risks, enhance their cybersecurity posture, and align with regulatory expectations under the CRA.

Faites les premiers pas pour assurer la conformité au CRA de manière rentable

The optimal way to ensure readiness for CRA compliance is to seek the assistance of cybersecurity experts who will prepare a strategy for implementing cybersecurity measures in your organisation. Spyrosoft can provide the necessary expertise and support to navigate the requirements effectively. We will not only assist you in selecting the best practices available on the market that align with the CRA, but also help implement them in an optimal and cost-effective manner, ensuring minimal impact on production and product costs.

The CRA is an EU regulation designed to strengthen cybersecurity standards for products with digital elements sold within the European Union. Its goal is to ensure that devices are secure by design and by default, protecting users from cyber threats and harmonising requirements across member states.

Le CRA s'applique aux produits comportant des éléments numériques, tels que les logiciels, le matériel et les appareils connectés susceptibles d'être ciblés par des cyberattaques. Cela inclut l'électronique grand public, les appareils IoT et les solutions logicielles d'entreprise.

Le CRA devrait entrer en vigueur vers 2026 ou 2027, à l'issue du processus législatif de l'UE et d'une période de transition pour sa mise en œuvre. Les entreprises devraient commencer à se préparer dès maintenant afin de garantir une conformité fluide une fois qu'il sera appliqué.

Les fabricants doivent adopter des principes de sécurité dès la conception, fournir des mises à jour de sécurité régulières, mettre en place des processus de gestion des vulnérabilités et signaler les incidents significatifs. Ils devront également se soumettre à des évaluations de conformité pour prouver leur conformité.

Spyrosoft’s cybersecurity experts support organisations in assessing current practices, identifying compliance gaps, and implementing CRA-aligned strategies. We help companies achieve readiness in a cost-effective way, minimising disruption to production and operations.