Home > Cyber Resilience Act (CRA)
General Cyber Resilience Act (CRA) information
The Cyber Resilience Act (CRA) is a EU law that establishes mandatory cybersecurity requirements for products, inclusive of software.
It requires manufacturers to design products with security in mind from the outset, provide regular updates to address vulnerabilities, and ensure ongoing monitoring throughout the product’s lifecycle.
The act aims to reduce cybersecurity risks, make companies accountable for maintaining secure products, and give consumers greater transparency and confidence when choosing products.
The CRA timeline:
- 10–11 Dec 2024 — CRA came into force; with a three‑year transition period
- Aug 2025 — Radio Equipment Directive (RED) cybersecurity requirements affecting D7 came into effect (EN 18031‑1/‑2)
- 11 Jun 2026 — Conformity assessments begin (Veethree are self‑assessing – this is being check on a per product basis)
- Aug 2026 — First set of CRA harmonised standards released (enables deeper compliance work)
- 11 Sep 2026 — CRA reporting obligations start (actively exploited vulns/severe incidents via EU single platform)
- Oct 2026 — Second set of CRA harmonised standards released
- Oct 2027 — Final set of additional CRA requirements released as harmonised standards (aim to be compliant to earlier sets by now)
- 11 Dec 2027 — Full application of CRA (secure‑by‑design/default, vulnerability handling, CE marking incl. software/SDKs)
The directives we are currently Meeting:
The meeting of this act allows for sales of our products within Europe, and also aligns with Customers that are required to align with more stringent sector requirements. Security is built from the ground up, making it easier for Customers to meet their requirements with much less effort. Our work at Veethree strives to make our products compliant with the CRA. (Each requirement has to be approached on a product-by-product basis)
This is in the form of meeting the Essential Cyber Security requirements, this is not verbatim of the CRA text, these are the following:
- Products being designed, developed in a way to ensure an appropriate level of cyber based risks
- Products being distributed without known exploitable vulnerabilities (Unless they are acceptable with a stringent rationale)
- Products are made available with a secure by default configuration
- Products have effective authorisation methods where required that report on unauthorised access
- The confidentiality and integrity of data, that is classed as relevant for intended use is protected
- The availability of our devices is protected and the impact on other devices are minimised
- The attack surfaces of our products are understood and limited to what is required for the intended use of the product
- The security of the product has been designed and developed to reduce potential incidents
- The products have sufficient ability to provide security related information for analysis
The Radio Equipment Directive (RED):
The Radio Equipment Directive (RED) is used to encompass devices with radio emitting capabilities. For our product range this affects the D7.
There have been additions to RED that came into effect on August 1st 2025 regarding Cyber Security as a transition period until the CRA comes into law fully, only two of the requirements apply, these being:
- The device must be unable to harm the network, or its function.
- The device must incorporate safeguards to ensure that personal data and privacy of the user an the subscriber are protected.
In order to meet these requirements we are using REDs harmonised standards EN 18031-1 and EN 18031-2.
These are just the stated Essential requirements, we are striving to meet all of the obligations of the Cyber Resilience Act for the purpose of providing secure but effective products. Our company obligation is to comply with the Cyber Resilience Act (CRA).
Contact Us
Please do get in touch should you wish to discuss your Cyber Resilient hardware requirements and our commitment to meeting with CRA compliance . Simply fill out the form below, and one of our team will get back to you.
