Product Cybersecurity Law

The Cyber Resilience Act is EU product law for cybersecurity. It takes the product-compliance model used for CE-marked goods and applies it to software, hardware, connected products, separate components, and some remote data processing.

Horizontal product law

The CRA is not a general company cybersecurity law. It is a product law. It asks whether a product with digital elements can be made available on the EU market, which actor carries each duty, and whether the product and the manufacturer's processes meet the cybersecurity requirements.

rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;

Regulation (EU) 2024/2847, Article 1(a)

The legal title calls these rules horizontal cybersecurity requirements. Horizontal means the CRA is not written for one sector only. It can apply to many product types if the product is within scope and no exclusion or special overlap rule removes it.

CE marking model

The CRA uses the existing CE marking model. It does not create a new cybersecurity logo. For a product that already carries CE marking under another EU product law, the CRA adds cybersecurity to the same product-compliance file.

The CE marking shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.

Regulation (EU) 2024/2847, Article 29

This matters because many manufacturers already understand CE marking. The Blue Guide explains that CE marking is not a quality mark, not a country-of-origin mark, and not proof that a public authority tested every product. It is the manufacturer's declaration that the product meets the Union laws that require CE marking.

Cybersecurity in the product file

The CRA adds cybersecurity content to familiar product-compliance objects. The legal form is familiar; the technical content is new for many products.

  • Annex I Part I sets cybersecurity requirements for the product itself.
  • Annex I Part II sets requirements for the manufacturer's vulnerability-handling process.
  • The technical documentation must show how the product and processes meet the applicable requirements.
  • The conformity assessment checks the product and the manufacturer's processes against those requirements.
  • The EU declaration of conformity and CE marking connect the CRA result to the normal EU product-compliance system.

Place beside other product laws

The CRA does not replace existing product laws. A connected machine, radio product, toy, industrial controller, or medical device accessory may already be regulated under another EU regime. If the CRA also applies, the manufacturer must handle the CRA together with the other applicable legal act.

Some overlaps are dealt with directly in the CRA. These product groups have their own exclusion or limitation rules:

  • medical devices and in vitro diagnostic medical devices;
  • motor-vehicle type-approval products;
  • products certified under the civil-aviation framework;
  • marine equipment;
  • identical spare parts;
  • products developed or modified exclusively for national security or defence purposes;
  • products specifically designed to process classified information.

Other overlaps work differently. Depending on the product and the risk being regulated, the CRA can complement laws such as:

  • the Machinery Regulation;
  • the General Product Safety Regulation;
  • the Radio Equipment Directive;
  • the GDPR;
  • the Data Act;
  • the AI Act;
  • NIS2.

Sources