Product Cybersecurity Law
The Cyber Resilience Act is EU product law for cybersecurity. It takes the product-compliance model used for CE-marked goods and applies it to software, hardware, connected products, separate components, and some remote data processing.
Horizontal product law
The CRA is not a general company cybersecurity law. It is a product law. It asks whether a product with digital elements can be made available on the EU market, which actor carries each duty, and whether the product and the manufacturer's processes meet the cybersecurity requirements.
rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;
Regulation (EU) 2024/2847, Article 1(a)
The legal title calls these rules horizontal cybersecurity requirements. Horizontal means the CRA is not written for one sector only. It can apply to many product types if the product is within scope and no exclusion or special overlap rule removes it.
Why the law exists
The recitals describe two main problems. First, many products with digital elements reached users with weak security, known vulnerabilities, or unclear security updates. Second, users often did not have enough information to choose and use products securely.
The EU also wanted one internal-market rule instead of many national or sector-specific cybersecurity approaches. That is why the CRA links cybersecurity to placing products on the market, not only to network operations or internal security management.
CE marking model
The CRA uses the existing CE marking model. It does not create a new cybersecurity logo. For a product that already carries CE marking under another EU product law, the CRA adds cybersecurity to the same product-compliance file.
The CE marking shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.
Regulation (EU) 2024/2847, Article 29
This matters because many manufacturers already understand CE marking. The Blue Guide explains that CE marking is not a quality mark, not a country-of-origin mark, and not proof that a public authority tested every product. It is the manufacturer's declaration that the product meets the Union laws that require CE marking.
Cybersecurity in the product file
The CRA adds cybersecurity content to familiar product-compliance objects. The legal form is familiar; the technical content is new for many products.
- Annex I Part I sets cybersecurity requirements for the product itself.
- Annex I Part II sets requirements for the manufacturer's vulnerability-handling process.
- The technical documentation must show how the product and processes meet the applicable requirements.
- The conformity assessment checks the product and the manufacturer's processes against those requirements.
- The EU declaration of conformity and CE marking connect the CRA result to the normal EU product-compliance system.
Place beside other product laws
The CRA does not replace existing product laws. A connected machine, radio product, toy, industrial controller, or medical device accessory may already be regulated under another EU regime. If the CRA also applies, the manufacturer must handle the CRA together with the other applicable legal act.
Some overlaps are dealt with directly in the CRA. These product groups have their own exclusion or limitation rules:
- medical devices and in vitro diagnostic medical devices;
- motor-vehicle type-approval products;
- products certified under the civil-aviation framework;
- marine equipment;
- identical spare parts;
- products developed or modified exclusively for national security or defence purposes;
- products specifically designed to process classified information.
Other overlaps work differently. Depending on the product and the risk being regulated, the CRA can complement laws such as:
- the Machinery Regulation;
- the General Product Safety Regulation;
- the Radio Equipment Directive;
- the GDPR;
- the Data Act;
- the AI Act;
- NIS2.