skip to content

EU Cyber Resilience Act

Duties on a manufacturer of a product with digital elements: security by design, a vulnerability-handling process, and reporting an actively exploited flaw fast. Interviewers probe who counts as one.

on this pageshow

questions

5

Under the EU Cyber Resilience Act, which products and companies are in scope?

level: juniorimportance: must knowfreq 68%

answer

  1. product law, not a sector law
  2. products with digital elements
  3. hardware, software, firmware, components
  4. whoever's brand is on the box
  5. rebranding makes you the maker

basics

~20 s

The CRA covers products with digital elements: hardware or software placed on the EU market, including firmware and components. The manufacturer, whoever sells it under their own name, carries the duties; importers and distributors carry lighter ones.

solid answer

~50 s

The CRA regulates `products with digital elements` placed on the EU market: connected and unconnected hardware, standalone software, firmware, and software components sold on to other makers. Remote data processing that is integral to the product - the cloud half a device cannot work without - is pulled in with it, while a standalone cloud service is not a product with digital elements and is handled by other EU rules such as NIS2. The party carrying the duties is the manufacturer: whoever places the product on the market under their own name or trademark. That definition bites. Rebrand someone else's hardware, or substantially modify a product you did not build, and you become its manufacturer. Importers and distributors owe due diligence rather than the full set, and free and open-source software supplied outside a commercial activity is out of scope entirely.

go deeper

for a junior

Be ready to say in one sentence what a product with digital elements is and who the manufacturer is. Knowing that firmware and standalone software count, not just connected gadgets, is most of the answer.

for a middle

Explain the mechanics of the manufacturer role: own name or trademark, rebranding, substantial modification, and the lighter importer and distributor duties. Be able to place remote data processing on the right side of the line.

for a senior

Expect to be asked to scope a real portfolio - which SKUs, components and backends are in, who signs, and what you must demand from suppliers by contract because you inherit their defects when you put your logo on them.

for a principal

Own the strategic read: which product lines you keep in the EU market at all, whether to consolidate SKUs to shrink the compliance surface, and how supplier contracts, insurance and pricing absorb an obligation with turnover-based fines behind it.

## What the CRA is The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is product-safety law applied to cybersecurity. Its logic is the same one the EU already uses for electrical safety or machinery: if you want to sell a thing in the single market, the thing must meet essential requirements, you must be able to show it does, and you affix a CE marking saying so. What is new is that the essential requirements are about security, and that they do not stop at the moment of sale - they run for a declared support period afterwards. It entered into force at the end of 2024. The bulk of the obligations apply from late 2027, with the vulnerability-reporting duties starting roughly a year earlier, which is why the question is already live in interviews. ## What counts as a product with digital elements A product with digital elements is any software or hardware product, plus its remote data processing solutions, made available on the EU market. In practice that sweeps in far more than consumer IoT: - connected hardware - a thermostat, a router, a industrial gateway - and its firmware - hardware with software that never goes online at all - standalone software sold as a download or on a subscription, including desktop and mobile applications - software and hardware components placed on the market separately, sold business-to-business rather than to end users; each is a product in its own right with its own manufacturer A `remote data processing solution` is in scope when it is integral to the product: the product cannot perform its function without it. The backend a smart lock calls to open is in; a general-purpose cloud service you sell as a service is not a product with digital elements at all, and its security obligations come from elsewhere in EU law such as NIS2. Out of scope: products already governed by sector-specific EU regimes (certain medical devices, motor vehicles, civil aviation), and free and open-source software supplied outside a commercial activity - the individual contributor, the unpaid project - which the regulation deliberately excludes, while giving organisations that systematically sustain such projects a separate, lighter steward regime. ## Who carries the duties The central role is the manufacturer: the party that develops or has developed a product and markets it under its own name or trademark. Two consequences catch people out. 1. **Rebranding transfers the role.** Buy a white-label device, put your logo on it, sell it in the EU: you are the manufacturer, and the essential requirements, the vulnerability handling and the reporting clock are yours, not the original maker's. Your recourse against your supplier is a contract you have to write; it is not a defence to the regulator. 2. **Substantial modification transfers it too.** If you modify a product in a way that changes its intended purpose or affects its compliance, you take on the manufacturer's duties for the modified product. A pure security update that fixes a flaw without changing intended purpose is not a substantial modification - otherwise patching would be punished. Importers and distributors sit below the manufacturer: they must not place non-compliant products on the market, must check that the CE marking and documentation are present, and must inform the manufacturer and market surveillance authorities when they learn of a problem. Open-source software stewards - legal entities providing sustained support for open-source products used commercially - have their own tailored set. ## The two duty families Everything a manufacturer owes falls into two groups. First, essential product requirements: secure-by-default configuration, no known exploitable vulnerabilities at the moment the product is placed on the market, appropriate access control, protection of data confidentiality and integrity, minimised attack surface, resilience against denial of service, security-relevant logging, and the ability to deliver updates. Second, vulnerability-handling requirements: keep a software bill of materials covering at least the top-level dependencies in a commonly used machine-readable format, remediate vulnerabilities without delay, provide free security updates, run a coordinated vulnerability disclosure policy with a published contact address, and report actively exploited vulnerabilities to the authorities. ## Conformity and enforcement Most products self-assess against the requirements and self-declare. Categories the regulation calls important and critical - things like password managers, identity systems, or hypervisors - escalate towards third-party assessment or certification. Enforcement is national market surveillance, with fines for breaching the essential requirements reaching the higher of 15 million euro or 2.5% of worldwide annual turnover, so the exposure is not a rounding error. The interview point is simply this: work out whether you are in scope and who in your supply chain is the manufacturer before arguing about controls, because the answer decides whose problem everything else is.

  • We sell pure SaaS with nothing installed on the customer's side. Are we in scope?
    Probably not as a product with digital elements. The CRA reaches cloud only where the remote data processing is integral to a product - the product cannot do its job without it. A standalone service you host and sell is regulated elsewhere, notably under NIS2. Check carefully if you also ship an agent, a device or a client application, because that shipped thing is a product and its backend may come with it.
  • We buy white-label hardware and sell it under our brand. Who is the manufacturer?
    You are. Placing a product on the EU market under your own name or trademark makes you the manufacturer, with the full set of essential requirements, vulnerability handling and reporting duties. The original maker's obligations do not shield you. The practical response is contractual: require the source firmware, an SBOM, fix service levels and a disclosure contact from your supplier, because you will be judged on the product you sold.
  • Does the CRA apply to a component we only sell to other manufacturers?
    Yes. A hardware or software component placed on the market separately is itself a product with digital elements, and you are its manufacturer. Separately, integrators must exercise due diligence on the components they build in, so your business customers will demand SBOM data, a disclosure contact and fix timelines from you in order to satisfy their own duty.

It is CE marking for security. The same rule that stops you selling an unsafe kettle in Europe now asks whether the kettle's firmware can be updated and who answers when it is exploited.

saying these in an interview costs you the question

  • Thinks the CRA only covers consumer IoT devices
  • Assumes software with no hardware is out of scope
  • Says rebranded hardware stays the original maker's problem
  • Believes CE marking cannot apply to software
  • Treats every open-source project as automatically in scope
  • Confuses the CRA with a data protection regime

context

open as a page

What triggers the EU Cyber Resilience Act's 24-hour early-warning report?

level: middleimportance: must knowfreq 62%

basics

~20 s

Becoming aware that a vulnerability in your product is being actively exploited, or that a severe incident affects its security. Within 24 hours you send an early warning to the coordinating national CSIRT and ENISA - not a public advisory.

open as a page

Does the EU CRA let a CE-marked industrial gateway keep its default engineer account?

level: seniorimportance: should knowfreq 42%

basics

~20 s

No. A shared credential shipped on every unit fails the CRA's secure-by-default configuration and access-control requirements. It must be replaced with per-unit or per-technician credentials plus an auditable break-glass path, delivered as a security update rather than a redesign.

open as a page

Under the EU CRA, how do you decide the support period you declare for a product?

level: principalimportance: should knowfreq 34%

basics

~20 s

It must reflect how long the product is realistically used, and be at least five years unless the expected lifetime is shorter. Derive it from field lifetime, your dependencies' maintenance horizons and the sustaining engineering you can fund.

open as a page

Does the EU CRA's open-source steward regime shield a foundation whose library ships in paid products?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Partly. A steward is not a manufacturer: no CE marking, no conformity assessment, no essential-requirement liability. It does owe a documented cybersecurity policy and reporting of exploited flaws. The vendor embedding the library carries the product duties.

open as a page