AiVibe

Cybersecurity & Compliance

Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market, covering secure design, vulnerability handling and security updates.

The CRA applies to products with digital elements, meaning hardware and software that connect directly or indirectly to a device or network, from consumer IoT devices to industrial components and software; some products, such as medical devices, motor vehicles and civil aviation equipment, are covered by their own legislation instead. Manufacturers must design products to meet essential cybersecurity requirements, such as secure-by-default configuration, protection of data, a limited attack surface and the ability to receive security updates, and must handle vulnerabilities throughout a defined support period.

Vulnerability handling obligations include identifying components, including by drawing up a software bill of materials, remediating vulnerabilities without delay, providing security updates, operating a coordinated vulnerability disclosure policy and reporting actively exploited vulnerabilities and severe incidents to authorities through a single reporting platform. Products are classified as default, important or critical, with higher classes requiring stricter conformity assessment, and compliant products carry the CE marking.

The regulation entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and most other obligations from 11 December 2027. Secure development practices aligned with standards such as IEC 62443-4-1 help manufacturers of industrial products prepare while harmonised standards under the CRA are developed. Interpreting scope and product classification requires qualified legal advice.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to Cyber Resilience Act (CRA)

Ask AiMuruga can explain Cyber Resilience Act (CRA) for your plant, product or security programme, and draw how it fits.