What the Cyber Resilience Act is and who must comply
The Cyber Resilience Act (EU Regulation 2024/2847) is the first European regulation to impose mandatory cybersecurity requirements on all "products with digital elements" sold in the EU market, from software to industrial IoT/OT devices, including CE marking.
Unlike NIS2, which regulates operators of critical infrastructure, the CRA regulates the manufacturer supply chain: manufacturers, importers and distributors must ensure security-by-design, vulnerability management across the product's whole lifecycle, and transparency, including a declaration of conformity and an SBOM available to authorities.
The regulation entered into force at the end of 2024; reporting obligations - actively exploited vulnerabilities and severe incidents within 24 hours to ENISA - apply from September 2026, while the full compliance regime, with CE marking and complete technical documentation, applies from December 2027.
For anyone operating industrial OT/IoT networks, even without manufacturing directly: you need to verify that the suppliers of installed devices meet vulnerability-management and security-update obligations, because non-compliant products directly increase your network's attack surface.
CRA
Cyber Resilience Act (EU Reg. 2024/2847)
EU regulation that imposes cybersecurity requirements on manufacturers, importers and distributors of products with digital elements placed on the European market. Full effect from 11/12/2027. Directly applies to OEMs, system integrators and OT/IoT component vendors.
- 01Security by design across the full product lifecycle
- 02Vulnerability handling and coordinated disclosure
- 03Software component management, including SBOM
- 04Notification of actively exploited vulnerabilities within 24h
- 05Security updates throughout the declared support period
For industrial asset owners, MON5 provides visibility on CRA-relevant products installed on plant: firmware, versions, known vulnerabilities, network exposure. It lets you verify that suppliers honour their vulnerability handling obligations and manage the software/firmware inventory required by supply chain requirements.
- →Firmware and version inventory for OT/IoT devices
- →CVE correlation on installed components
- →EPSS scoring to prioritise patching
- →Evidence on network exposure of CRA-relevant products
- →Audit trail to verify supplier responsiveness
- Product with digital elements
- Any hardware or software, or combination of the two, with a logical or physical connection to a network or device, falling within CRA scope (excluding some already-regulated sectors, such as medical devices or automotive).
- Security-by-design
- The principle that security must be designed into a product from the start of development, not bolted on afterwards: attack-surface management, secure defaults, least-privilege.
- SBOM (Software Bill of Materials)
- A structured list of the software components - including open-source libraries and third-party dependencies - that make up a product, required by the CRA for supply-chain vulnerability management.
- Actively exploited vulnerability
- A vulnerability for which there is credible evidence of ongoing exploitation; the CRA requires the manufacturer to notify ENISA within 24 hours of becoming aware of it.
- Support period
- The length of time during which the manufacturer commits to providing security updates for the product, declared and communicated to the user at the point of sale.
- CE marking (CRA context)
- The declaration by which the manufacturer attests that the product complies with the regulation's essential cybersecurity requirements - a condition for placing it on the EU market from 2027.
Does the Cyber Resilience Act cover products installed in OT environments?+
Yes. The CRA applies to products with digital elements: PLCs, HMIs, industrial gateways, smart sensors and firmware-embedded devices installed in production or connected to corporate networks.
How do you manage CRA compliance for firmware and legacy devices?+
MON5 identifies all CRA-relevant products on-site, maps firmware versions, known vulnerabilities (CVE) and network exposure, supporting lifecycle management and mandatory vulnerability disclosures.
When do companies need to comply with the Cyber Resilience Act?+
The CRA entered into force in 2024. Main obligations apply progressively until 2027. Companies should immediately begin inventorying products with digital elements and assessing their vulnerability posture.
Who is responsible for CRA compliance: the manufacturer, importer or distributor?+
The CRA spreads obligations across the supply chain: the manufacturer is primarily responsible (secure design, vulnerability management, documentation), but importers and distributors must verify a product's compliance before placing it on the market and report known non-conformities.
What happens if a vulnerability is actively exploited on a CRA-relevant product?+
The manufacturer must notify ENISA within 24 hours of becoming aware of it (early warning), with an intermediate notification within 72 hours and a final report within 14 days of a fix becoming available.
Does the CRA apply to open-source software too?+
Open-source components used inside a commercial product fall into scope through the manufacturer that integrates them (SBOM obligation). Stand-alone open-source projects without commercial development are generally excluded, with some exceptions.
What penalties does the CRA impose for non-compliance?+
Up to €15 million or 2.5% of annual global turnover for the most serious breaches of essential cybersecurity requirements, with smaller penalties for documentation and notification obligations.
Does the CRA apply only to new products or to ones already installed?+
It applies to products placed on the market after the requirements take effect. For legacy OT devices already installed, the impact is indirect: you need to check whether the supplier will keep supporting them and manage risk in the meantime with visibility into vulnerabilities and firmware versions.
Let's figure out what you really need.
Show us the OT perimeter and the regulations you need to cover: we will tell you what MON5 documents directly, where complementary work is needed, and which tier to start from - no hard selling.