Security belongs in the product lifecycle.
Understand the EU Cyber Resilience Act through the decisions your product team already makes, from scope and secure design to evidence, market placement and support.
TO FRAME THE WORK ↓
Start with the thing you build.
The CRA addresses products with digital elements supplied on the Union market. Scope needs a product-specific review of connections, market activity and exclusions.
What exactly is placed on the market?
Draw the product boundary. Record intended use, connections, components and remote functions before you classify it.
Work through product scope →One product. Different responsibilities.
The manufacturer’s development and support duties differ from checks required of importers and distributors.
Follow the product, not a pile of forms.
A working framework for organising activity across the lifecycle. This sequence is editorial guidance, not a mandated legal order.
- 01Define
Product boundary & market route
- 02Design
Risk & security properties
- 03Demonstrate
Evidence & conformity
- 04Maintain
Vulnerabilities & updates

A vulnerability is a product event.
Effective handling continues through support. Intake, assessment, correction, communication and documentation need clear ownership.
This is an operational illustration. Check Article 14 separately for reporting triggers and timing.
Understand vulnerability handling →Evidence before the mark.
Conformity assessment, documentation and the EU declaration connect product security decisions to market placement.
Determine the route. Keep the record.
Product classification affects which assessment procedures are available. A checklist cannot replace the legal requirements or the applicable conformity procedure.
Dates on the drawing board.
These milestones are verified in the European Commission’s legislative summary. Product history and transitional provisions still require review.
The Regulation entered into force.
Article 14 duties began to apply.
Principal product duties apply.
Dates: European Commission legislative summary ↗
View full timeline →Go deeper into the work.
Focused guides for the decisions that connect a product to the CRA.
A readable entry point to Annex I product properties and vulnerability-handling requirements.
↗02 / GUIDETechnical documentation and product evidenceOrganise risk, design, verification and support records into a traceable product file.
↗03 / GUIDEHow to scope a software product under the CRAAn editorial guide to product boundaries, components and remote functions.
↗04 / GUIDEProduct security preparation checklistA working list for teams preparing product evidence and responsibilities.
↗