Independent information resource Product security · EU CRA
PRODUCT SECURITY / FIELD GUIDE 001

Security belongs in the product lifecycle.

Understand the EU Cyber Resilience Act through the decisions your product team already makes, from scope and secure design to evidence, market placement and support.

FIG. 01 / CONNECTED PRODUCT ASSEMBLYHARDWARE · SOFTWARE · SUPPORT
01 / PRODUCT BOUNDARY

Start with the thing you build.

The CRA addresses products with digital elements supplied on the Union market. Scope needs a product-specific review of connections, market activity and exclusions.

A / PHYSICAL PRODUCTB / EMBEDDED SOFTWAREC / COMPONENTSPRODUCT MAP / ILLUSTRATIVE ASSEMBLY
BOUNDARY STUDY / 01–04

What exactly is placed on the market?

Draw the product boundary. Record intended use, connections, components and remote functions before you classify it.

Work through product scope →
02 / SUPPLY CHAIN

One product. Different responsibilities.

The manufacturer’s development and support duties differ from checks required of importers and distributors.

03 / ENGINEERING METHOD

Follow the product, not a pile of forms.

A working framework for organising activity across the lifecycle. This sequence is editorial guidance, not a mandated legal order.

  1. 01
    Define

    Product boundary & market route

  2. 02
    Design

    Risk & security properties

  3. 03
    Demonstrate

    Evidence & conformity

  4. 04
    Maintain

    Vulnerabilities & updates

Engineer inspecting a circuit board beside an opened industrial device and technical drawings
FIG. 02 / SECURITY DECISIONS THROUGH DEVELOPMENT
04 / AFTER RELEASE

A vulnerability is a product event.

Effective handling continues through support. Intake, assessment, correction, communication and documentation need clear ownership.

01 / RECEIVERecord the issue
02 / ASSESSUnderstand impact
03 / REMEDIATEVerify a correction
04 / COMMUNICATEUpdate and document

This is an operational illustration. Check Article 14 separately for reporting triggers and timing.

Understand vulnerability handling →
05 / MARKET PATHWAY

Evidence before the mark.

Conformity assessment, documentation and the EU declaration connect product security decisions to market placement.

PRODUCT FILE / 03
ASSESSMENT / 02
RISK RECORD / 01
CONFORMITY IS PRODUCT-SPECIFIC

Determine the route. Keep the record.

Product classification affects which assessment procedures are available. A checklist cannot replace the legal requirements or the applicable conformity procedure.

RISK ASSESSMENTTECHNICAL FILEASSESSMENT ROUTEDECLARATION + CE
Understand conformity ↗
06 / REGULATORY CLOCK

Dates on the drawing board.

These milestones are verified in the European Commission’s legislative summary. Product history and transitional provisions still require review.

Entry into force

The Regulation entered into force.

Reporting applies

Article 14 duties began to apply.

Main provisions

Principal product duties apply.

Dates: European Commission legislative summary ↗

View full timeline →
START WITH A CLEAR PRODUCT DEFINITION

Turn a broad regulation into focused product questions.

Open preparation checklist ↗