TESTING EMERGING MARKET

EU Cyber Resilience Act Compliance

A new product cybersecurity compliance, vulnerability management and conformity assessment services market is forming around the EU Cyber Resilience Act — as mandatory vulnerability reporting obligations took effect on 11 September 2026 and full enforcement of all security-by-design requirements approaches on 11 December 2027.

Key Deadline: 11 December 2027 (full CRA enforcement — all products with digital elements)

Executive Summary

Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), is the EU's first horizontal cybersecurity law for products with digital elements. It applies to virtually every connected product placed on the EU market — from consumer IoT devices and smart home appliances to industrial control systems, operating systems, firmware and standalone software. The CRA imposes mandatory security-by-design requirements, lifecycle vulnerability management obligations, technical documentation duties, conformity assessment procedures and CE marking requirements.

The CRA entered into force on 10 December 2024 and is being enforced in phases. Vulnerability reporting obligations under Article 14 became applicable on 11 September 2026 — manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours. Full enforcement of all substantive obligations — including security-by-design, secure default settings, software bill of materials (SBOM), conformity assessment and CE marking — begins on 11 December 2027. Fines for non-compliance reach up to €15 million or 2.5% of global annual turnover.

A commercial services market is forming around these requirements. Cybersecurity consultancies, product security assessment firms, SBOM tooling providers, conformity assessment bodies and secure development lifecycle (SDL) consultancies are clustering around CRA compliance needs. The scope is enormous: every manufacturer, importer and distributor of connected products sold in the EU must comply, regardless of where they are established.

This Topic Hub tracks whether an independent CRA compliance services market is forming, who participates, what evidence supports the thesis, and what remains uncertain.

EII Judgment

What Is Real

The CRA is binding law. Vulnerability reporting obligations are already in force since 11 September 2026. The regulation covers all products with direct or indirect network connectivity. CE marking will be mandatory for in-scope products. Fines of up to €15M or 2.5% of global turnover are enforceable.

What Is Forming

Product cybersecurity assessment services, SBOM generation tooling, vulnerability management platforms, secure development lifecycle consulting, conformity assessment body preparation for CRA notification, and product security testing services are all clustering around CRA compliance requirements.

What Is Not Yet Proven

Whether notified body capacity will be sufficient for the volume of conformity assessments. Whether the market will consolidate around a few large cybersecurity firms or remain fragmented. Whether self-assessment routes will be sufficient for most products, limiting the third-party assessment market. Whether non-EU jurisdictions will adopt equivalent requirements.

What Matters Now

Manufacturers have roughly 14 months until full enforcement. Vulnerability reporting is already active. Security-by-design documentation, SBOM creation, conformity assessment preparation and CE marking processes take months to build. The preparation window is narrowing rapidly.

Research Assessment

89EII /100
82Human Value /100
55Crowding /100

EII Score reflects binding regulation with an already-active reporting obligation, enormous product scope covering all connected devices, and clear enforcement timeline. Human Value Score reflects the direct impact on consumer product safety — insecure IoT devices, smart home products and industrial systems affect billions of users. Crowding Score reflects growing but not yet saturated service provider activity — the CRA compliance market is earlier-stage than AI safety testing.

Why This Market Is Forming Now

  • Regulation is enforceable and partially active. The CRA is not a voluntary framework. Article 14 vulnerability reporting obligations have been in force since 11 September 2026. Manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours, with full incident reports within 72 hours. Full enforcement follows on 11 December 2027.
  • Scope is horizontal and enormous. The CRA applies to all products with digital elements that have direct or indirect network connectivity. This includes consumer IoT, smart home devices, industrial control systems, operating systems, firmware, mobile applications, connected medical devices, smart toys and enterprise software. Every manufacturer, importer and distributor is in scope, regardless of establishment location.
  • Security-by-design is mandatory. Products must be secure by default — default passwords must be eliminated, non-essential ports disabled, and security features enabled by default. Manufacturers must implement security-by-design throughout the product lifecycle, from development through end-of-support. These are not guidelines but binding legal requirements.
  • CE marking creates a market access gate. From December 2027, products with digital elements must carry CE marking demonstrating CRA compliance before being placed on the EU market. This creates a binary market access requirement similar to what exists for product safety, electromagnetic compatibility and radio equipment — but now extended to cybersecurity.
  • Supply chain obligations extend liability. Manufacturers must maintain software bills of materials (SBOM), conduct due diligence on third-party components, and bear joint liability for integrated components. This creates demand for supply chain security mapping, component auditing and SBOM management tooling.

Regulatory Timeline

Nov 2024
CRA published in Official Journal

Regulation (EU) 2024/2847 published. First EU horizontal cybersecurity legislation for products with digital elements.

Source: EUR-Lex
10 Dec 2024
CRA enters into force

20 days after publication. Transition period begins. Manufacturers may begin voluntary compliance preparation.

Source: Art. 92, CRA
11 Jun 2026
Notified Body designation rules apply

Articles 35–51 concerning conformity assessment bodies begin to apply. Member states may start designating notified bodies for CRA assessments.

Source: CRA transitional provisions
11 Sep 2026
Vulnerability reporting obligations active

Article 14 reporting obligations in force. Manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours. Full incident reports within 72 hours. Applies to ALL in-scope products currently on the EU market, including products placed before this date.

Source: Art. 14, CRA
11 Dec 2027
Full CRA enforcement

All substantive obligations apply. Security-by-design, secure default, vulnerability management, SBOM, technical documentation, conformity assessment and CE marking mandatory for all products placed on the EU market.

Source: CRA Articles 8–13, Annex I
11 Jun 2028
Transitional arrangements expire

Cybersecurity certificates issued under other EU legislation (e.g. RED Delegated Regulation) cease to be valid unless renewed under CRA framework.

Source: CRA transitional provisions

Who Is Affected

Hardware Manufacturers

DIRECT LEGAL RESPONSIBILITY

Manufacturers of IoT devices, smart home products, connected appliances, industrial controllers, networking equipment and any hardware with digital elements must ensure security-by-design, provide SBOM, obtain conformity assessment and affix CE marking.

Software Vendors

DIRECT LEGAL RESPONSIBILITY

Standalone software, mobile apps, operating systems, firmware, and any software with network connectivity must comply. This includes both paid software and free/open-source software distributed commercially. Security updates must be provided throughout the support period.

Importers & Distributors

VERIFICATION OBLIGATION

Importers must verify that manufacturers have completed conformity assessment, prepared technical documentation and affixed CE marking. Distributors must verify compliance before making products available on the EU market.

Component Suppliers

DUE DILIGENCE SCOPE

Third-party components integrated into digital products are subject to manufacturer due diligence. Component suppliers must provide security documentation, vulnerability information and SBOM data to downstream manufacturers.

Notified Bodies & Testing Labs

ACCREDITATION ROLE

Conformity assessment bodies preparing for notification under the CRA for Class II (important) and Class III (critical) products. Must be designated by member states. Existing notified bodies under other EU legislation streamlining applications.

What CRA Compliance Requires

CRA compliance is not a single certification. It is a set of security, documentation and assessment obligations spanning the entire product lifecycle.

Security-by-Design & Secure Default

Products must be designed with security in mind from development onset. Default passwords must be eliminated. Non-essential ports and services must be disabled. Security settings must be secure by default. Authentication, access control, data encryption and secure boot mechanisms must be implemented where appropriate. These requirements apply throughout the product lifecycle, not just at initial release.

Vulnerability Management & Reporting

Manufacturers must establish effective vulnerability identification, remediation and disclosure processes. Actively exploited vulnerabilities must be reported to ENISA within 24 hours (early warning), with full analysis within 72 hours. Security updates must be provided throughout the product support period. This obligation has been active since 11 September 2026.

Technical Documentation & SBOM

Manufacturers must prepare comprehensive technical documentation including security design specifications, risk assessment reports, vulnerability handling records and a software bill of materials (SBOM). The SBOM must cover all third-party components and their known vulnerabilities. Documentation must be maintained and updated throughout the product lifecycle.

Conformity Assessment & CE Marking

Products must undergo conformity assessment before being placed on the EU market. Class I (default) products may use self-assessment. Class II (important) and Class III (critical) products require third-party assessment by a notified body. Successful assessment results in CE marking and EU declaration of conformity. Products cannot be sold in the EU without CE marking from December 2027.

CRA Compliance Service Map

From horizontal regulation to emerging product cybersecurity compliance market.

REGULATION & STANDARDS
CRA
Regulation 2024/2847
ENISA
Vulnerability Reporting
IEC 62443-4-1
SDL Framework
ETSI CRA
Standards Drafts
↓
COMPLIANCE REQUIREMENTS
Security-by-
design
Vulnerability
management
SBOM & risk
documentation
CE marking &
conformity
↓
SERVICE LAYERS
Assessment
Product security
testing & audit
Tooling
SBOM generation
& management
Consulting
SDL & compliance
advisory
Certification
Notified bodies
& testing labs
↓
BUYERS
IoT & consumer
electronics mfrs
Software
vendors
Industrial
equipment mfrs
Importers &
distributors

Emerging Service Ecosystem

Product Security Assessment Firms

Trail of Bits, Bishop Fox, NCC Group, Include Security — extending traditional security testing into CRA-specific product assessment. Services include pre-market security audits, vulnerability scanning, penetration testing and CRA gap analysis. Many firms are building dedicated CRA compliance assessment packages.

SBOM & Vulnerability Tooling

CycloneDX (OWASP) — open SBOM standard increasingly adopted for CRA compliance. Snyk, Dependabot, JFrog — component vulnerability tracking. anchore, Syft — automated SBOM generation. These tools address the CRA's SBOM and vulnerability management documentation requirements.

Cybersecurity Consultancies

Deloitte, EY, PwC, KPMG — all building CRA compliance advisory practices. BSI Group, TÜV, SGS, LRQA — preparing conformity assessment capabilities for CRA notification. Services include readiness assessments, gap analysis, SDL implementation consulting and conformity assessment preparation.

Standards & Certification Bodies

ETSI — publishing CRA technical standards drafts. IEC 62443-4-1 — widely referenced as the SDL compliance framework. ENISA — operating the Single Reporting Platform for vulnerability notifications. CEN/CENELEC — developing harmonized standards for CRA conformity assessment.

Evidence Classification

What Is Verified

  • CRA (Regulation 2024/2847) is binding law
  • Vulnerability reporting obligations active since 11 Sep 2026
  • Full enforcement: 11 December 2027
  • Fines: up to €15M or 2.5% global turnover
  • Scope: all products with direct/indirect network connectivity
  • CE marking mandatory for in-scope products
  • ENISA operating the Single Reporting Platform (SRP)
  • ETSI publishing CRA technical standards drafts

What Is Inferred

  • Product cybersecurity compliance services will become a recurring market, not a one-time assessment
  • SBOM tooling demand will grow substantially as every manufacturer needs component tracking
  • Notified body capacity will be a bottleneck for Class II and III conformity assessments
  • Non-EU jurisdictions (UK, Australia, US) will adopt equivalent product cybersecurity requirements

What Is Unknown

  • How many notified bodies will be designated and by when
  • Whether self-assessment routes will cover most products, limiting third-party assessment demand
  • How member states will differ in enforcement approach
  • Whether open-source software faces different compliance pathways in practice
  • The exact product classification for Class II and Class III categories

What Could Break the Thesis

  • Further delays. The CRA already has a phased implementation. Political pressure from industry could trigger additional deadline extensions, reducing urgency for compliance investment.
  • Self-assessment dominance. If most products fall into Class I (default) and can use self-assessment, the third-party conformity assessment market will be significantly smaller than expected.
  • Enforcement inconsistency. Member states must designate competent authorities and notified bodies. If capacity varies widely, the level playing field may not materialise and enforcement may be uneven.
  • Open-source exemption scope. If open-source software developed outside commercial activity receives broad exemptions, a significant portion of software development may operate outside the compliance framework.
  • Tooling commoditisation. If automated SBOM generation and vulnerability scanning tools become sufficient for basic compliance documentation, the premium consulting and assessment market may be smaller than expected.

What Companies Should Prepare

  1. Classify your products — determine which fall under CRA scope (any product with direct or indirect network connectivity) and identify the applicable class (default, important or critical)
  2. Establish vulnerability reporting capability — build or procure a process for reporting actively exploited vulnerabilities to ENISA within 24 hours, with full analysis within 72 hours (this obligation is already active)
  3. Conduct security-by-design review — audit your product development process against CRA Annex I requirements including secure default settings, authentication, access control, data encryption and secure update mechanisms
  4. Generate SBOM — create a comprehensive software bill of materials for each product covering all third-party components, their versions and known vulnerabilities
  5. Prepare technical documentation — compile security design specifications, risk assessment reports, vulnerability handling records and test evidence required for conformity assessment
  6. Determine conformity assessment route — Class I products may use self-assessment; Class II and III require notified body assessment. Verify whether your product category has been classified
  7. Map to IEC 62443-4-1 — align your secure development lifecycle with this widely referenced standard as evidence of CRA compliance
  8. Plan for CE marking — integrate CRA conformity assessment into your existing CE marking process, ensuring technical documentation and EU declaration of conformity are ready before December 2027

Sources

Tier A — Primary Regulatory Sources

  • EUR-Lex: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 13 November 2024 laying down horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). OJ L 2024/2847.
  • ENISA: Single Reporting Platform (SRP) for vulnerability and incident reporting under the CRA. enisa.europa.eu

Tier B — Official / Institutional Sources

  • Kirkland & Ellis: "The EU Cyber Resilience Act: Preparing for the New Reporting Obligations for Products With Digital Elements" (September 2026). Detailed legal analysis of Article 14 reporting obligations.
  • ETSI: Multiple CRA technical standards drafts published for public comment. etsi.org
  • Gigadevice: CRA compliance timeline and manufacturer requirements overview. Published September 2026.

Tier C — Commercial / Industry Sources

  • CycloneDX (OWASP): Open SBOM standard for CRA compliance documentation. cyclonedx.org
  • Silicon Labs: CRA commitment and product compliance approach. silabs.com. Published September 2026.
  • Multiple Chinese compliance advisory firms: CRA compliance guides for export enterprises. Published September–October 2026.

Tier D — Industry Media (not official sources)

  • Multiple law firm publications on CRA implementation timelines, conformity assessment pathways and product classification.
  • CSDN technical analysis of CRA engineering implementation requirements for embedded products.

Published: 2026-10-06 · Last updated: 2026-10-06 · Status: TESTING

This is an independent research publication by Emerging Industries Intelligence. It is not legal advice.