The EU Cyber Resilience Act: does it apply to your business

Selling software, connected products or companion apps into Europe? Your business could fall within the EU Cyber Resilience Act, even if it is based outside the EU.

Robin Kanjilal
Robin Kanjilal
Managing Director
5 min read
The EU Cyber Resilience Act: does it apply to your business

Why location doesn't matter, and what actually determines if you're in scope.

Many organisations assume the EU Cyber Resilience Act (CRA) only affects technology companies based in Europe. In reality, that's one of the biggest misconceptions surrounding the legislation.

The CRA isn't concerned with where your business is located. It's concerned with whether you place products with digital elements onto the European market. That means a UK manufacturer selling connected products into Europe, a software company distributing applications to EU customers, or a business bundling a companion mobile app with its products could all find themselves subject to the legislation.

For organisations looking to grow internationally, particularly into European markets, understanding the CRA is becoming just as important as understanding CE marking, product safety or GDPR.

Cybersecurity that’s built in, not added on

Perhaps the most significant change the CRA brings is that cybersecurity can no longer be treated as something added after a product has been built. Organisations must instead demonstrate that security was considered from the outset, through secure-by-design development, vulnerability management, technical documentation and ongoing support.

And this legislation extends well beyond traditional hardware manufacturers.

Mobile applications, connected devices, embedded software and many digital products supplied as part of a commercial offering can all fall within scope. An organisation becomes the "manufacturer" under the CRA when it places products on the market under its own name or brand, even if the development or manufacturing has been outsourced.

Where the lines actually sit
The tricky part isn't the obvious cases, connected devices and standalone software are clearly in scope, and a purely informational website is clearly not. It's the products that sit in between.

A patient-facing app used for appointment reminders or product registration is likely to fall under the CRA if it isn't already regulated as a medical device. That’s even when it's offered free of charge, because supplying it as part of a commercial activity counts as placing it on the EU market.

Internal software, such as a warehouse management system used only within the business, generally sits outside the CRA, but that changes the moment it's commercialised, licensed or sold to customers.

Companion consumer apps, wellness applications and connected accessories without a medical purpose can all fall within scope too, even where the core product itself is regulated separately as a medical device.

The common thread is this: if a product has digital elements and reaches the EU market as part of a commercial offering, it's worth checking rather than assuming.

Dates worth knowing now

·      Reporting obligations came into effect on 11 September 2026.
They require actively exploited vulnerabilities and severe cyber incidents to be reported to ENISA or the relevant national CSIRT. An early warning is due within 24 hours, with formal notification required within 72.

·      The full requirements become mandatory from 11 December 2027.
These include secure-by-design and secure-by-default obligations, conformity assessment, CE marking and technical documentation.

What about products already on the market?
But not every business is starting from a blank sheet. Many organisations have CRA-applicable products already in the field that weren't designed with secure-by-design principles in mind. The legislation doesn't expect an overnight rebuild, but it does expect a credible path towards compliance.

That typically starts with a gap assessment against the CRA's requirements, identifying where vulnerability management, documentation or update processes fall short. Compensating controls, such as strengthened patching processes or improved monitoring, can then reduce risk while longer-term design changes are planned.

The December 2027 deadline gives existing products a transition window, but progress needs to be demonstrable.

Get ready for action

Whether you were aware of the need for CRA compliance or not, acting as soon as possible is crucial. Knowing whether the CRA applies to your business is just the first step. The next is understanding what needs to be done and where you should start.

Wondering where to start?
Take a look at this article outlining what compliance actually involves and the questions you should be asking.

 

 

 

 

 


 [BH1]Link to Part 2

Keep exploring

Related insights

let's collaborate

Contact our Dubai or Global teams to discuss IT infrastructure and security that supports regulated growth and international expansion.

Let's strengthen reliability and optimise your IT for efficiency.