[OT Sec] Analysis of the EU Cyber Resilience Act (CRA): Security Requirements and Regulatory Impacts on Digital Products

Table of Contents
1. Overview

As security threats to digital products and services continue to grow, the European Union (EU) has proposed the Cyber Resilience Act (CRA). The CRA is the first legislative act to clearly define cybersecurity requirements for all network-connected products and software sold in the European market.
The core objective of the CRA is to ensure security throughout the entire product lifecycle, from design to decommissioning, reducing security vulnerabilities and protecting users and businesses from cyberattacks.
The CRA targets a wide range of products, including Industrial Control Systems (ICS), Internet of Things (IoT) devices, network equipment, and security software. Manufacturers that fail to comply with the cybersecurity requirements will face strict regulatory consequences.
2. Scope and Key Requirements

The CRA applies to network-connected products and related software. The main targets include:
1) Products under the CRA Scope:
- Industrial Control Systems (ICS) and OT equipment (SCADA, PLC, DCS)
- IoT devices (smart appliances, medical devices, connected cars, etc.)
- Network equipment (firewalls, routers, switches, etc.)
- Operating systems and security software
- Cloud and SaaS-based applications
2) Products excluded from CRA:
- Products for national security and military use
- Research and testing equipment
- Open-source software, under certain conditions
The CRA applies different security requirements based on the level of risk associated with each product, and manufacturers must comply with the relevant cybersecurity requirements.
3. Key Cybersecurity Requirements of the CRA

To ensure product security and prevent cybersecurity incidents, the CRA mandates the following:
1) Cybersecurity Risk Assessment
- Perform cybersecurity risk assessments and identify potential vulnerabilities in advance.
- Apply security controls if the product is network-connected.
- Continuously update risk assessments when new vulnerabilities are discovered.
2) Essential Security Requirements
- All digital products must follow Security by Design principles.
- Products must be shipped with default secure settings.
- Clear guidance must be provided to users on security features and settings.
3) Vulnerability Handling & Security Updates
- Manufacturers must establish vulnerability detection and response processes.
- Report vulnerabilities to relevant authorities (e.g., ENISA) within 24 hours.
- Provide security updates and patches for at least five years.
- Operate a Vulnerability Disclosure Program (VDP).
4) Technical & General Documentation
- Document the security architecture and key security features of the product.
- Provide technical documents on hardware/software security design.
- Maintain documentation on vulnerability handling, network protection, and patch management processes.
5) EU Declaration of Conformity (DoC)
- Manufacturers must submit an EU Declaration of Conformity, ensuring compliance with CRA security requirements.
- The DoC includes security testing results, vulnerability management procedures, and technical documentation.
- This allows the product to be CE marked and legally sold in the EU market.
6) Communications with Authorities & Incident Reporting
- Manufacturers must report cybersecurity incidents to EU authorities immediately.
- Share discovered vulnerabilities with ENISA and national security agencies.
- Establish a collaborative network with researchers and security companies for threat response.
7) Application for Certification
- Manufacturers must apply to a Notified Body for cybersecurity certification.
- Undergo security evaluation to verify compliance with CRA requirements.
- Conduct regular audits and testing to maintain certification status.
4. CRA Implementation Timeline & Regulatory Impact

The CRA aims to finalize its legislative process in 2024, with key milestones as follows:
- 2024: Final approval of the act
- 2025: Publication of detailed technical regulations
- 2027: Full enforcement and mandatory compliance
Once enforced, all digital product manufacturers entering the EU market must comply with the CRA. Non-compliance may result in sales bans and fines of up to EUR 15 million (approx. KRW 22 billion) or 2.5% of global annual turnover, whichever is higher.
5. Conclusion

The CRA is the first comprehensive legislation regulating the cybersecurity of digital products. It sets strict security standards for all network-connected products and software.
Manufacturers and suppliers must establish processes for risk assessment, vulnerability management, security updates, technical documentation, and incident reporting to comply with CRA requirements and enter the EU market.
The CRA is not just a guideline but a mandatory regulation—non-compliance could lead to market exclusion. Therefore, organizations must reinforce Security by Design, build systematic security processes, and prepare for upcoming regulatory changes.