EU Cyber Resilience Act at DATA MODUL
The Cyber Resilience Act (CRA) introduces new cybersecurity requirements for manufacturers of digital products and their supply chains. As a technology partner for industrial display, embedded, and system solutions, DATA MODUL is proactively preparing its products, processes, and documentation to comply with the new regulation. Together with our customers, suppliers, and technology partners, we are creating the foundation for a secure, transparent, and compliant implementation of the Cyber Resilience Act.
What does the Cyber Resilience Act mean for our customers?
The CRA establishes harmonized cybersecurity requirements across Europe for Products with Digital Elements (PDEs). As a result, manufacturers must address four key areas:
Security by Design
Products must follow Security by Design principles, ensuring cybersecurity risks are minimized throughout the entire product lifecycle.
Vulnerability Management
Manufacturers are required to continuously identify, assess, and remediate vulnerabilities, including ongoing monitoring and the provision of security updates.
Security Documentation
Manufacturers must provide comprehensive security and compliance documentation, including transparent information about software components.
Product Responsibility
Manufacturers remain responsible for providing security updates and vulnerability management throughout the intended product lifecycle.
Key Milestones of the Cyber Resilience Act
Questions about the Cyber Resilience Act?
The Cyber Resilience Act introduces new cybersecurity requirements for digital products throughout their entire lifecycle. Together, we can ensure a secure, transparent, and compliant implementation. Our experts are happy to advise you.
Frequently Asked Questions about the Cyber Resilience Act
What is the Cyber Resilience Act (CRA)?
The Cyber Resilience Act (CRA) is an EU regulation that establishes harmonized cybersecurity requirements for Products with Digital Elements (PDEs) across Europe. Its objective is to reduce cyber risks throughout the entire product lifecycle and ensure a consistently high level of cybersecurity for digital products placed on the European market. Manufacturers are required to integrate cybersecurity into product development, manage vulnerabilities, and provide security updates.
Which products are covered by the Cyber Resilience Act?
The CRA generally applies to Products with Digital Elements (PDEs) that are made available on the European market. These include industrial embedded systems, single-board computers, panel PCs, displays with integrated electronics, IoT devices, and other connected hardware and software products. Whether and to what extent a product falls within the scope of the CRA depends on its functionality and intended use.
What requirements does the CRA place on manufacturers?
The CRA introduces comprehensive requirements covering the development, documentation, and lifecycle management of digital products. Key obligations include implementing Security by Design principles, establishing structured vulnerability management, maintaining transparent security and compliance documentation, and providing security updates throughout the intended product lifecycle. The overall objective is to reduce cybersecurity risks from the outset and ensure the long-term security of digital products.
What does the Cyber Resilience Act mean for DATA MODUL customers?
DATA MODUL is proactively preparing its products, processes, and documentation to meet the requirements of the Cyber Resilience Act. Working closely with customers, suppliers, and technology partners, we are creating the foundation for a transparent and compliant implementation of the new regulation. If you have any questions about the CRA or its implications for your products, our experts are happy to assist you.
When do the CRA requirements become applicable?
The Cyber Resilience Act entered into force on 11 December 2024. Additional obligations will take effect in stages, including the requirement to report actively exploited vulnerabilities from 11 September 2026. By 11 December 2027, all CRA requirements must be fully implemented. An overview of the most important milestones can be found in the CRA timeline on this page.
Which documentation will DATA MODUL provide under the CRA?
To meet the requirements of the Cyber Resilience Act, DATA MODUL is preparing comprehensive security and product documentation. This includes, among other things, a Software Bill of Materials (SBOM), security-related documentation, and information on vulnerability management. The scope and availability of this documentation will depend on the specific requirements of each product.