News line content

DATA MODUL among Germany’s Top 10 most innovative SMEs

EU Cyber Resilience Act at DATA MODUL

The Cyber Resilience Act (CRA) introduces new cybersecurity requirements for manufacturers of digital products and their supply chains. As a technology partner for industrial display, embedded, and system solutions, DATA MODUL is proactively preparing its products, processes, and documentation to comply with the new regulation. Together with our customers, suppliers, and technology partners, we are creating the foundation for a secure, transparent, and compliant implementation of the Cyber Resilience Act.

Cyber Resiliance Act at DATA MODUL

What does the Cyber Resilience Act mean for our customers?

The CRA establishes harmonized cybersecurity requirements across Europe for Products with Digital Elements (PDEs). As a result, manufacturers must address four key areas:

Security by Design

Security by Design

Products must follow Security by Design principles, ensuring cybersecurity risks are minimized throughout the entire product lifecycle.

Risk Management

Vulnerability Management

Manufacturers are required to continuously identify, assess, and remediate vulnerabilities, including ongoing monitoring and the provision of security updates.

Security Documentation

Security Documentation

Manufacturers must provide comprehensive security and compliance documentation, including transparent information about software components.

Product Responsibility

Product Responsibility

Manufacturers remain responsible for providing security updates and vulnerability management throughout the intended product lifecycle.

Our Approach to the Cyber Resilience Act

DATA MODUL follows a Security by Design approach and is preparing its products, processes, and documentation to meet the requirements of the EU Cyber Resilience Act (EU) 2024/2847. Working closely with customers, suppliers, and technology partners, we ensure a transparent and compliant implementation.

SVG
Haken CRA

Security by Design

  • Consideration of Essential Security Requirements during product design and component selection 
  • Secure hardware and software architectures throughout the entire product lifecycle
SVG
Dokument CRA

Software Transparency

  • Comprehensive information on software components
  • Transparent security and compliance documentation
SVG
Lupe CRA

Vulnerability Management

  • Continuous identification, assessment, and remediation of vulnerabilities 
  • Ongoing delivery of security updates
SVG
Reporting

Reporting

  • Preparation of reporting processes for security incidents 
  • Close collaboration with customers, suppliers, and technology partners

Key Milestones of the Cyber Resilience Act

Cyber Resiliance Act Timeline

Questions about the Cyber Resilience Act?

Cyber Resilicane Act questions

The Cyber Resilience Act introduces new cybersecurity requirements for digital products throughout their entire lifecycle. Together, we can ensure a secure, transparent, and compliant implementation. Our experts are happy to advise you.

Contact our CRA experts

Frequently Asked Questions about the Cyber Resilience Act

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA) is an EU regulation that establishes harmonized cybersecurity requirements for Products with Digital Elements (PDEs) across Europe. Its objective is to reduce cyber risks throughout the entire product lifecycle and ensure a consistently high level of cybersecurity for digital products placed on the European market. Manufacturers are required to integrate cybersecurity into product development, manage vulnerabilities, and provide security updates.

Which products are covered by the Cyber Resilience Act?

The CRA generally applies to Products with Digital Elements (PDEs) that are made available on the European market. These include industrial embedded systems, single-board computers, panel PCs, displays with integrated electronics, IoT devices, and other connected hardware and software products. Whether and to what extent a product falls within the scope of the CRA depends on its functionality and intended use.

What requirements does the CRA place on manufacturers?

The CRA introduces comprehensive requirements covering the development, documentation, and lifecycle management of digital products. Key obligations include implementing Security by Design principles, establishing structured vulnerability management, maintaining transparent security and compliance documentation, and providing security updates throughout the intended product lifecycle. The overall objective is to reduce cybersecurity risks from the outset and ensure the long-term security of digital products.

What does the Cyber Resilience Act mean for DATA MODUL customers?

DATA MODUL is proactively preparing its products, processes, and documentation to meet the requirements of the Cyber Resilience Act. Working closely with customers, suppliers, and technology partners, we are creating the foundation for a transparent and compliant implementation of the new regulation. If you have any questions about the CRA or its implications for your products, our experts are happy to assist you.

When do the CRA requirements become applicable?

The Cyber Resilience Act entered into force on 11 December 2024. Additional obligations will take effect in stages, including the requirement to report actively exploited vulnerabilities from 11 September 2026. By 11 December 2027, all CRA requirements must be fully implemented. An overview of the most important milestones can be found in the CRA timeline on this page.

Which documentation will DATA MODUL provide under the CRA?

To meet the requirements of the Cyber Resilience Act, DATA MODUL is preparing comprehensive security and product documentation. This includes, among other things, a Software Bill of Materials (SBOM), security-related documentation, and information on vulnerability management. The scope and availability of this documentation will depend on the specific requirements of each product.

 

CRA Contact

For any questions, please feel free to contact us.
Please fill in the form and hit submit. If desired, we will get in touch with you within the next few days. Your contact data will be kept confidential.

You agree that we may store and process your data to answer your request. You can revoke your consent at any time by e-mail to datenschutz(at)data-modul.com or to the contact details given in the imprint. Incidentally, we refer to our privacy policy.