← Back to list

The Cyber Resilience Act and the End of Insecure Products

Digital products have become ordinary parts of everyday life. Homes contain smart speakers, routers, connected cameras, fitness trackers…

Karl Saamuel Hollman in TalTech Legal Lab Blog · 2026-05-25 09:56 · 0 claps · 9.7 min read
#cybersecurity #cyber-resilience-act #eu-law #insecure-products
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🚀 · Self Improvement 💪 · Fitness & Wellness 📷 · Photography ⚖️ · Law & Justice

Image from the collection of Magnific

Image from the collection of Magnific

The Cyber Resilience Act and the End of Insecure Products

Digital products have become ordinary parts of everyday life. Homes contain smart speakers, routers, connected cameras, fitness trackers, baby monitors, smart TVs, and internet-connected appliances. Businesses depend on software, cloud-connected devices, industrial control systems, digital platforms, and remote services. Public institutions also rely on digital infrastructure to provide essential functions. Yet many of these products have historically entered the market with weak passwords, poor update mechanisms, insecure default settings, unclear support periods, and limited vulnerability management.

The Cyber Resilience Act changes this legal landscape. It treats cybersecurity not as an optional product feature, but as a mandatory condition for placing products with digital elements on the EU market. The Act therefore marks an important shift in EU law: cybersecurity is becoming part of product compliance, product safety, and market access.

The central argument of this blogpost is that the Cyber Resilience Act moves the EU away from a “buyer beware” model of digital security. Instead, it places responsibility on manufacturers and other economic operators to ensure that digital products are designed, developed, maintained, and supported in a cybersecure manner throughout their lifecycle.

What is the Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. It was adopted on 23 October 2024, published in the Official Journal on 20 November 2024, and entered into force on 10 December 2024. The main obligations will apply from 11 December 2027, while reporting obligations for actively exploited vulnerabilities and severe incidents will apply earlier, from 11 September 2026.

The Act applies to products with digital elements. This includes hardware and software products whose intended or reasonably foreseeable use involves a direct or indirect data connection to a device or network. In practical terms, the scope is broad. It may cover connected consumer devices, software applications, operating systems, network equipment, industrial digital products, identity management tools, password managers, and many other products that form part of the digital environment.

The European Commission explains that the Act introduces mandatory cybersecurity requirements for hardware and software products throughout their lifecycle. Products that comply with the CRA will bear the CE marking, and national market surveillance authorities will supervise enforcement.

This is legally significant because the CRA does not merely regulate cybersecurity as an internal organisational matter. Unlike NIS2, which focuses mainly on the cyber resilience of essential and important entities, the CRA focuses on the security of products themselves. It asks whether a digital product is sufficiently secure before and after it reaches the market.

Cybersecurity becomes product compliance

The deeper importance of the Cyber Resilience Act is that it changes how we understand digital product safety. A product with digital elements is not truly safe if it can easily be compromised, manipulated, hijacked, or used as an entry point into other systems. A smart camera with weak access controls, a router without security updates, or a software product with poor vulnerability handling may create risks not only for the buyer, but also for other users, networks, and services.

The CRA therefore treats cybersecurity as a legal feature of product conformity. In the past, security weaknesses were often treated as technical defects, maintenance problems, or matters for contractual support. Under the CRA, cybersecurity becomes part of the legal conditions for making a product available on the EU market.

This is a major shift. It means that an insecure digital product may no longer be seen merely as low quality or poorly designed. It may be legally non-compliant. Cybersecurity moves from being a competitive advantage to being a baseline regulatory requirement.

The Act also reflects a wider development in EU digital regulation. The EU is increasingly using market access rules to shape the design of digital technologies. The GDPR did this with data protection by design and by default. The AI Act does this with high-risk AI systems. The Cyber Resilience Act now applies similar regulatory logic to digital products: security must be integrated into the product from the beginning, not added later as an afterthought.

The problem of insecure products

The CRA responds to a structural market failure. Consumers and businesses often cannot assess the cybersecurity quality of a digital product before buying it. A device may look modern, affordable, and functional, while still having serious security weaknesses. The buyer usually cannot inspect the code, evaluate the update policy, test vulnerability management, or verify whether the manufacturer has secure development processes.

This creates an information asymmetry. Manufacturers know much more about the security of their products than users do. At the same time, insecure products can create externalities: the harm caused by one insecure device may extend beyond the owner. Compromised devices can be used in botnets, exploited to attack other systems, or used as gateways into corporate and public networks.

The Cyber Resilience Act addresses this by shifting part of the responsibility back to the producer. It requires manufacturers to consider cybersecurity throughout the product lifecycle and to provide security support. This is important because digital products do not become secure simply because users are careful. Security depends heavily on design choices made before the product reaches the market.

Who has obligations under the CRA?

The CRA regulates several categories of economic operators, but manufacturers carry the central responsibility. Manufacturers must ensure that products with digital elements are designed, developed, and produced in accordance with the essential cybersecurity requirements of the Act. They must also carry out conformity assessments, prepare technical documentation, provide instructions and information to users, and handle vulnerabilities.

Importers and distributors also have obligations. Importers must ensure that products manufactured outside the EU comply with the CRA before placing them on the EU market. Distributors must act with due care and avoid making non-compliant products available. This structure is familiar in EU product regulation: responsibility is distributed across the supply chain, but the manufacturer remains the primary actor responsible for product conformity.

This matters because many digital products sold in the EU are developed, assembled, or maintained through complex international supply chains. A product may contain third-party components, open-source software, outsourced development, cloud dependencies, and embedded services. The CRA forces companies to treat cybersecurity as a supply-chain and lifecycle issue, not merely as a final-stage technical check.

Security by design and by default

One of the most important legal ideas behind the CRA is security by design. The Act rejects the idea that cybersecurity can be added after the product has already been built. Security must be considered during design, development, production, and maintenance.

This has practical consequences. Products should be configured securely by default. They should protect against unauthorised access, reduce attack surfaces, support vulnerability handling, and allow security updates. Manufacturers should avoid placing the burden entirely on users to configure basic protections. A product should not be insecure simply because the user failed to discover hidden settings or change unsafe defaults.

This approach is important because many cybersecurity failures are predictable. Weak default passwords, lack of encryption, unsupported software components, poor access control, and missing update mechanisms are not extraordinary events. They are design and governance failures. The CRA turns these failures into compliance concerns.

The legal message is clear: cybersecurity is not a luxury feature. A connected product should not be sold first and secured later. It should be placed on the market only if cybersecurity has been integrated into its design logic.

Security does not end at the moment of sale

Traditional product regulation often focuses on the moment a product is placed on the market. Digital products complicate this model because they remain vulnerable after sale. New vulnerabilities may be discovered months or years later. Attack techniques evolve. Software dependencies age. Support periods end. A product that was reasonably secure at launch may become insecure over time if it is not maintained.

The Cyber Resilience Act responds by adopting a lifecycle approach. Manufacturers must not only design products securely but also manage vulnerabilities and provide security updates. This is one of the CRA’s most important contributions. It recognises that cybersecurity is not a one-time compliance event. It is a continuing obligation.

This lifecycle logic is particularly important for consumer devices. Users may buy a connected product and reasonably expect it to function for several years. If the manufacturer stops providing updates too early, the product may remain physically usable but digitally unsafe. The CRA therefore connects product security with post-market support.

For businesses, this also changes procurement and compliance expectations. Buyers of digital products will increasingly need to ask: How long will the product receive security updates? How are vulnerabilities disclosed? Are software components documented? What happens if a critical vulnerability is discovered? These questions will become part of legal and commercial due diligence.

Vulnerability and incident reporting

The CRA also introduces reporting obligations. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements. These reports will be submitted through the Single Reporting Platform, which ENISA is tasked with establishing and operating.

This is a crucial part of the Act. It means that manufacturers must have internal processes for detecting vulnerabilities, assessing whether a vulnerability is being actively exploited, determining whether an incident is severe, and coordinating reporting with technical remediation.

The reporting framework also shows that the CRA is not only about preventing insecure products from entering the market. It is also about improving the EU’s ability to respond to vulnerabilities once products are already in use. ENISA describes the Single Reporting Platform as a tool that will allow manufacturers to report once rather than notify multiple national authorities separately.

In practice, this will require closer cooperation between legal, technical, and product teams. A vulnerability report is not merely a technical message. It may have regulatory consequences, reputational consequences, and customer communication implications. Companies will need clear internal procedures before the reporting obligations begin.

CE marking and market surveillance

Another important feature of the CRA is its connection to the EU’s existing product compliance system. Products covered by the Act will use the CE marking to indicate compliance with cybersecurity requirements. National market surveillance authorities will enforce the rules and may take action against non-compliant products.

This is symbolically and legally important. CE marking is familiar from product safety regulation. By connecting cybersecurity to CE marking, the EU is signalling that cybersecurity is now part of the basic conformity framework for digital products.

The practical implication is that cybersecurity becomes a market access issue. Non-compliant products may face restrictions, withdrawal, recall, or penalties. Manufacturers that treat cybersecurity as optional may find that they cannot lawfully place their products on the EU market.

This may also influence global product design. Because the EU market is large, manufacturers outside the EU may choose to align their products with CRA requirements even beyond Europe. In this sense, the CRA may have a regulatory effect similar to other EU digital laws: it can shape international compliance practices through access to the European market.

The relationship between the CRA and other EU cyber laws

The Cyber Resilience Act should not be viewed in isolation. It forms part of a broader EU cybersecurity framework. NIS2 focuses on the cybersecurity obligations of essential and important entities. The GDPR addresses the protection of personal data, including security of processing. The Cybersecurity Act strengthens ENISA’s role and creates cybersecurity certification frameworks. The CRA adds another layer by focusing on the security of products with digital elements.

This layered approach reflects the reality of digital risk. Cybersecurity failures can arise from many sources: weak organisational governance, poor data protection, insecure infrastructure, vulnerable products, negligent suppliers, or inadequate incident response. No single legal instrument can address all of these issues.

The CRA fills an important gap. Even if an organisation has strong internal cybersecurity governance, it may still be exposed if the products it uses are insecure. Conversely, even a well-designed product may become risky if the organisation using it fails to configure or maintain it properly. Cyber resilience therefore requires both secure organisations and secure products.

Does the CRA mean the end of insecure products?

The title of this blogpost asks whether the CRA means the end of insecure products. The answer is more nuanced. The CRA will not eliminate all vulnerabilities. No legal framework can guarantee perfect cybersecurity. Software will continue to contain bugs, attackers will continue to innovate, and digital systems will remain complex.

However, the CRA may mark the end of a particular regulatory tolerance: the idea that insecure products can be placed on the market without clear responsibility for their security. The Act does not promise perfect safety. Instead, it requires manufacturers to adopt a structured, documented, and lifecycle-based approach to cybersecurity.

This distinction is important. The CRA is not a guarantee that products will never be hacked. It is a legal framework for asking whether a manufacturer acted responsibly before and after the product entered the market. Did the manufacturer design the product securely? Were known risks addressed? Were updates provided? Were vulnerabilities handled? Were reporting obligations followed? Was conformity properly assessed?

In this way, the CRA changes the compliance question. The issue is not only whether a product failed. The issue is whether the manufacturer had a legally defensible cybersecurity process.

Conclusion: From functionality to resilience

The Cyber Resilience Act represents a major development in EU digital product law. It changes cybersecurity from a voluntary feature into a mandatory legal requirement. It also changes the meaning of product compliance. A digital product must not only function. It must be secure, maintainable, updateable, and resilient.

This is the Act’s broader legal significance. The EU is recognising that digital products create risks that cannot be managed only by users, IT departments, or post-incident responses. Cybersecurity must begin at the design stage and continue throughout the product lifecycle.

The CRA therefore moves the EU toward a new model of digital product responsibility. Manufacturers must take cybersecurity seriously before products reach consumers, businesses, and public institutions. Importers and distributors must also play a role in preventing non-compliant products from entering the market.

The result is a new baseline for the digital economy: if a product has digital elements, cybersecurity is part of its legal identity. The connected product of the future must not only be innovative and convenient. It must also be resilient.

References

European Commission. (2025). Cyber Resilience Act. Shaping Europe’s Digital Future. (https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)

European Commission. (2025). The Cyber Resilience Act: Summary of the legislative text. Shaping Europe’s Digital Future. (https://digital-strategy.ec.europa.eu/en/policies/cra-summary)

European Commission. (2026). Cyber Resilience Act: Reporting obligations. Shaping Europe’s Digital Future. (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)

European Union Agency for Cybersecurity. (2026). Single Reporting Platform (SRP). ENISA. (https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp)

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). (https://eur-lex.europa.eu/eli/reg/2024/2847)


메타데이터
post_id
6262c4cd59bc
slug
the-cyber-resilience-act-and-the-end-of-insecure-products-6262c4cd59bc
url
https://medium.com/taltech-legal-lab/the-cyber-resilience-act-and-the-end-of-insecure-products-6262c4cd59bc
canonical_url
https://medium.com/taltech-legal-lab/the-cyber-resilience-act-and-the-end-of-insecure-products-6262c4cd59bc
author_url
https://medium.com/@karlsaamuelh
status
ok
fetched_at
2026-06-14 11:28:49