
Digital devices and software are part of our everyday lives, and every new product brings with it not only new features but also potential security risks. With the Cyber Resilience Act (CRA), the EU has introduced new regulations to ensure that digital products are better equipped to withstand cyberattacks right from the start. Manufacturers must embed cyber security as an integral part of their development process, whilst businesses must prepare to meet new requirements.
But what exactly does the CRA require of businesses? What are the relevant deadlines? And how does Mint Secure support implementation? Let’s take a closer look.
What is the Cyber Resilience Act?
The Cyber Resilience Act is an EU regulation designed to ensure that all digital products containing ‘electronic components’ meet a minimum level of cybersecurity. This applies to software, IoT devices, industrial systems and more. The aim is to minimise security vulnerabilities and oblige companies to keep their products secure throughout their entire lifecycle.
Key points of the CRA
Security by Design:
Cybersecurity must be taken into account right from the development phase.
Regular updates:
Manufacturers must actively address vulnerabilities.
Reporting obligations
Security incidents must be reported within 24 hours.
Documentation requirement
Organisations must maintain a Software Bill of Materials (SBOM).
CE marking
Products that do not comply with the CRA may not be sold in the EU.
Comparison with NIS2: Are there any parallels?
The NIS2 standard is another EU regulation on cybersecurity that focuses on critical infrastructure. Whilst the Cyber Resilience Act focuses on digital products, NIS2 deals with the security of networks and systems.
Common features
Both are based on ‘security by design’.
Both require reporting obligations for security incidents.
Both provide for heavy penalties for non-compliance.
Differences
The CRA applies to all digital products, whilst NIS2 focuses on critical infrastructure.
The CRA requires a Software Bill of Materials (SBOM), whereas NIS2 does not.
NIS2 requires organisations to carry out a risk assessment, whilst the CRA focuses on product development.
Deadlines and timeframes: What must organisations do?
The CRA implementation will be carried out in stages. The following dates are key:
March 2024
Final adoption of the CRA by the European Commission.
January 2025
Companies must take the first steps towards security screening.
December 2027
All new products must comply with the CRA, otherwise sanctions may be imposed.
Penalties for non-compliance:
- Heavy fines for companies that do not comply.
- A ban on the sale of products without CRA certification.
- Damage to reputation, as breaches of the CRA undermine customer trust.
How Mint Secure supports you
Mint Secure supports companies in the CRA implementation, from the technical testing of products to the required documentation. The following services are particularly relevant:
Security analyses & penetration testing
Identification of vulnerabilities in digital products before they are launched on the market. See the full scope of services
Compliance consultancy
Support with documentation, SBOMs and CRA certification. See the scope of services
Training & Awareness
Staff training on secure software development and CRA requirements.
Incident Response
Assistance with reporting and managing security incidents within the 24-hour deadline. Scope of services
Conclusion
The Cyber Resilience Act is a milestone for digital security in Europe. Organisations should prepare well in advance to avoid penalties and design their products to be secure from the outset.
Those who embed the requirements early on in development, update processes and documentation will not only meet the deadlines on time, but will also gain a head start over competitors who only begin shortly before December 2027.
Mint Secure supports you from the initial assessment right through to CRA-compliant documentation. Please get in touch.

