EU Cyber Resilience Act (CRA)
Key takeaways:
The Cyber Resilience Act (CRA) is a European Union (EU) regulation that establishes mandatory cybersecurity requirements for products with digital elements across their entire lifecycle, from design and development to post-market support.
In scope
Out of scope (or limited scope)
September 2026 CRA requirements
December 2027 CRA requirements
Governance and cross-functional alignment
Product portfolio assessment
Standards and industry engagement
Secure-by-design product development
Vulnerability response and disclosure
Continuous security lifecycle management
The CRA regulations apply to connected hardware and embedded systems, software and digital control systems, and cloud-connected and network-enabled products.
Non-connected products are not covered by the CRA. In addition, products governed by sector-specific EU regulations are not covered by the CRA.
Eaton’s secure-by-design product development process and existing vulnerability response and disclosure practices are being enhanced by additional governance and cross-functional alignment across engineering, cybersecurity, quality and legal teams. In addition, Eaton is conducting a product portfolio assessment to identify in-scope products and mapping requirements to the product lifecycle.
Eaton participates in CEN/CENELEC to support development of European and international standards that incorporate quality, safety, environmental, interoperability and accessibility requirements.
Supplier selection and contracting
SBOMs and technical documentation
Contractual controls
Distribution obligations