下载文档 () / 20
动力,因我们而不同*

EU Cyber Resilience Act (CRA)

EU Cyber Resilience Act (CRA): What it means for your business

Key takeaways:

  • CRA introduces mandatory cybersecurity requirements for connected products
  • New reporting obligations for actively exploited vulnerabilities and severe incidents affecting in-scope products begin September 2026, with full compliance in December 2027
  • Eaton is aligning products, processes and documentation to meet all requirements

What is the Cyber Resilience Act? (CRA)

The Cyber Resilience Act (CRA) is a European Union (EU) regulation that establishes mandatory cybersecurity requirements for products with digital elements across their entire lifecycle, from design and development to post-market support.

Key requirements of the CRA

  • Secure-by-design product development
  • Software Bill of Materials (SBOM) transparency
  • Vulnerability management and disclosure
  • Ongoing security updates and patching
  • Incident reporting obligations

Which products are impacted?

In scope

  • Connected hardware and embedded systems
  • Software and digital control systems
  • Cloud-connected and network-enabled products

Out of scope (or limited scope)

  • Non-connected products
  • Products governed by sector-specific EU regulations (such as certain aerospace products)

CRA timeline and key compliance dates

September 2026 CRA requirements

  • Vulnerability reporting and incident requirements begin

December 2027 CRA requirements

  • Full compliance required
  • CE marking mandatory for in-scope products

What this means for your business

Greater transparency and documentation

  • SBOM, compliance visibility

Improved product security and reliability

  • Reduced risk of vulnerabilities

No disruption to Eaton product availability

  • We don't anticipate any disruption or delay of product availability due to CRA

How Eaton is preparing for CRA compliance

Governance and cross-functional alignment

  • Engineering, cybersecurity, quality, legal integration

Product portfolio assessment

  • Identifying in-scope products
  • Mapping requirements to lifecycle

Standards and industry engagement

  • Participation in CEN/CENELEC

How Eaton already aligns with CRA requirements

Secure-by-design product development

  • SDL + IEC 62443-4-1 alignment

Vulnerability response and disclosure

  • PSIRT + disclosure program

Continuous security lifecycle management

  • Updates, advisories, remediation processes

FAQs

The Cyber Resilience Act (CRA) is a European Union regulation designed to safeguard consumers and businesses buying software or hardware products with digital elements. It introduces mandatory cybersecurity requirements for manufacturers covering the planning, design, development and maintenance of such products. CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products.
spacer
Compliance requirements for the CRA begin in September 2026 and full compliance is required by December 2027.
spacer

The CRA regulations apply to connected hardware and embedded systems, software and digital control systems, and cloud-connected and network-enabled products.

Non-connected products are not covered by the CRA. In addition, products governed by sector-specific EU regulations are not covered by the CRA.

spacer

Eaton’s secure-by-design product development process and existing vulnerability response and disclosure practices are being enhanced by additional governance and cross-functional alignment across engineering, cybersecurity, quality and legal teams. In addition, Eaton is conducting a product portfolio assessment to identify in-scope products and mapping requirements to the product lifecycle.

Eaton participates in CEN/CENELEC to support development of European and international standards that incorporate quality, safety, environmental, interoperability and accessibility requirements.

spacer
  • Cybersecurity is a fundamental part of Eaton’s “secure by design” approach and is built into every product we deliver. Eaton already manages cybersecurity risks throughout the entire product lifecycle, from early design and risk analysis to testing, deployment and ongoing support, as the CRA now requires.
  • The CRA brings new reporting obligations regarding actively exploited vulnerabilities and severe incidents.
  • There are legacy product exemptions within the CRA for products placed on the EU market before 11 December 2027. If an existing product undergoes a substantial modification after December 2027, it loses the legacy exemption and must fully comply with CRA.
spacer

Supplier selection and contracting

  • The CRA requires manufacturers to take reasonable steps to ensure that products we procure, import or distribute meet the CRA’s essential cybersecurity requirements. The CRA requires that cybersecurity be embedded in Eaton’s supplier selection and contracting processes. 

SBOMs and technical documentation

  • The CRA requires that manufacturers require suppliers to provide a SBOM and technical documentation for their products as a condition of contract.

Contractual controls

  • Contracts with suppliers must require that they meet Annex I standards, provide SBOMs and documentation, and maintain vulnerability disclosure processes, with indemnities if they fail to do so.

Distribution obligations

  • For distribution of third-party products, Eaton must verify CE marking, EU declaration of conformity and manufacturer/importer documentation before contracts are signed.
  • For white-label products sold under the Eaton name, Eaton has full manufacturer obligations.
  • For products we customize or modify, such as adding firmware, software or integrating a product, this may constitute a substantial modification and trigger full manufacturer obligations.
  • If non-compliance is discovered after procurement, Eaton should halt distribution and notify the manufacturer and importer.
spacer