Siber Dayanıklılık Yasası — (AB) 2024/2847 bilgilendirme kartı (AES)
| |

EU Cyber Resilience Act (CRA): A New Era of Cybersecurity in Digital Products

Introduction: Why is CRA important?

The European Union has enacted a comprehensive regulation that brings digital security down to the product level: the Cyber Resilience Act (CRA). Officially known as Regulation (EU) 2024/2847, it entered into force on 10 December 2024 and establishes the first EU-wide horizontal (sector-independent) cybersecurity framework for ’products containing digital elements“.

Because the CRA is a directly applicable regulation, not a directive, it is applied uniformly in all EU member states without the need for national transposition. This means a single, predictable basis for every producer subject to the rules. Producers in third countries exporting to the EU, such as Turkey, are also obliged to comply with these rules insofar as their products are offered on the EU market.

This article objectively examines the scope of CRA, the key obligations it imposes on manufacturers, the phased implementation schedule, and what it means, particularly for Turkish electronics, IoT, white goods, and connected device manufacturers.

  • Canonical identification: Regulation (EU) 2024/2847 (CELEX 32024R2847).
  • Effective date: December 10, 2024.
  • Full implementation of key obligations: December 11, 2027.
  • Horizontal framework: applies to all products with digital elements, not just a specific sector.

Which products are included?

CRA's scope is structured around the concept of "products with digital elements." This definition encompasses all hardware and software products, as well as separately released remote data processing solutions, that can establish a direct or indirect (logical or physical) data connection to a network or other device. In short, virtually any smart product capable of connecting to the internet or another device is potentially included.

The regulation categorizes products according to their risk level. The vast majority of standard products may demonstrate compliance through the manufacturer's self-assessment (self-declaration). In contrast, "important" products, considered more sensitive from a cybersecurity perspective, are classified in Annex III and may be subject to stricter procedures according to their class (Class I or Class II). The highest-risk "critical" products are listed in Annex IV and may face the most stringent third-party assessment expectations.

Certain product categories are excluded from the scope of the CRA because they are subject to their own sectoral regulations (e.g., areas with their own cybersecurity regimes, such as certain medical devices, motor vehicles, aviation, and some marine equipment). It is necessary to assess exactly which category your product falls into in light of the relevant annexes and implementing regulations issued by the Commission.

  • Connected/smart hardware: routers, cameras, smart home devices, IoT sensors.
  • Home appliances and electronics: connected appliances such as refrigerators, washing machines, and TVs.
  • Software products: operating systems, applications, embedded software (firmware).
  • “Essential” products (Annex III, Class I/II) and “critical” products (Annex IV) are subject to stricter assessment.
  • Certain products with their own sectoral regulations (specific medical devices, vehicles, aviation) are excluded.

Manufacturer's responsibilities

CRA adopts an approach that extends cybersecurity throughout the entire product lifecycle. The manufacturer is obligated to consider security from the design phase (security by design and security by default), to release the product without known exploitable vulnerabilities, and to manage vulnerabilities throughout the product's support period.

Vulnerability handling is at the heart of the regulation: manufacturers must establish processes for identifying and resolving vulnerabilities and providing users with free security updates. Other expectations include maintaining a software bill of materials (SBOM) documenting the components included in the product and clearly defining the support period.

On the conformity assessment side, the classic EU “new approach” logic applies: the manufacturer conducts a conformity assessment, prepares a technical file and an EU declaration of conformity, and affixes the CE mark to the product that meets the requirements. The CE mark here is a declaration that the product meets the CRA’s essential cybersecurity requirements. Which assessment path is followed depends on whether the product is classified as standard, “material” or “critical”.

  • Security by design and default configuration.
  • Not including any known exploitable vulnerabilities at market launch.
  • Vulnerability management and free updates throughout the support period.
  • Maintaining software material lists (SBOM) and technical documentation.
  • Conformity assessment, EU declaration of conformity and CE mark.
  • A clearly defined support period that is communicated to the user.

Key dates: notification obligation or full implementation?

The CRA (Contract for the Protection of Natural Resources) does not come into effect on a single date, but rather gradually. Therefore, saying "the CRA starts in 2027" can be misleading; some obligations come into effect much earlier. While the regulation came into effect on December 10, 2024, the full implementation date for most of the essential requirements that manufacturers must comply with is December 11, 2027.

However, two intermediate milestones are critically important. First, the provisions of Section IV regarding notification by conformity assessment bodies (notified body system) will apply from 11 June 2026. Second, and most urgent for manufacturers: the obligations under Article 14 regarding the notification of actively exploited vulnerabilities and severe incidents will apply from 11 September 2026.

The Article 14 notification regime requires particular attention due to its staggered timelines: the manufacturer must provide an early warning within 24 hours of becoming aware of the issue, and a detailed notification within 72 hours. This early deadline implies a crisis communication and incident response capacity that many manufacturers must have in place even before completing full CRA compliance.

  • December 10, 2024: The regulations came into effect.
  • June 11, 2026: Notification of conformity assessment bodies (Part IV) comes into effect.
  • September 11, 2026: The obligation to report clear and serious incidents of abuse under Article 14 begins (24-hour early warning / 72-hour detailed notification).
  • December 11, 2027: Full implementation of key obligations.

What does this mean for Turkish manufacturers?

For Turkish manufacturers offering digitally integrated products (connected electronics, IoT, smart appliances, software, etc.) to the EU market, the CRA (Customs Act) is directly binding regardless of geographical location. Once a product is launched in the EU, the determining factor is not where the manufacturer is established, but whether the product meets the requirements. For manufacturers not based in the EU, placing their products on the market generally requires the presence of a responsible economic actor within the EU (e.g., an authorized representative or importer).

In practice, this may require a reassessment of product development and post-sales processes: secure software development lifecycle, vulnerability disclosure policy, update infrastructure, SBOM generation, and support period commitment. Given the early notification obligation on September 11, 2026, it is crucial that incident response and reporting mechanisms are in place before 2027.

Early preparation offers advantages both in spreading compliance costs over time and in ensuring uninterrupted access to the EU market after 2027. The first step is usually a scope assessment: which items in your product portfolio fall under the definition of “products with digital elements,” which of these could be classified as “material” or “critical,” and therefore which would be subject to stricter compliance pathways?

  • Turkish manufacturers exporting to the EU are subject to CRA to the extent that their products enter the EU market.
  • For non-EU producers, a responsible actor within the EU (authorized representative/importer) is usually required.
  • A secure development, open notification, and update infrastructure may need to be established.
  • The early warning date of September 11, 2026, requires that incident response capacity be ready early.
  • First practical step: scope and classification assessment for the product portfolio.

Frequently Asked Questions

Why does CRA bind manufacturers based in Türkiye?

CRA applies when a product is placed on the EU market; the manufacturer being outside the EU does not provide an exemption. You must comply with the requirements to the extent that your product is placed on the EU market. Furthermore, placing products on the market by manufacturers outside the EU generally requires the presence of a responsible economic actor (authorized representative or importer) within the EU.

If the main implementation is 2027, what are the dates for 2026?

The CRA will enter into force gradually. The main obligations will be fully implemented on 11 December 2027. However, the provisions of Section IV concerning the notification of conformity assessment bodies will enter into force on 11 June 2026, and the obligations under Article 14 concerning the notification of actively exploited vulnerabilities and serious incidents will enter into force on 11 September 2026.

“What exactly does "a product containing digital elements" encompass?

This encompasses hardware and software products that can establish a direct or indirect data connection to a network or other device, as well as separately offered remote data processing solutions. Typical examples include connected electronics, IoT devices, smart appliances, embedded software, and standalone software. Certain products with their own industry-specific cybersecurity regimes (specific medical devices, vehicles, aviation) are excluded.

“What do "important" and "critical" products mean?

CRA classifies products according to their risk level. Most standard products can be deemed compliant by the manufacturer's self-assessment. “Important” products are listed in Annex III (Class I/II) and may be subject to stricter procedures; the highest risk “critical” products are listed in Annex IV and may face the most stringent third-party assessment expectations. The precise classification is made in light of the relevant annexes and Commission implementing regulations.

What does the CE mark mean under CRA?

CRA follows the EU's "new approach" logic: the manufacturer conducts the conformity assessment, prepares the technical file and the EU declaration of conformity, and affixes the CE mark to the product that meets the requirements. In this context, the CE mark is a declaration that the product meets CRA's essential cybersecurity requirements; the assessment path to be followed varies according to the product's class (standard/material/critical).

This content is for informational purposes only and does not constitute legal opinion or compliance assessment. The current official legislation text (EUR-Lex) should be used for precise requirements.

Other Topics