Navigating the
EU Cyber Resilience Act (CRA)
Understand what the CRA means for products with digital elements, how cybersecurity responsibilities now extend across the full product lifecycle, and how AAEON is preparing to support customers entering the European market.
Secure by Design
Cybersecurity requirements must be incorporated throughout manufacturer’s product planning, design, development, and production to identify and address risks.
Lifecycle Support
Manufacturers must establish processes to identify, assess, and address vulnerabilities through security updates throughout a product's support period.
Secure by Default
Manufacturers must ensure products are secure by default, with cybersecurity measures in place to minimize attack surfaces and prevent known exploitable vulnerabilities.
Incident Reporting
Manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of products with digital elements within specified timelines.
What is the Timeline for the CRA?
The CRA entered into force in December 2024, but is being implemented in stages, with all of the Act’s main provisions fully applicable from 11 December 2027.
11 June 2026
CRA provisions for notifying conformity assessment bodies begin to apply.
11 September 2026
Mandatory vulnerability and incident reporting obligations begin.
11 December 2027
Remaining CRA requirements go into force, meaning products with digital elements within the Act’s scope must meet its essential cybersecurity requirements.
How Has AAEON Prepared for the CRA?
AAEON proactively reviewed its existing Product Security Development Lifecycle Process, as well as undertaking both internal and external reviews with independent consulting firms, achieving IEC 62443-4-1 Maturity Level 2 certification through LCIE (Laboratoire Central des Industries Électriques) in May 2026.
Through this certification, AAEON demonstrates that its Product Security Development Lifecycle Process incorporates standardized, repeatable procedures that embed cybersecurity into its full product development lifecycle, including:
- Cybersecurity requirements included with functional requirements in Product Requirements Documents (PRDs) for AAEON products.
- Software-specific security requirements defined in Software Requirements Specifications (SRSs) for AAEON products.
- SBOM provision during the design phase, including the registration of third-party components.
- Robust security verification and validation testing throughout product development, including threat mitigation and penetration testing.
- Secure code review to help identify and address potential security weaknesses.
- Security update processes and documentation in place for post-market vulnerability management.
How Can AAEON Help its Customers?
Recognizing that system integrators and solution builders remain responsible for assessing the conformity of their own finished products, AAEON has expanded the services it offers to support customers’ own CRA preparation and conformity assessment activities.
Automated SBOM Generation
Through CI/CD to provide our customers with greater visibility and transparency into third-party component management.
Product Security Testing
Including firmware security testing, SBOM verification, and Common Vulnerabilities and Exposures (CVE) tracking.
Pre-compliance Support
Pre-compliance reports and supporting documentation to assist customers with their own assessment activities, including CB and VoC processes where applicable.
Technical Evidence & Support
Technical evidence and practical support for customers preparing final products for introduction into the European market.
Together, these measures can help AAEON customers strengthen product security, improve market readiness, and reduce the technical and documentation workload associated with their own conformity assessment activities.
FAQs
What is the difference between the CRA & IEC 62443-4-1? |
The cybersecurity principles that underpin both the CRA and IEC 62443-4-1 have significant overlap, but within a different regulatory context. The CRA is a legally binding set of regulations implemented by the European Union, while IEC 62443-4-1 is a voluntary international standard that defines secure development lifecycle (SDL) requirements. Despite their shared security principles, IEC 62443-4-1 should not be regarded as an alternative to the CRA’s conformity assessment procedures. instead, the IEC 62443-4-1’s secure development practices framework can provide a structured base on which manufacturers and system integrators can build processes that address relevant CRA cybersecurity requirements. |
Does IEC 62443-4-1 certification guarantee CRA compliance? |
No, IEC 62443-4-1 certification confirms that a manufacturer has been independently assessed and found to operate a secure development lifecycle, but IEC 62443-4-1 certification covers the development process and not products specifically, and so cannot be used to replace the CRA’s conformity assessment requirements. |
What are the penalties for not complying with the CRA? |
The CRA provides clear guidelines on the penalties that may be imposed on entities for non-compliance, with severity determined by the provision that such an entity fails to comply with. This penalty is €15,000,000, or up to 2.5% of worldwide annual turnover for the preceding financial year in cases where the offender is an undertaking. Improper reporting, such as providing incomplete or misleading information to notified bodies carries administrative fines of up to €5,000,000, or up to 1% of worldwide annual turnover for the preceding financial year in cases where the offender is an undertaking. |
Does the CRA apply to manufacturers and businesses located outside Europe? |
Yes. The CRA applies to products with digital elements placed on the EU market regardless of where the manufacturer is located. This includes importers, who are responsible for ensuring appropriate conformity assessment procedures have been carried out by a product’s manufacturer prior to placing the product on the European market, while also being able to provide evidence in the form of technical documentation that necessary CRA requirements have been fulfilled. |
What benefit does a manufacturer holding IEC 62443-4-1 certification give system integrators? |
The security practices of upstream suppliers like AAEON can influence the cybersecurity posture of an integrator’s finished product. For example, vulnerabilities introduced by upstream third-party components may affect the security of a finished product, leading to conformity issues, additional costs, and delays in getting a product to market. |
What is an SBOM? |
A Software Bill of Materials (SBOM) is a comprehensive inventory of the software components used in a product. By providing and maintaining an SBOM, customers are able to determine which third-party components a platform contains, making it easier to evaluate and manage potential vulnerabilities throughout the product lifecycle. |
Can AAEON perform CRA conformity assessments for customers? |
No. AAEON can provide technical evidence, practical support, and supporting documentation such as pre-compliance reports, but responsibility for conformity remains with the manufacturer placing the finished product on the EU market. |
Prepare Today. Stay Ahead Tomorrow.
Download our full White Paper to learn more about CRA requirements, AAEON's preparation, and how we can support your compliance journey.