Cyber Resilience Act.
Cybersecurity requirements for products with digital elements
What CRA requires.
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements, throughout their lifecycle.
Products are built from components, software and services from many suppliers. Showing that a product meets its requirements means collecting information from that value chain — and keeping it current for as long as the product is on the market.
Why it's hard.
A lifecycle obligation
Requirements apply throughout the product lifecycle, not only at launch.
Components from many suppliers
Software and hardware components come from suppliers who hold the information you need.
Documentation that stays current
Evidence has to be kept up to date as products and components change.
Overlap with NIS2
Cybersecurity requests from customers often mix product and organisational requirements.
How Regweaver helps.
CRA requirements as structured requests
Turn CRA requirements into structured requests that run through the same relationships as your other frameworks.
Across the value chain
Send requests to suppliers and partners in every tier you work with, and see which answers are outstanding.
Evidence tied to the requirement
Every answer and document is linked to the requirement it supports, so the trail is there when someone asks.
Versioned records
Answers and evidence are versioned and timestamped, so you can show what was known and when.
Who's affected.
You may not be in scope — but your customers are.
Companies in scope
Regulation impacts organisations — but execution happens across teams.
Teams responsible for compliance
Related: Multi-tier value chain governance
Not sure how the CRA applies to your products?
Request a RegCheck and get a tailored regulatory overview from our team.