Understanding the EU Cyber Resilience Act
Every week, I receive questions about the EU Cyber Resilience Act (CRA). Product managers wonder if their routers will comply. Security architects ask what "secure-by-default" means. Legal teams try to figure out compliance responsibilities when importing products.
The European Telecommunications Standards Institute (ETSI) released draft standards on August 13, covering 17 product categories, from operating systems to internet-connected toys. These are specific technical requirements that will determine if you can sell your products in the EU when the CRA takes effect in December 2027. The standards are in public enquiry now, with final versions expected by December 2026.
Here's what practitioners are asking when they reach out to me.
Compliance for Network Switches
Do you need to comply with all 17 standards or just one? Only the one that applies to your product category. The ETSI standards cover routers, modems, and switches as a distinct category. You'll need to meet the requirements in that specific standard.
However, if your switches include embedded management software, you might also need to consider the network management systems standard. If they have firewall capabilities, add that standard to your list. Product categories aren't always clear-cut.
Start by mapping every feature your product offers to the 17 categories. Then review the applicable standards when they're finalized in December 2026. You have until December 2027 to implement changes, but remember to factor in hardware redesign cycles, firmware updates, and third-party component sourcing.
Secure-by-Default Requirements
"Secure-by-default" means your product ships in its most secure configuration, not its most convenient one. The default admin password can't be "admin." Remote management can't be enabled out of the box. Unnecessary services can't run on startup.
The ETSI standards require secure-by-default settings across multiple product categories. Practically, this involves:
- Unique credentials per device
- Disabled or restricted remote access until the user enables it
- Encrypted communications as the default protocol
- Minimal attack surface in the initial configuration
You'll need to document why each default setting was chosen and how it balances security with usability. Your technical documentation for CE marking must demonstrate security considerations at every decision point.
Detailing Your Software Bill of Materials (SBOM)
The standards require a machine-readable Software Bill of Materials (SBOM) in a structured format like SPDX or CycloneDX, not a simple text file.
Your SBOM should identify every software component and dependency, including:
- Direct dependencies
- Transitive dependencies
- Version numbers for every component
- Known vulnerabilities associated with those versions
The machine-readable requirement allows automated tools to scan your SBOM against vulnerability databases. If you're shipping a firewall with a vulnerable version of OpenSSL, the SBOM should make that clear.
Start building your SBOM infrastructure now. This isn't something you can add three months before the deadline. You need tools that automatically generate and update the SBOM as part of your build process.
Compliance Responsibilities for US Companies
Under the CRA, manufacturers, importers, distributors, and service providers all have obligations. If you're the manufacturer selling to an EU importer, you're responsible for ensuring the product meets the standards before it enters the EU market.
Your distributor agreement should specify who handles conformity assessment, maintains technical documentation, and manages post-market surveillance. Don't assume the importer will handle it. The CRA holds manufacturers accountable even when they're not physically present in the EU.
If you're placing the product on the EU market, you need:
- A technical file demonstrating compliance with applicable ETSI standards
- A signed EU declaration of conformity
- CE marking on the product
- A process for handling vulnerability disclosures and issuing security updates
The "we just ship to distributors" defense won't work. The regulation follows the product, and you're the entity that designed and built it.
Supporting Security Updates
The proposed standards mandate post-sale update capabilities, but the specific support period depends on the product's expected lifetime. A network router has a different support obligation than a wearable device.
You'll need to define and publish your support period before selling the product. This becomes part of your compliance documentation. If you claim a five-year support window, you're legally obligated to provide security updates for five years.
Consider this when pricing products for the EU market. The cost of maintaining update infrastructure and monitoring vulnerabilities for years after sale needs to be in your business model.
Cryptographic Compliance for Password Managers
If the ETSI standard for password managers mandates modern cryptography, and your implementation relies on deprecated algorithms, you'll fail compliance.
"Modern cryptography" typically means current NIST or ECRYPT-CSA recommendations. Algorithms like SHA-1 or RSA-1024 won't pass. You need SHA-256 or better, RSA-2048 minimum, or equivalent elliptic curve implementations.
Backward compatibility modes are a gray area. If you support legacy algorithms only when explicitly required for compatibility with older systems, and your default mode uses modern cryptography, you might be compliant. But if your product defaults to weaker algorithms, that's a problem.
Review your cryptographic implementations against current NIST SP 800-175B and plan your migration path now. Cryptographic changes often require significant testing, especially in products that interoperate with other systems.
Next Steps
The ETSI standards are under public enquiry until mid-September through mid-November 2026, depending on the product category. If you manufacture or sell products in any of the 17 categories, submit comments during the enquiry period. The standards will be finalized by December 2026.
ETSI, along with CEN and CENELEC, is running workshops across Europe for small and medium businesses preparing for CRA compliance. Attend one if you're trying to understand how the standards apply to your products.
The compliance clock is ticking. December 2027 isn't far away when you consider product development cycles, testing, and documentation. Start mapping your products to the applicable standards now, before the final versions are published.





