AI for business · Regulation
Cyber Resilience Act — products with digital elements
Cybersecurity requirements for hardware and software products sold in the EU — from smart devices to apps — for their whole life cycle.
Applies in phasesEUCybersecurityRegulation (EU) 2024/2847
What it means for AI
AI software and devices with AI are products with digital elements. A high-risk AI system that meets the CRA’s essential requirements is presumed to meet the AI Act’s cybersecurity requirement.
What you must do
- Since 11 Sep 2026: report actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform — early warning in 24 h, notification in 72 h, final report in 14 days (vulnerability) or one month (incident).
- From 11 Dec 2027: secure by design, no known exploitable vulnerabilities, security updates for the support period, SBOM, CE marking.
Examples
A Slovenian company sells a smart thermostat with a voice assistant
It must already report exploited vulnerabilities and from Dec 2027 meet all CRA requirements, including updates.
Key dates
The CRA enters into force.
Rules on conformity assessment bodies apply.
Reporting obligations for manufacturers apply.
All CRA requirements apply.
Fines
Up to €15 million or 2.5% of worldwide turnover.
Related regulations
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.