ETC recognizes the European Union’s efforts to strengthen the cybersecurity of connected products through the Cyber Resilience Act (EU) 2024/2847. The CRA sets new requirements for manufacturers covering product security throughout the development lifecycle
and vulnerability handling and disclosure.
What the CRA Requires
The CRA applies to hardware and software products with digital elements sold in the EU.
In plain terms, it requires manufacturers to:
- Build security into products throughout their lifecycle, from design and development through ongoing support, rather than treating it as an afterthought.
- Establish a process for receiving, assessing, and disclosing security vulnerabilities, including timely reporting of actively exploited vulnerabilities to EU authorities.
Key Dates
- December 10, 2024 — CRA enters into force, beginning a 36-month transition period.
- September 11, 2026 — Reporting obligations begin for actively exploited vulnerabilities and severe incidents.
- December 11, 2027 — Main obligations take full effect, including conformity assessment and CE marking.
Our Commitment to Security
Security is an ongoing priority in how we design, build, and support our products. ETC's product security is guided by recognized frameworks and standards, including ISO/IEC 27001 for information security management, IEC 62443-4-1 for secure product development
lifecycles, and the NIST Secure Software Development Framework (SSDF).
Our Actions
We are monitoring the CRA’s implementation guidance and harmonized standards as they are finalized, and we are evaluating what changes, if any, our products and processes will need to meet the applicable requirements.
We are also engaging with European industry associations and technical working groups, including VPLT and ESTA, to help shape practical implementation guidance for our industry.
We are committed to meeting our obligations under the regulation ahead of the relevant deadlines.