The EU Cyber Resilience Act (CRA) sets essential cybersecurity standards for IoT, smart home devices, and all digital products in the EU single market. It mandates security by design and by default, ensuring products remain secure throughout their lifecycle. The CRA applies to most hardware and software with digital elements, except for:

-Non-commercial projects

-Cloud services without physical components

-Industries like automotive, healthcare, and aviation already covered by specific regulations.

CRA Timeline
CRA Timeline
CRA Timeline
Manufacturer responsibilities under the CRA
Manufacturer responsibilities under the CRA
Manufacturer responsibilities under the CRA

Infineon is committed to helping customers not only comply with the Cyber Resilience Act (CRA), but also use it as a driver for growth and market leadership.

With roles in key CRA-shaping committees, Infineon offers comprehensive product mapping, tools, and insights to simplify compliance.

The European Cyber Resilience Act (CRA) is reshaping IoT cybersecurity. To simplify your compliance journey, we’ve compiled key resources to help you understand, prepare, and meet CRA requirements. Dive into expert insights, tools, and actionable guidance below.

1. Exclusive Interview: Thomas Rosteck (Chief Security Advisor, Infineon)
Gain insights into the CRA’s goals, impact on manufacturers, and future security trends.

Read the full interview

2. Blog: "Europe’s Cyber Resilience Act – Be Ready by 2027"
Explore key timelines, requirements, and best practices for secure product development.

Read the blog

3. Official CRA Legislation
Access the complete EU CRA regulatory text to stay fully informed.

Read the legislation

 

CRA Compliance made easy: Expert insights for C-Level Executives

Watch our training video to gain a comprehensive understanding of the EU Cyber Resilience Act and learn how to integrate its requirements into your business strategy,  for a more secured and future ready organization

1. On-Demand Webinar: Understanding EN 50764 – The CRA Harmonized Standard for Smartcards & Secure Elements
Explore EN 50764, the candidate CRA harmonized standard for smartcard and secure element platforms. Learn about its alignment within the CRA framework, key requirements, and implementation insights.

Watch the webinar

2.On-Demand Webinar: "Navigating the EU CRA"
Learn the CRA’s essential requirements, standardization progress, and compliance strategies with Infineon experts.

Watch the webinar

3.Podcast: "Preparing for CRA" – Insights from Preeti Ohri Khemani
Listen to expert advice on the CRA’s impact, global supply chains, and preparation strategies.

Stream the podcast

Please note that the table is indicative and based on preliminary guidance; it is subject to changes based on development of CRA harmonized standards, CRA implementation Acts, and any EU Commission- or ENISA- issued CRA guidance.

Frequently Asked Questions

Frequently Asked Questions

The EU CRA shall apply from 11th December 2027, and some of the key provisions, such as Chapter IV (Art. 35-51) on Notification of Conformity Assessment Bodies will become applicable from 11th June 2026. While the reporting obligations under Art. 14 will become applicable from 11th September 2026.

The EU CRA applies to all connected digital devices and components with hardware and software, that are sold within the EU single-market.

Manufacturers that fail to comply with the EU CRA may face may face significant fines and penalties, as determined by the relevant EU authorities.

The European Standardization organizations CEN-CENELEC and ETSI will be developing the harmonized European Standards for EU CRA for the next years

Manufacturers should consult the EU's guidelines and regulations, and consider partnering with security experts like Infineon to help your products meet the EU CRA's requirements.

This regulation applies to all products with digital elements that are capable to directly or indirectly connect with devices or networks, and that will be sold within the EU single-market.

Here are a couple of examples:

If your product is low security risk then it might fall under the CRA category "default"

Here are a couple of examples for this:

If your product is high security risk then it might fall under the CRA category "Important"

Here are a couple of examples for this:

Here are some examples of microelectronics components affected by CRA regulations:

The CRA conformity specifications will be developed by CENELEC as part of the CRA standardizations. The first drafts of the test catalogs are expected by end of 2025 for some of CRA aspects.

For third-party tests, the CE test labs – Notified Bodies are required.

Do you have any questions about the EU Cyber Resilience Act or how Infineon can help you comply? Contact us!

 

The European Cyber Resilience Act (CRA) is reshaping IoT cybersecurity. To simplify your compliance journey, we’ve compiled key resources to help you understand, prepare, and meet CRA requirements. Dive into expert insights, tools, and actionable guidance below.

1. Exclusive Interview: Thomas Rosteck (Chief Security Advisor, Infineon)
Gain insights into the CRA’s goals, impact on manufacturers, and future security trends.

Read the full interview

2. Blog: "Europe’s Cyber Resilience Act – Be Ready by 2027"
Explore key timelines, requirements, and best practices for secure product development.

Read the blog

3. Official CRA Legislation
Access the complete EU CRA regulatory text to stay fully informed.

Read the legislation

 

CRA Compliance made easy: Expert insights for C-Level Executives

Watch our training video to gain a comprehensive understanding of the EU Cyber Resilience Act and learn how to integrate its requirements into your business strategy,  for a more secured and future ready organization

1. On-Demand Webinar: Understanding EN 50764 – The CRA Harmonized Standard for Smartcards & Secure Elements
Explore EN 50764, the candidate CRA harmonized standard for smartcard and secure element platforms. Learn about its alignment within the CRA framework, key requirements, and implementation insights.

Watch the webinar

2.On-Demand Webinar: "Navigating the EU CRA"
Learn the CRA’s essential requirements, standardization progress, and compliance strategies with Infineon experts.

Watch the webinar

3.Podcast: "Preparing for CRA" – Insights from Preeti Ohri Khemani
Listen to expert advice on the CRA’s impact, global supply chains, and preparation strategies.

Stream the podcast

Please note that the table is indicative and based on preliminary guidance; it is subject to changes based on development of CRA harmonized standards, CRA implementation Acts, and any EU Commission- or ENISA- issued CRA guidance.

Frequently Asked Questions

Frequently Asked Questions

The EU CRA shall apply from 11th December 2027, and some of the key provisions, such as Chapter IV (Art. 35-51) on Notification of Conformity Assessment Bodies will become applicable from 11th June 2026. While the reporting obligations under Art. 14 will become applicable from 11th September 2026.

The EU CRA applies to all connected digital devices and components with hardware and software, that are sold within the EU single-market.

Manufacturers that fail to comply with the EU CRA may face may face significant fines and penalties, as determined by the relevant EU authorities.

The European Standardization organizations CEN-CENELEC and ETSI will be developing the harmonized European Standards for EU CRA for the next years

Manufacturers should consult the EU's guidelines and regulations, and consider partnering with security experts like Infineon to help your products meet the EU CRA's requirements.

This regulation applies to all products with digital elements that are capable to directly or indirectly connect with devices or networks, and that will be sold within the EU single-market.

Here are a couple of examples:

If your product is low security risk then it might fall under the CRA category "default"

Here are a couple of examples for this:

If your product is high security risk then it might fall under the CRA category "Important"

Here are a couple of examples for this:

Here are some examples of microelectronics components affected by CRA regulations:

The CRA conformity specifications will be developed by CENELEC as part of the CRA standardizations. The first drafts of the test catalogs are expected by end of 2025 for some of CRA aspects.

For third-party tests, the CE test labs – Notified Bodies are required.

Do you have any questions about the EU Cyber Resilience Act or how Infineon can help you comply? Contact us!