The Device Chronicle sat down with Will Jin, Cybersecurity Technical Lead at testing and certification agency TÜV SÜD, and Thomas Ryd, CEO, Northern.tech.
Will specializes in defining compliance roadmaps and aligning products with applicable regulations. He has rich expertise in cybersecurity, penetration testing, vulnerability assessments, and developing customized test programs for specific architectures and risk profiles.
Will and Thomas discussed the hidden complexities of complying with the EU Cyber Resilience Act (CRA).
For manufacturers of products with digital elements (PDEs), CRA compliance is mandatory. Starting September 11th, 2026, manufacturers are required to report vulnerabilities in their products; by December 11th, 2027, they must have complete workflows in place to achieve full compliance. The best path forward is through proactivity. By taking action now to understand the hidden complexities of the CRA, manufacturers can avoid potential court appearances, fines, and penalties.
Thomas asked Will who would enforce the CRA and what penalties manufacturers could face.
Will explains that each EU Member State will appoint its own market surveillance authorities to enforce the regulation. Exactly which bodies will take on this role is not yet clear, but enforcement will happen country by country. Authorities can use several methods, including database audits, direct documentation requests, and random sampling of off-the-shelf products.
Article 64 of the CRA sets out three tiers of fines, which apply from December 11, 2027. In each tier, the fine is a fixed amount or a percentage of worldwide annual turnover, whichever is higher.
Fines are not the only consequence. Will notes that a product that fails to meet the essential requirements can also be pulled from the EU market.
Will and Thomas emphasized the important link between the CRA and CE marking. Complying with the CRA determines whether a manufacturer can meet CE marking requirements at all. Products that fail to meet CRA requirements face fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is greater. Noncompliant OEMs also lose their valid CE mark, which excludes their products from the EU market, in addition to the financial penalties.
Will comments: "It doesn't matter if you've been selling a product forever – after December 11, 2027, if you lack CRA compliance, your DoC is invalid, and the fines are significant. Once product makers realize noncompliance threatens their CE marking, market access, and bottom line, they immediately prioritize compliance."
That urgency is not felt equally across industries. The CRA applies to almost any product with digital elements sold in the EU, but Will explains that machinery manufacturers are currently the most concerned about compliance. Timing adds to the pressure, as the sector is also preparing for new cybersecurity provisions under the EU Machinery Regulation (which is covered in more detail below).
Other sectors are exempt because they already comply with sector-specific EU regulations that mandate their own cybersecurity requirements. These sectors include medical devices, civil aviation, automotive, marine equipment, and products built exclusively for national security and defense. Certain SaaS products may also fall outside the CRA's scope. Will notes that when a SaaS product does not interact with other digital products, manufacturers can argue it is out of scope. For all other manufacturers, the starting point is the same: confirm whether your product is in scope, then treat CRA compliance as a condition of keeping the CE mark.
Thomas asked Will how manufacturers should approach CRA compliance. Will explains that manufacturers generally choose between two pathways:
Self-assessment: The CRA allows manufacturers of lower-risk products to assess their own compliance. However, the manufacturer assumes all regulatory risk, as no independent third party validates its documentation or processes.
Third-party certification: Will considers this the safest approach. A testing and certification body like TÜV SÜD guides the manufacturer through documentation, gap analysis, and testing requirements. The process ends with an official test report or certificate, based on the product's readiness.
Which pathway is open to a manufacturer depends on how the CRA classifies the product. Most products fall into the default category, where self-assessment is an option. Products classified as important or critical face stricter rules. Important Class I products can only be self-assessed when the manufacturer fully applies harmonized standards that are still being finalized. For Important Class II and critical products, third-party assessment is mandatory.
Thomas asked Will how the CRA relates to established standards and how manufacturers can reuse work they have already done.
Will and his colleagues at TÜV SÜD expect the CRA to become the primary cybersecurity benchmark for European manufacturers. They expect existing standards and provisions to be largely absorbed into the CRA framework. These include ETSI EN 303 645, EN 18031, and the cybersecurity provisions of the EU Radio Equipment Directive (RED). This is already underway for RED: the delegated regulation that brought cybersecurity into RED is set to be repealed on December 11, 2027, when the CRA fully applies.
IEC 62443 is a different case. Will notes that the standard remains deeply embedded in the industrial and machinery sectors. Manufacturers often use it to meet requirements in non-EU markets, such as Brazil or the UK, or to gain a competitive advantage. Common certifications include IEC 62443-4-1 for development processes, IEC 62443-4-2 for the technical requirements of control system components, and IEC 62443-3-3 for system-level capabilities.
According to Will, IEC 62443 certification overlaps with roughly 60–70% of the CRA's requirements. That is a strong head start, but manufacturers still need a targeted gap assessment to reach full compliance. IEC 62443-4-2 covers technical product testing and substantial documentation. However, it does not fully address the CRA's strict rules on upstream and downstream vulnerability handling and supply chain management.
Will also highlights an overlap between IEC 62443 and the EU Machinery Regulation, which introduces mandatory cybersecurity provisions from January 20, 2027. That date lands almost a year before the CRA fully applies, which is why machinery manufacturers feel the most pressure. For those already certified under IEC 62443, Will explains that existing documentation can help accelerate compliance with both regulations.
Thomas asked Will about the different certification approaches manufacturers can take for CRA compliance.
Standard-based certification involves a manufacturer aligning their product with a recognized, harmonized standard, such as EN 18031 for the Radio Equipment Directive (RED). Under this process, a testing agency evaluates the product against the standard, generates a technical report, and submits it to a Notified Body for the issuance of an official public certificate. This approach provides high market confidence, streamlined audits, and visibility in public registries.
In contrast, regulation-based certification is used when harmonized standards are unavailable or not applied. In this scenario, the Notified Body audits the product directly against the full text of the regulation to verify compliance across every single clause. This route requires complete compliance with all regulatory line items, meaning partial adherence or skipped requirements are not permitted.
Will further explained that the dedicated horizontal standards for CRA evaluation are being developed under the EN 40000 series, which is currently still in draft. Once the relevant standards are finalized and cited as harmonized standards in the Official Journal of the European Union (OJEU), manufacturers will be able to apply them to obtain a presumption of conformity with the CRA essential cybersecurity requirements covered by those standards.
Depending on the manufacturer’s readiness and existing cybersecurity framework, the compliance approach may involve direct application of the relevant EN 40000 standards or a gap assessment against those requirements. TÜV SÜD can provide the necessary guidance throughout the CRA compliance process and serve as a trusted compliance partner.
Thomas asked about the critical role that a testing and certification agency such as TÜV SÜD can play in the CRA compliance process.
Will explains that when a CRA Notified Body, such as TÜV SÜD, audits and signs off on a product, it issues a formal Certificate of Conformity. This third-party validation proves full regulatory compliance to market surveillance authorities without requiring the manufacturer to rely solely on self-assessment.
For products in the CRA's default (lower-risk) category, manufacturers may perform a self-assessment and issue their own EU DoC. To issue a DoC, the legal document must include product identification details and the corporate address. Specific regulations and harmonized standards applied (e.g., EN 18031, IEC 62443), with references to supporting technical files and cybersecurity documentation.
Will cautions that if a manufacturer strays from officially recognized standards during a self-declaration, market surveillance authorities will demand justification. Deviating from standard pathways may trigger rigorous audits and potential scrutiny over technical validity.
Thomas and Will discuss the dynamic nature of product lifecycles. Under the CRA, compliance requirements continue long after an initial launch.
Reporting obligations are already in effect. Since September 11, 2026, manufacturers that become aware of an actively exploited vulnerability or a severe incident must send an early warning within 24 hours and a full notification within 72 hours. For an exploited vulnerability, a final report is issued within 14 days after a fix becomes available. For a severe incident, the final report is due within one month.
Furthermore, manufacturers must declare a support period of at least five years, unless the product's expected lifetime is shorter. Throughout that period, they must monitor, assess, and fix vulnerabilities. Each security update released during the support period must also remain available for at least 10 years, or for the rest of the support period if that is longer.
Meeting these obligations for years after launch requires new, scalable workflows for secure updates and device lifecycle management. These include secure over-the-air (OTA) software updates, fleet management, audit logging, device software inventory reporting, and zero-trust security. Whatever tools a manufacturer uses to monitor for exploitable vulnerabilities must also integrate with its update workflow, so that a vulnerability can move from detection to a deployed fix without delay.
The CRA also mandates security updates to install automatically by default where applicable, with a clear way for users to opt out or postpone them. That opt-out creates a gap manufacturers need to plan for. Will suggests updating customer service contracts and purchase orders (POs) to reflect mandatory patching schedules. If a customer declines critical security updates, the contract should make clear where responsibility for the product's CE and CRA compliance then lies.
Will and Thomas's conversation highlights several insights manufacturers should keep in mind as the CRA moves toward full application:
With just over a year until the CRA fully applies, the manufacturers best placed to succeed will be those that treat compliance as an ongoing part of the device lifecycle, rather than a one-time certification.
To learn more about how OTA software updates support CRA compliance, read our white paper, The role of OTA updates in CRA compliance.