The Cyber Resilience Act or CRA is an EU regulation that establishes mandatory cybersecurity requirements for products with digital elements made available on the EU market. It introduces obligations related to secure product design, vulnerability handling, security updates, technical documentation, conformity assessment, and reporting of certain actively exploited vulnerabilities and severe incidents. The exact obligations depend on the product and its classification.
From secure design to ongoing vulnerability management, we are working on our CRA readiness.

The European Union's Cyber Resilience Act imposes new, mandatory requirements for the cybersecurity of products with digital elements. For manufacturers or system suppliers, the regulation means that Security by Design and Security by Default must be consistently implemented throughout the entire product lifecycle from development and operation to end-of-life. This includes structured risk assessments, secure development and update processes, end-to-end vulnerability management, and the traceability of all implemented security measures.
As a manufacturer, we are working to ensure CRA compliance with both our existing products and our new developments. Since the CRA took effect at the end of 2024, compliance with the regulation has been integrated into our product design from the very beginning.
Our certifications
The Cyber Resilience Act requires our organization to embed cybersecurity throughout the entire product lifecycle. While certifications do not in themselves constitute compliance with the CRA, they are still laying out the groundwork to meet many of its expectations. With our certifications, we show our established management systems, security practices, and the integration of cybersecurity into our product development processes.
We are certified according to:
Integrating CRA conformity throughout the product lifecycle
To improve product security and maintain regulatory compliance, the CRA requires manufacturers to integrate cybersecurity throughout the lifecycle of products with digital elements. This implies complying with essential cybersecurity requirements, implementing robust vulnerability handling processes, and ensuring timely incident reporting.

Vulnerability Handling
As a manufacturer, our obligation is to offer long-term security support throughout a product’s lifecycle. In part, we achieve this by introducing processes to assess vulnerabilities or provide updates. For our standard solutions, regular security updates must be made available during the defined support period of at least five years, starting upon delivery. For tailor-made B2B solutions, find out more about our cybersecurity services.
Another essential element of our compliance with security requirements is the management of vulnerabilities. According to the CRA we are obliged to timely inform about identified vulnerabilities and recommended actions. This, as well as maintaining information about software components used in the product – up-to-date Software Bill of Materials (SBOM) – is included in our internal compliance processes to support transparency and regulatory compliance.
Incident Reporting
The CRA further requires the reporting of actively exploited vulnerabilities affecting the product and severe incidents impacting its security within 24 hours of becoming aware of the issue. After an early assessment of the incident, additional information should be provided, leading to a final report and the information of the product user.
Product Requirements
By following the CRA regulations, we help ensure that your products are secure, compliant, and ready for the European market. We design our products to minimize cybersecurity risks from the very beginning (security by design). Our approach is risk-based, to reduce data processing, and minimize the attack surface.
As part of our CRA compliance process, we create technical documentation, including a cybersecurity risk assessment, testing results and procedures for vulnerability handling, e.g. Upon delivery of a new product, the accompanying documentation will entail security features already enabled and configured appropriately in the product (security by default). Another part of the documentation includes the requirement to draft an EU Declaration of Conformity (DoC), mandatory for the CE marking for hardware and software with digital elements.
How far along is duagon in terms of CRA readiness?
We take the requirements of the Cyber Resilience Act very seriously and are taking the necessary steps to achieve compliance. We will offer information for you regarding our approach, our services and what documentation upon having completed the analysis and assessment phase.
FAQ - Cyber Resilience Act

The CRA applies broadly to products with digital elements, including hardware and software products that are connected directly or indirectly to a device or network. Examples may include embedded systems, industrial devices, gateways, connected equipment, software applications, and certain remote data-processing solutions.
Whether a specific product is in scope, exempt, or subject to other EU legislation should be assessed based on its intended purpose, functionality, market role, and applicable regulatory framework.
Many embedded and industrial products may fall within the scope of the CRA if they are products with digital elements placed on the EU market. This can include connected industrial computers, gateways, controllers, edge devices, software, and networked equipment.
Manufacturers should assess each product individually, including its connectivity, intended use, software components, update model, and applicable sector-specific legislation.
The CRA requires manufacturers of in-scope products to address cybersecurity throughout the product lifecycle. Key areas include secure-by-design development, risk assessment, protection against known vulnerabilities, secure default configuration, vulnerability handling, security updates, technical documentation, and conformity assessment.
Manufacturers must also meet specific reporting obligations for certain vulnerabilities and incidents. The detailed requirements should be reviewed against the product category and applicable legal guidance.
The CRA entered into force in 2024, with most product requirements scheduled to apply from 11 December 2027. Some obligations, including certain vulnerability and incident reporting requirements, apply earlier.
Because implementation dates and obligations can depend on the requirement concerned, manufacturers should maintain a CRA roadmap and confirm their obligations with qualified legal or compliance specialists.
A product that falls within the scope of the Cyber Resilience Act is CRA-compliant if it meets the applicable cybersecurity requirements.
It typically involves product classification, cybersecurity risk assessment, secure development practices, vulnerability management, technical documentation, conformity assessment, post-market processes, and evidence that security updates and vulnerability handling are managed appropriately.
Manufacturers can prepare by creating a CRA readiness roadmap. Typical first steps include identifying in-scope products, mapping existing security processes, conducting product risk assessments, reviewing software components, establishing vulnerability-handling processes, defining update policies, and preparing technical documentation.
A gap assessment can help prioritize actions across secure development, SBOM, PSIRT, testing, supplier management, documentation, and post-market support.
CRA readiness requires appropriate technical documentation showing how cybersecurity requirements have been addressed. The required documentation depends on the product, conformity-assessment route, and applicable obligations.
Useful evidence may include product descriptions, risk assessments, threat models, security architecture documentation, software-component inventories, test results, vulnerability-management records, update policies, user instructions, and declarations of conformity where applicable.
Cybersecurity services can help manufacturers assess their current maturity, identify product-security gaps, and implement the processes and evidence needed for CRA readiness.
Support may include CRA gap assessments, risk assessment, threat modelling, secure software development, security testing, SBOM implementation, PSIRT setup, vulnerability management, documentation support, and lifecycle-security planning.
Failing to meet the CRA’s requirements can result in various consequences, ranging from fines, restrictions or bans on placing products on the market, recall measures, liability risks towards customers.
As a manufacturer, duagon is establishing the technical and organizational measures needed to meet its cybersecurity requirements throughout the product lifecycle. Our services include analyzing the required safety level, conducting comprehensive risk analyses, preparing the necessary technical documentation, and implementing vulnerability management processes to identify, assess, and address security vulnerabilities. By combining these activities, we strengthen the cybersecurity of our products.
Security-related Application Conditions (SecRACs) are security-related application conditions in cybersecurity. They define prerequisites, assumptions, and usage restrictions that an operator or system integrator must meet to operate a technical system securely. The term originates primarily from the railway sector.
The CE marking indicates that a product meets the applicable EU requirements and has successfully undergone the necessary conformity assessment procedures. With the CRA, this will also include mandatory cybersecurity requirements for products with digital elements in the future.
By affixing the marking, the manufacturer declares that the product complies with all applicable EU legislation and may be placed on the market within the European Union.
End of Support (EOS) refers to the point in time when a manufacturer discontinues support for a product. After this date, security updates, bug fixes, and technical support are generally no longer provided. In the context of the Cyber Resilience Act, the support period is particularly important: Manufacturers must provide security updates and vulnerability fixes for products with digital components for a specified period of time. Once EOS is reached, this obligation ends, provided that the support period requirements set forth in the CRA have been met.
A product with digital elements (PDE) is any hardware or software product that can connect, directly or indirectly, to another device or network. This includes connected devices such as smart home products, industrial IoT equipment, computers, mobile devices, software applications, and embedded software. Under the Cyber Resilience Act, products with digital elements must meet specific cybersecurity requirements throughout their intended support period.
The term security by default refers to a product being delivered with secure settings already enabled. Users do not have to configure essential security features themselves to achieve an appropriate level of protection. Under the CRA, manufacturers are expected to ensure that products are secure in their default configuration when placed on the market.
Cybersecurity is considered throughout the entire product lifecycle, starting as early as the initial stages of design and development. Thereby, security is integrated into the product through measures such as secure architecture, risk assessments, secure coding practices, vulnerability management, and security testing. In regard to the CRA, manufacturers are required to integrate cybersecurity into the design, development, and maintenance of products with digital elements to reduce cybersecurity risks from the outset.
SBOM stands for Software Bill of Materials. It is a structured list of software components, libraries, and dependencies that make up a software product. It ensures transparency in the software supply chain and helps manufacturers, customers, and security teams identify affected components when vulnerabilities are discovered. According to the CRA, manufacturers are required to maintain information about the software components used in their products as part of their cybersecurity and vulnerability management processes.
Find out how to protect your critical infrastructure

Our sales team provides detailed information on our hardware, software expertise, required standards, and cybersecurity best practices. They also collaborate with our engineers to create the best solution for your application.
