• Pantar Road, Lija, LJA2021
  • info@stl.com.mt
  • (+356) 22 584 300
  • BOOK A CALL
Logo
  • Home
  • About Us
  • Services
    • Professional Services
      • Network Services
      • Infrastructure Services
      • Digital Solutions
    • Managed Services
      • Managed DBA
      • Managed BI
      • Microsoft 365 Managed
      • Managed Network And Guest WIFI
      • Managed Virtual Desktop
      • Managed Desktop Solution
      • Managed Backup Solutions
      • Managed IP Telephony
    • Cyber Security
      • Next – Generation Firewall (NGFW)
      • END-POINT Protection
      • Network Access Control (NAC) Solutions
      • Security Awareness Training
      • Microsoft Secure Solutions
      • AI-Powered Cybersecurity Solutions (Powered by Darktrace)
      • Data Loss Prevention (DLP)
    • ERP Solutions
      • Oracle Netsuite Services
    • Hospitality
      • Oracle MICROS Simphony POS
      • Oracle OPERA Cloud PMS Malta
      • Oracle Hospitality Materials Control
      • Otrum Property TV Solution And Digital signage
      • IP Telephony
      • WISDOM DATA WAREHOUSE & BI
      • Smart Order
    • Cloud Services
      • Virtual Private Server (VPS) Hosting
      • Dedicated Servers
      • Cloud Backup Solutions
    • Software Services
      • Custom Software Development
      • Outsourced Devops
  • Partners
  • Blog
  • Careers
  • Contact Us
  • Helpdesk
    • Managed Services Help Desk
    • Hospitality Solutions Help Desk
    • Software Services Help Desk
    • Download Remote Support Tool

The EU’s Cyber Resilience Act – Are You Prepared for What’s Coming?

  • Home
  • Blog Details
  • September 1 2025
  • Smart Technologies Ltd
What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is an EU regulation (2024/2847) that came into force on 10 December 2024 and becomes fully applicable from 11 December 2027. It sets baseline cybersecurity standards for all hardware and software products with digital components sold in the EU – this includes everything from IoT devices and firmware to cloud‑connected software.

 

Why it matters

Many connected products today are vulnerable, poor update processes and weak default configurations have led to significant breaches. The CRA addresses this by requiring secure‑by‑design principles and lifecycle security management. It also ensures that consumers and businesses can choose products confidently, backed by a CE‑mark indicating compliance.

 

Who will this affect

The CRA applies to manufacturers, importers and distributors of “products with digital elements” (PDEs), including devices with firmware, remote data processing tools, and connected software. Exclusions include medical devices, motor vehicles and aviation, which already fall under other regulations.

 

Core obligations
  1. Secure by design and default: Products must have minimal vulnerabilities, protected default settings, and ability to be restored

  2. Vulnerability handling: manufacturers must identify and document issues (e.g. via SBOMs), respond to threats promptly, and provide security updates at no extra cost.

  3. Incident reporting: serious incidents or exploited vulnerabilities must be reported to ENISA within 24–72 hours, with deadlines differing by type: reporting begins 11 September 2026; cybersecurity requirements are enforced from 11 December 2027.

  4. Conformity assessments: basic-risk products Class I can use self‑assessment; higher-risk (Class II and critical PDEs) need third‑party audits before CE‑

 

Penalties for non‑compliance

Failure to comply may lead to fines up to €15 million or 2.5 percent of global turnover, plus market withdrawal of non‑compliant products and potential reputational damage.

 

Our Top Tips – Are You Ready?
  1. Map your product portfolio now: Identify which hardware and software components fall under the regulation.

  2. Review development processes: Incorporate threat modelling, SBOMs, and automated security testing into your design and build workflows.

  3. Set up incident management: Create a team and workflows to detect, patch, and report security incidents within the required timeframes.

  4. Plan for conformity: Determine which products need self‑assessment and which require third‑party review. Start gathering technical documentation ahead of time.

  5. Update supply‑chain procedures: Ensure contracts and vendor agreements include obligations to support CRA compliance throughout the lifecycle of the product.

 

Working with an experienced partner can streamline this transformation. If you want to ensure your products meet the Cyber Resilience Act requirement and remain market-ready across Europe, book a call with us: https://stl.com.mt/book-a-call/

Previous Post
Case Study: Seamless Connectivity and Security for a Modern Learning Environment
Next Post
Smart Technologies is Now Malta’s Only 3CX Platinum Partner: What That Means for Your Business

Leave a Comment Cancel reply

Recent Posts

  • Smart Technologies is Now Malta’s Only 3CX Platinum Partner: What That Means for Your Business
  • The EU’s Cyber Resilience Act – Are You Prepared for What’s Coming?
  • Case Study: Seamless Connectivity and Security for a Modern Learning Environment
  • Smart Technologies, Merqury Cybersecurity and Fortinet Collaborate on Quantum-Secured VPN for PRISM
  • The Future of Network Management with RUCKUS AI

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • January 2024
  • October 2023
  • September 2023
  • August 2023
  • May 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • July 2022
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • April 2020
  • February 2020
  • April 2019
  • February 2019
  • January 2019
  • November 2018
  • September 2018
  • July 2018
  • May 2018
  • March 2018
  • February 2018
  • December 2017
  • September 2017
Shape
Logo

Smart Technologies has been in business since 2008, establishing partnerships and serving loyal clients, from huge companies to startups.

Useful Links

  • Home
  • About Us

Our Services

  • Professional
  • Software
  • ERP
  • Managed
  • Hospitality
  • Cloud

Contact Info

  • Smart Technologies Ltd. Navi Buildings Level 1, Pantar Road, Lija, LJA2021
  • info@stl.com.mt
  • (+356) 22 584 300

    ISO 9001

© Copyright 2023. All Rights Reserved Smart Technologies Ltd.

another website by TheWebAlly Logo

  • Home
  • About