Trust & Compliance / Cyber Resilience Act
Cyber Resilience Act
Build data protection into every product.
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for hardware and software sold in the EU, and its vulnerability and incident reporting obligations already apply. XQ helps manufacturers meet the Annex I requirements for data: developers add encryption, access control and activity logging to their products through XQ’s APIs and SDKs, and customer data stays protected across the product’s support period.
Built for Manufacturers of connected devices and software sold in the EU · Product security and PSIRT teams · Importers and distributors of products with digital elements
At a glance
RegulationRegulation (EU) 2024/2847
ReportingApplies since 11 September 2026: 24-hour early warning, 72-hour notification
Full application11 December 2027
PenaltiesUp to €15M or 2.5% of worldwide turnover
Works with REST API · SDKs · IoT and edge devices · AWS · Azure · On-premises
Secure by design
Add object-level encryption and policy-based access to products during development, not after release.
Evidence for reporting
Access and activity logs help scope an actively exploited vulnerability or severe incident quickly.
Protect data for the product’s life
Keys can expire or be revoked, so data on retired or compromised devices can be made unreadable.
What the CRA requires
The CRA applies to “products with digital elements” — hardware and software whose intended use includes a data connection to a device or network. Manufacturers carry most obligations; importers and distributors must check that products they place on the EU market comply.
- Essential cybersecurity requirements (Annex I) for how products are designed, developed and produced — including secure-by-default configuration, protection from unauthorized access, and confidentiality and integrity of data.
- Vulnerability handling throughout a support period of at least five years, unless the product is expected to be in use for less time.
- Reporting of actively exploited vulnerabilities and severe incidents through ENISA’s single reporting platform: an early warning within 24 hours, a notification within 72 hours and a final report afterwards.
- Conformity assessment and CE marking, with third-party assessment for important and critical product categories.
- Penalties of up to €15 million or 2.5% of worldwide annual turnover for breaching the essential requirements.
How XQ maps to Annex I
| Annex I, Part I requirement | How XQ helps |
|---|---|
| 2(d) — Protection from unauthorized access | Only authenticated users and devices that satisfy policy can obtain decryption keys, through your identity and access management system. |
| 2(e) — Confidentiality of stored, transmitted or processed data | Data is encrypted at rest and in transit, with unique keys per object managed separately from the product. |
| 2(f) — Integrity of data | End-to-end encryption makes unauthorized manipulation or modification of protected data detectable. |
| 2(g) — Data minimisation | Field-level encryption and time-limited access keep sensitive data readable only by those who need it, for as long as they need it. |
| 2(l) — Recording and monitoring internal activity | Access to and modification of protected data is logged with user, data and time, and can feed your monitoring tools. |
| 2(m) — Secure removal of data | Revoking or expiring keys renders data permanently unreadable, even on devices or storage you no longer control. |
Designing CRA controls into a product roadmap?
Reporting deadlines are already here
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. Real-time visibility into who accessed which data, and when, helps product security teams judge an incident’s scope within the 24- and 72-hour windows.
What stays with the manufacturer
XQ provides data-protection capabilities; it does not perform conformity assessments, issue CE marking or run your vulnerability-handling process. Those remain the manufacturer’s responsibility, and XQ’s controls and logs support the technical documentation you prepare for them.
Related resources and articles
FAQ
The Cyber Resilience Act, answered directly.
What is the EU Cyber Resilience Act?
The Cyber Resilience Act, Regulation (EU) 2024/2847, sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU. It entered into force on 10 December 2024 and applies in full from 11 December 2027.
Who has to comply with the CRA?
Manufacturers of hardware and software products with digital elements placed on the EU market carry most of the obligations. Importers and distributors must check that the products they place on the market comply.
When do the CRA reporting obligations apply?
From 11 September 2026. Manufacturers must report actively exploited vulnerabilities and severe incidents with an early warning within 24 hours and a notification within 72 hours, followed by a final report.
How does XQ help manufacturers meet Annex I?
Through XQ’s APIs and SDKs, developers add encryption, policy-based access control, integrity protection, activity logging and key revocation to their products — supporting the Annex I requirements on unauthorized access, confidentiality, integrity, monitoring and secure data removal.
Does XQ provide CE marking or conformity assessment?
No. Conformity assessment and CE marking remain the manufacturer’s responsibility. XQ’s controls and logs support the technical documentation that process relies on.
How does the CRA relate to NIS2?
NIS2 regulates how essential and important entities secure their operations; the CRA regulates the security of the products they buy. Many organizations face both, and XQ’s data-layer controls support each.
Ship products that protect their data.
Talk to our team about building CRA-ready encryption, access control and logging into your products.