Skip to content
← Services

CRA

Regulation (EU) 2024/2847 — Cyber Resilience Act

Product SafetyEuropean UnionIn force: December 10, 2024

What it is

The Cyber Resilience Act introduces horizontal cybersecurity requirements for products with digital elements placed on the EU market — covering hardware, software, embedded components, and the entire lifecycle from design through end-of-support.

What it requires

All products with digital elements placed on the EU market except SaaS, certain medical devices, and aviation/automotive products covered by sectoral law. Manufacturers must perform conformity assessments, maintain vulnerability handling processes for the product's expected lifetime or five years (whichever is shorter), provide free security updates, and report actively exploited vulnerabilities and severe incidents to ENISA within 24/72 hours.

Key facts

Supervisor
Member-state market surveillance authorities, coordinated through the European Cybersecurity Resilience Group
Maximum fine
Up to EUR 15 million or 2.5% of global annual turnover for non-compliance with essential cybersecurity requirements
Key deadline
2027-12-11 (general application date for most obligations)

DSI services for CRA

DSI Advisory Services helps covered entities translate CRA obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.

See the service →

Related briefings

The Ship and the Iceberg
Chokepoint DoctrineJuly 12, 2026
The Ship and the Iceberg

Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.

Free tier13 min read
Every Company Is China-Free. The Refinery Says Otherwise.
Chokepoint DoctrineJuly 10, 2026
Every Company Is China-Free. The Refinery Says Otherwise.

Bloom Energy's CEO said it for years: no China supply chain. A short-seller says otherwise — but Bloom is a symptom, not the story. Concealing Chinese origin is now an industrial practice ($549M in aluminium as 'pallets'; tungsten laundered through Taiwan; Chinese magnets in the F-16, the F-18 and the F-35 three times over), because 'China-free' is worth a fortune and origin is structurally unverifiable. The deeper move: China controls these inputs by export licence, not ban — and every licence forces disclosure of the end user. Beijing holds a more accurate map of American critical dependencies than America's own regulators do. My assessment of the real risk, and where it goes in a Taiwan crisis.

Free tier9 min read
The Camera That Cannot Be Turned Off
Chokepoint DoctrineJuly 8, 2026
The Camera That Cannot Be Turned Off

Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.

Free tier10 min read
Every Box Is Governed. The Space Between Is No One's Job.
Chokepoint DoctrineJuly 4, 2026
Every Box Is Governed. The Space Between Is No One's Job.

Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.

Free tier9 min read
Your Smart TV Is Someone Else's Criminal Infrastructure
Chokepoint DoctrineJuly 3, 2026
Your Smart TV Is Someone Else's Criminal Infrastructure

On 2 July 2026, the FBI and IRS Criminal Investigation seized NetNut, a residential proxy service run by the NASDAQ-listed Israeli company Alarum Technologies, after Google and partners degraded the Popa botnet — roughly two million consumer devices, including the Android TV box and smart television under millions of ordinary homes, enrolled with little or no consent. A residential proxy routes criminal traffic through real home connections, so when a target checks the source it sees your ISP and your city, not a data centre. In one week of June 2026, Google's Threat Intelligence Group counted 316 distinct threat clusters — criminal and nation-state — using NetNut exit nodes; a comparable network, IPIDEA, carried APT28, Sandworm, and Volt Typhoon. My assessment: the FBI's advice to avoid cheap streaming boxes is correct and insufficient, and this is not a botnet you kill but a market you would have to close, resilient because the same infrastructure serves legitimate ad-verification and nation-state espionage alike. The connected device is the permanent weak point: the risk rides an access path you never chose to open. What to do today: segment your smart devices onto a separate network, and ask what the box under your television does when the television is off.

Free tier8 min read
The Crypto-Agility Audit
Practitioner OperationsJune 12, 2026
The Crypto-Agility Audit

NIS2 Article 21 requires “state-of-the-art” cryptography. DORA Article 6 requires emerging-risk monitoring of quantum. CRA Article 11 names crypto-agility as a design property. CNSA 2.0 sets a January 2027 contractor floor. Each framework audits a procedural shell. The substantive obligation lives in the union — and the audit that maps across the four is the one that almost no organisation has yet run. Crypto-agility is a property of architecture, not a control. The state-of-the-art has moved. The audit has not yet caught up. The supervisory practice is on a calendar that will close the gap whether the organisation prepares or not. The practitioner playbook for the PQC migration the regulators are actually asking for, mapped to the regulators actually doing the asking.

Free tier12 min read