Understand the CRA timeline, the SBOM and reporting duties, CE marking, and exactly what OT and connected-product makers must do before the 2027 deadline. A free, practical playbook.
The EU Cyber Resilience Act, Regulation (EU) 2024/2847, is the first law anywhere to make cybersecurity a condition of placing a product on the market. It covers every product with digital elements, hardware and software alike, and that squarely includes the industrial controllers, gateways, sensors, and connected OT components that run modern plants. If your organization makes, integrates, imports, or distributes such products into the EU, the CRA applies to you, and the clock is already running. The reporting obligations took effect on 11 September 2026, and the full requirements apply from 11 December 2027. This playbook turns the regulation into a clear, staged plan so you know what to do, and by when.
The playbook breaks the CRA into the areas your team must act on, each explained in plain language with a practical checklist:
The CRA is often discussed as a consumer and IT software law, but its reach into operational technology is direct. Industrial controllers, remote terminal units, gateways, and the growing population of connected OT devices are all products with digital elements. If you build or integrate them for the EU market, you carry CRA obligations, and the secure-by-design and vulnerability handling duties align closely with the practices in IEC 62443. Our OT cybersecurity services help manufacturers and integrators meet both.