Compliance

EU Cyber Resilience Act

Introduction

The EU Cyber Resilience Act (CRA) sets cybersecurity requirements for hardware and software products with digital elements on the European market. They include secure-by-default configuration and continuous vulnerability handling.

Why it's needed

The CRA entered into force in December 2024. Its vulnerability-reporting duties apply from September 2026 and most other obligations from December 2027. After that, products that cannot show compliance cannot carry the CE mark, so they cannot be sold in the European Union.

How TrustDyne works

TrustDyne maps findings such as hardcoded cryptographic keys, insecure network protocols and unprotected storage to CRA Annex I requirements, and shows a pass or fail result for each requirement in the report. It supports your conformity work. It is not a certification.