The new European Cyber Resilience Act (CRA) introduces strict cybersecurity requirements for any product with digital elements. Find out who is targeted and what measures must be taken.
What is the Cyber Resilience Act (CRA)?
The Cyber Resilience Act (CRA) is a European Union legislative initiative aimed at establishing essential cybersecurity requirements for products with digital elements. This includes both hardware devices (such as routers and IoT) and software (applications, operating systems, and even WordPress plugins or indirectly monetized open-source code).
The goal of the CRA is to ensure that digital products sold in the EU are secure from the design stage until the end of their lifecycle.
How does the CRA affect Open Source software and the WordPress ecosystem?
One of the most debated aspects of the CRA has been its impact on the open-source community. Although non-commercial open-source projects are, in principle, exempt, the CRA introduces the concept of open-source stewards.
If open-source software is integrated into a marketed product, or if its maintenance has a commercial character (such as offering paid technical support or PRO versions of a free plugin), it may fall under the CRA. WordPress agencies and developers must ensure that the products they develop and distribute meet the new standards, especially if they sell to clients in the EU.
Main requirements introduced by the CRA
1. Security by Design
Manufacturers must demonstrate that they have integrated security measures from the product conception phase. These include data encryption, strong authentication, and attack surface reduction.
2. Vulnerability Handling
Companies are required to maintain strict processes for discovering and fixing vulnerabilities. Any actively exploited vulnerability or severe incident must be reported to ENISA (European Union Agency for Cybersecurity) within very strict deadlines (sometimes within 24 hours).
3. Free Support and Updates
Manufacturers must provide free security updates for a defined period of time (usually for the expected lifetime of the product or a minimum of 5 years).
4. CE Marking
To be sold in the EU, products with digital elements will need the CE Marking. This certifies that the product complies with CRA requirements, including creating a Software Bill of Materials (SBOM) and a technical security assessment.
When does it come into effect?
The CRA has been adopted and will be implemented gradually. Vulnerability reporting rules will start applying sooner (estimated in 2026), and full compliance, including the CE marking obligation, will become mandatory from 2027.
What should companies do right now?
- Product audit: Identify all digital products you develop, sell, or distribute.
- Reporting processes: Establish internal procedures for the rapid reporting and remediation of vulnerabilities.
- Adopt SBOM (Software Bill of Materials): Start documenting the third-party and open-source software components you use.
- Security by Design: Review your development cycle (SDLC) to include security testing and best practices at every step.