A regulatory blind spot

Europe has long regulated cybersecurity sector by sector: the MDR for medical devices, DORA for finance, NIS 2 for operators of essential services. Alongside them, ISO 27001 remains a voluntary scheme that certifies an organisation, not a product.

The result was a vast middle ground. An IP camera, an industrial sensor, a vertical ERP, a B2B mobile app, an automation controller’s firmware could all be placed on the European market with no security requirement whatsoever, no commitment to provide updates, and no one clearly on the hook for fixing a flaw discovered three years down the line.

That is precisely the gap the CRA fills.

The incidents that shifted the debate

Four cases triggered the change, and they all tell the same story.

  • Mirai (2016): a botnet built from consumer cameras and video recorders, compromised at scale because they shipped with default passwords nobody ever changed.
  • WannaCry (2017): a known, already-patched vulnerability — but tens of thousands of machines that were never updated, for want of a process or of vendor support.
  • SolarWinds (2020): the poison injected straight into a legitimate update, then distributed to thousands of customers who had done everything right.
  • Log4Shell (2021): a free open-source library, maintained by a handful of volunteers, embedded in millions of applications — most of whose vendors had no idea they were shipping it.

The common thread is blunt: in every case, the vulnerability was not at the victim’s end. It sat inside a product they had bought, integrated or installed in good faith. And legally, no one was required to fix it.

The European Commission drew its conclusion in 2022: since the market does not spontaneously reward security — a secure product costs more to build and doesn’t sell any better — security has to become a condition of market access. The regulation entered into force on 10 December 2024.

The principle: horizontal, not sectoral

The CRA applies to any product with digital elements sold in the Union: software, hardware, firmware, mobile apps, connected objects, right down to components embedded in someone else’s product. Sectors already covered by an equivalent regime (medical devices, aviation, automotive) are carved out, precisely because they were already regulated.

Put plainly: if you sell digital products in Europe and nothing covered you until now, the CRA is your regulation.

Why now

Because the cost of running an attack has collapsed. Cybercrime has industrialised: ransomware rented out as a turnkey service, corporate network access resold on dedicated markets, phishing platforms sold by subscription. ENISA, the EU cybersecurity agency, tracks dozens of ransomware strains active at any one time, phishing as the leading intrusion vector, and published vulnerabilities being exploited within days.

Generative AI is accelerating all of it: flawless, personalised phishing copy, voice cloning, automated target triage. By early 2025, the large majority of observed social engineering campaigns were already AI-assisted.

The consequence for SMEs and mid-caps is direct: “we’re too small to be worth anyone’s time” no longer holds. Targeting costs next to nothing now, so nobody is too small.

What the regulation actually asks for

Five obligations — and they are more operational than legal:

  • Security by design: no default passwords, encryption of sensitive data, minimal attack surface, secure default configuration.
  • A component inventory (SBOM): knowing exactly which software building blocks you ship — the real lesson of Log4Shell.
  • Free security updates for the whole support period, set at a minimum of five years by default.
  • A vulnerability handling process: a named point of contact, a reporting procedure, a remediation timeline.
  • Technical documentation, the EU declaration of conformity and CE marking, now extended to cover cybersecurity.

The two dates that matter

11 September 2026 — the obligation to report any actively exploited vulnerability or severe incident to ENISA: early warning within 24 hours, a report within 72 hours, a final report within 14 days. Note carefully: this deadline also covers products already on the market.

11 December 2027 — full application: design requirements, documentation, CE marking. Products placed on the market before that date are not caught retroactively, unless they undergo a substantial modification.

Failure to meet the essential requirements can lead to fines of up to €15 million or 2.5% of annual worldwide turnover. In July 2026, the Commission published non-binding guidance, rich in worked examples and decision trees, explicitly designed with small organisations in mind.

From compliance burden to commercial argument

The most interesting thing about the CRA is that it codifies what your customers will ask you for anyway within two years. An up-to-date SBOM, a dated support commitment, a vulnerability disclosure channel: these are already scoring criteria in tenders. Companies that start now will turn them into a differentiator; the rest will experience them as an audit.

The most useful starting point isn’t a legal one. It’s a simple question to put to your own team this week: who here detects that one of our vulnerabilities is being actively exploited — and who presses the button within 24 hours?

And if you have neither the time nor the team for this

That is the situation of most SMEs and mid-sized companies we meet: the obligation is understood, but nobody internally has the mandate — or the hours — to carry it.

That’s who we built Probenta for: a SaaS platform that keeps your SBOM current, tracks your vulnerabilities and their remediation, and triggers the 24-hour / 72-hour / 14-day notification workflow; backed by hands-on support to assemble the technical documentation required for CE marking.

In France, market surveillance sits with ANFR and reports are routed through CERT-FR. But the CRA is an EU regulation: what you put in place once holds good across all 27 member states.