What is the EU Cyber Resilience Act?
The EU Cyber Resilience Act (CRA) is EU legislation setting mandatory cybersecurity requirements for products with digital elements sold in the EU market — covering everything from secure-by-default configuration (including default passwords) to mandatory vulnerability disclosure and security-update obligations.
The CRA works alongside the EU's Radio Equipment Directive (RED), which specifically covers radio equipment (including WiFi routers) and has its own delegated act addressing cybersecurity requirements for connected radio devices — the two overlap significantly on the default-credential question this site's Compliance Index tracks.
Like the UK's PSTI Act, the underlying target is the same well-documented risk pattern: a universal, shared default password that's identical across every unit of a product and exploitable at scale once known. The EU framework pushes manufacturers toward the same safer alternatives — unique per-device credentials, forced setup passwords, or no traditional login at all.
The CRA has a phased rollout with different obligations taking effect at different dates through 2026 and beyond, rather than a single hard cutover — manufacturers get a transition period to bring existing product lines into compliance, with the strictest requirements applying to genuinely new products going forward.
FAQ
- When does the EU Cyber Resilience Act take effect?
- The CRA has a phased implementation timeline with different requirements activating at different dates rather than one single date — check the European Commission's official CRA timeline for the current, authoritative schedule, since specific dates and scope details are the kind of thing that gets refined during implementation.
- Does the Cyber Resilience Act apply outside the EU?
- It governs products placed on the EU market — a manufacturer selling into the EU needs to comply for those products, regardless of where the company itself is based, which is a common pattern in EU product regulation (similar to how GDPR applies based on EU user data, not company location).
- How is this different from the UK's PSTI Act?
- Different jurisdictions, different specific legal text, but a very similar underlying target — both aim to eliminate universal default passwords and improve baseline IoT/connected-device security, just through separate UK and EU legislative processes with their own timelines and enforcement mechanisms.