EU Cyber Resilience Act Makes Security by Design a Legal Obligation by 2027
The EU Cyber Resilience Act (CRA) elevates 'security by design' from an industry buzzword to a binding legal requirement under Annex I, applicable to all products with digital elements from 11 December 2027. Unlike other controls in the regulation, this baseline requirement carries no 'where applicable' exemption, meaning manufacturers cannot opt out regardless of their product's risk class. The European Commission justified the law partly by estimating that data breaches and disruption attacks cost EU businesses at least €75 billion annually. Experts warn that architecture decisions determining compliance must be made years ahead of the deadline, as retrofitting security onto finished hardware is often technically impossible without a full redesign. An earlier obligation under the CRA — vulnerability reporting under Article 14 — takes effect sooner, on 11 September 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in