EU Cyber Resilience Act (CRA)
The Cyber Resilience Act is the EU regulation that sets mandatory cybersecurity requirements for products with digital elements sold in the European market, from consumer devices to industrial controllers. Manufacturers must build security into their products, handle vulnerabilities throughout the support period and report actively exploited vulnerabilities and serious incidents to the authorities.
How it works
The CRA applies to hardware and software that connects directly or indirectly to a device or network. Manufacturers must perform a risk assessment, meet essential requirements for secure design, default configuration, update mechanisms and data protection, and provide security support for at least five years or the expected product lifetime. Products are classified by criticality; important and critical products face stricter conformity assessment, including third-party evaluation for the highest class.
The regulation entered into force in December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from September 2026, and the full requirements apply from December 2027. Products that fall under existing sector rules, such as certain medical or automotive systems, are excluded, but most rail equipment is covered.
Why it matters for security
For the rail sector, the CRA reaches suppliers rather than operators: interlocking controllers, object controllers, onboard computers and SCADA equipment placed on the EU market will need documented secure development, vulnerability handling and update processes, with the CE marking as evidence. This complements IEC 62443-4-1 and 4-2, which many rail suppliers already apply, and the operator-facing obligations of NIS2.
Operators benefit indirectly: security support periods, coordinated vulnerability disclosure and software bills of materials become legal expectations rather than negotiated extras, which makes vulnerability management of long-lived rail assets more tractable.
Related solution
Supporting compliance with the NIS2 Directive in rail
Visibility, detection and reporting evidence across signaling, rolling stock and fixed installations.
See the solution →

