Contact person
Ted Strandberg
Projektledare
Contact Ted
The Cyber Resilience Act (CRA) affects far more companies than many realize. The first requirements have now entered into force, and organizations that are not prepared may struggle to meet customer expectations and remain in the supply chain. This webinar is tailored for SMEs and provides guidance on what to do next.
Many associate the Cyber Resilience Act with large technology companies. In reality, the regulation applies to all products with digital elements, including software, connected products, industrial systems, and machinery.
This means that many small and medium-sized enterprises (SMEs) may also be affected, including product developers, manufacturers, system providers, and suppliers.
The first obligations under the CRA come into force on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe cybersecurity incidents to the European Union Agency for Cybersecurity (ENISA).
When the full regulation takes effect in December 2027, additional requirements will apply, including secure development practices, vulnerability management, technical documentation, and CE marking.
For many companies, this is about more than regulatory compliance. Customers and contracting organizations are already placing higher demands on cybersecurity. Businesses that cannot demonstrate a systematic approach to cybersecurity risk being excluded from future opportunities.
Ted Strandberg, Cybersecurity Expert at RISE, chairs Sweden's national standardization working group for product cybersecurity and participates in European standardization efforts related to the Cyber Resilience Act.
He will share the latest insights on the regulation along with practical guidance on how companies can translate the requirements into concrete actions.