Jump directly to content

Cyber Resilience Act – how the new regulation affects your business

A woman using a control panel on the wall of her home.

Do you manufacture or sell products that include digital elements? If so, you are affected by the Cyber Resilience Act (CRA) – the EU's new regulation that tightens requirements throughout the entire product life cycle. Ted Strandberg, an expert in cyber security and functional safety, explains what is expected of your business.

How can we help?

Do you need guidance on how the EU Cyber Resilience Act affects your business and how you can adapt to the new requirements? Contact us by filling out the form:

 

CAPTCHA
By submitting the form, RISE will process your personal data.

A baby monitor that can be controlled via an app, an industrial machine that communicates with other equipment on the production line, and speakers that can tell you what the weather will be like next week. There are few electronic products today that do not contain digital elements. This means that the Cyber Resilience Act (CRA) has a very broad scope – it applies to all companies that develop, manufacture, import or sell products containing digital technology or software alone on the EU market. 

The CRA is a regulation aimed at improving the cybersecurity of products containing digital elements – that is, hardware and software that can be connected to a network or another digital device – across the entire European market. 

“This regulation is needed to boost resilience and protect European citizens and systems. We don’t want hackers to be able to take control of products, whether it’s a baby monitor, an industrial machine or a loudspeaker,” says Ted Strandberg, project manager for cyber security and functional safety at RISE. 

CRA will form part of the CE marking

The CRA was adopted in December 2024 and is to be implemented in stages from September 2026. The CRA is expected to be fully rolled out by the end of 2027. Unlike many other regulations and directives that the EU pushes through, the CRA has no direct predecessor. The regulation has been drawn up to complement other cybersecurity frameworks, such as NIS2, which imposes requirements on organisations rather than products. 

The requirements will be incorporated into the CE marking, which in practice means that cybersecurity will go from being a ‘nice-to-have’ to a mandatory requirement if a company wishes to continue selling its connected product on the EU market.

This Regulation is needed to increase resilience and protect European citizens and systems.

Ted Strandberg, cyber security and functional safety at RISE

CRA becomes part of CE marking

The CRA was adopted in December 2024 and will be phased in from September 2026. By the end of 2027, the CRA is expected to be fully rolled out. Unlike many other regulations and directives passed by the EU, CRA has no direct predecessor. The regulation has been developed to complement other cybersecurity regulations, such as NIS2, which places requirements on organisations rather than products.

The requirements will be incorporated into the CE marking, which in practice means that cybersecurity will go from being a "nice to have" to mandatory if you want to continue selling your connected product on the EU market.

Built-in security central to CRA

Security by Design, or built-in security, is a central part of the regulation. It is no longer acceptable to add security after the fact; instead, requirements are now imposed throughout the entire development phase and until the end of the life cycle.

"Most people probably associate the term 'life cycle perspective' with the environment and climate, but here we are talking about the life cycle of software. It extends from the initial idea and risk analysis to requirements specification, design, architecture, development and testing. Once the software has been released on the market, it is a question of maintenance and updates. We talk about End of Support, when the manufacturer stops sending out updates and no longer takes responsibility for security", explains Ted Strandberg.

Standards as tools for regulatory compliance

Ted Strandberg heads the national working group in Sweden that develops standards related to cybersecurity in products. By testing products against established standards, such as IT security in industrial automation systems (EN IEC 62443), it is possible to assess whether a product with digital elements meets basic cybersecurity requirements. Standards can be used as support to demonstrate compliance with CRA. For certain products classified as high risk – such as operating systems or central system components – CRA also introduces a certification requirement.

CRA compliance extra important for subcontractors

Proof of CRA compliance in the form of an accredited report is particularly important for subcontractors who want to maintain and strengthen their competitiveness. A subcontractor who cannot guarantee the safety of their components will be ruled out as an option for customers who market the finished product. Quite simply, there is too much at stake.

"Violating the rules can result in very high fines. Seeking assistance from RISE means sharing that risk. If your product has not been reviewed by a third party, you bear the risk of being penalised. If we make a mistake in the review, we also bear responsibility", explains Ted Strandberg.

CRA training provides a solid knowledge base

Before product testing, certification processes or other technical measures, knowledge building comes first. With the right knowledge, it becomes much easier to tackle CRA.

"One way to build that knowledge is to take a course with us. We offer company-specific courses that provide a solid foundation. For many players, the transition to CRA compliance will take time, so it's important not to wait too long to get started," says Ted Strandberg.

Three tips on how to deal with CRA:

  1. Raise your level of knowledge. We suggest doing this through a course that clarifies the steps you need to take to ensure CRA compliance.
  2. Try it!  Conduct accredited product testing and take advantage of the opportunity to receive advice during the product development phase.
  3. Get started!  There is no time to wait.

This is CRA

The Cyber Resilience Act (CRA) sets common cybersecurity requirements for products with digital elements. The regulation covers both hardware and software sold on the EU market – from connected consumer products to industrial systems and software.

The CRA was adopted in December 2024 and will be implemented in stages starting in September 2026. Full implementation is expected in December 2027.

The aim is to raise the basic level of security, reduce vulnerabilities in connected products and create a more resilient digital single market within the EU.

Ted Strandberg

Projektledare
+46 10 516 60 93 Read more about Ted
Profile image

Contact Ted

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Last published: Cybersecurity

NordicQCI – Nordic Quantum Communication Infrastructure

NordicQCI
NordicQCI

Sweden is launching an exciting new quantum initiative in which quantum communication infrastructure connecting Sweden with Finland and Estonia will be built.

Coordinator
Active
Not applicable
Region Stockholm
2026-2029
10 000 000 euro
Division: Division Digital Systems and Societal Transformation

RISE is the coordinator of the Vinnova‑funded project NordicQCI – Nordic Quantum Communication Infrastructure. The project is a central part of the European EuroQCI initiative and aims to strengthen the EU’s – including its overseas territories’ – ability to protect critical societal communications in a future where quantum technology is rapidly reshaping the security landscape.

NordicQCI will build quantum communication infrastructure that links Sweden with Finland and Estonia. The cross‑border quantum links will be implemented via the existing underwater cables connecting the countries. The project will also enable connection to EuroQCI’s space segment through an optical ground station in Stockholm, providing support for quantum‑secure satellite communications.

The Swedish partners in the project, in addition to RISE, are Ericsson, Stockholm University, KTH, and Linköping University. NordicQCI is funded through the CEF Digital EuroQCI programme, with co‑funding from Vinnova and the Advanced Digitalisation fund.

The project runs until June 2029 and represents an important step towards a robust, resilient, and quantum‑secure communication network throughout the Nordic region and Europe.

Timothy Gibbon

Forskare
+46 10 251 39 52 Read more about Timothy

Contact Timothy

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.

Laia Ginés

Forskare
+46 10 251 38 08 Read more about Laia

Contact Laia

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Project end date: Quantum technologies Sekundär områdes navigation:
Space
Cybersecurity
Quantum technologies

Secure innovation – the key to strong total defense

Secure innovation

In the event of an attack on Sweden, everyone would be expected to contribute to defending the country's peace and freedom to the best of their ability. This defence capability is created by the authorities, municipalities, regions, companies and volunteers. However, according to researchers at RISE, total defence becomes truly strong in the spaces between organisations and activities, where they meet and collaborate.

Against the backdrop of experiences from the two world wars, the idea that the whole of society should be mobilised in the event of war developed in Sweden during the second half of the 20th century. Shelters were built and supplies were stockpiled, while the civilian population was trained to respond to air raids and nuclear threats.

During the 1990s, the threat to Sweden changed, prompting the dismantling of total defence, a move that was subsequently heavily criticised. Since 2014, a reconstruction process has been underway, but, as the County Administrative Boards note in Introduction to Total Defence, it is not possible to simply reinstate the old system.

– The development of a modern total defence system is based on different fundamental conditions to those that applied in the past, simply because society looks different today. For example, we now live in a digital society where much of the innovation and development occurs between organisations and businesses rather than within them, says Carl Heath, senior researcher and focus leader for digital resilience at RISE.

Great need for places for new forms of cooperation

When the concept of total defence was first established, the state and municipalities owned the majority of Sweden's important social activities. Today, however, a significant proportion is privately owned. In other words, if the state is to rebuild a functioning total defence system, it must cooperate with the business community.

– For the public and private sectors to successfully address total defence challenges together, they must be able to do so securely. While we have extensive experience in creating secure conditions for innovation within an organisation, we lack the same experience and expertise in establishing this in the space between, says Carl Heath.

– Innovation often comes at the expense of safety, and vice versa – high safety standards can inhibit innovation, adds Melinda From, Head of RISE's Inclusive Systems Innovation unit.

The development of a modern total defence system is based on different fundamental conditions to those that applied in the past, simply because society looks different today.

A place for meetings and creative working methods.

In 2025, Carl Heath and Melinda From are conducting a preliminary study to map the conditions and obstacles to creating a secure innovation environment in Karlstad municipality. A great deal of knowledge exists about what constitutes a secure environment, drawn from current security legislation and collective experience. Similarly, it is clear what an innovation environment needs to consist of. However, combining the two is tricky, says Carl Heath.

– We want a place where we can meet and work creatively, both physically and digitally.' In modern innovation offices, organisations often share ideas with each other, leading to new insights. If these insights contain sensitive information, protecting it becomes particularly important, he says.

At the location envisaged by Carl Heath, there are people who know how to drive and facilitate innovation safely. This knowledge should not remain confined to one place, but should be shared with organisations so that more safe spaces for innovation can emerge naturally.

RISE acts as a facilitator, helping organisations to establish collaborations.

There are many experts at RISE who specialise in transformation, innovation management and renewal. We have experts who excel at facilitating complex contexts, and RISE already operates a variety of test and demonstration facilities. However, we can't do this alone. We really need the involvement of other stakeholders to create a common platform for secure innovation, says Melinda From.

Sweden's total defence interests lie with NATO.

Carl Heath discusses NATO and the EU's interest in Sweden's comprehensive defence strategy, in which the contribution of everyone from the Armed Forces to businesses, authorities and citizens is vital to the country's resilience. In contrast, many NATO countries have a stronger focus on the military and less on societal mobilisation.

– The expertise in systems that the public and private sectors can develop together through joint projects is important not only in Sweden, but also in the context of the EU and NATO, says Carl Heath.

Preliminary study: A safe innovation environment in Karlstad Municipality

Karlstad is home to the headquarters of several authorities, including the Swedish Civil Contingencies Agency (MSB), the Swedish Psychological Defence Agency, and the Swedish National Service Administration. The Swedish Defence University also has a branch here, and Karlstad Municipality and Region Värmland have identified public safety as a strategic priority.

A preliminary study to map the conditions and obstacles for a secure innovation environment in Karlstad Municipality will begin in December 2024. Linda Larsson (S), Chair of Karlstad Municipality's Municipal Executive Board, had this to say about the initiative:

– Since Karlstad is already a centre of expertise for civil security, it is fitting that this preliminary study is investigating the possibility of setting up a centre for safe training and innovation here. It is important that the centre can be used for both civil and military purposes, enabling the public and private sectors to support each other in accelerating the reconstruction of total defence.

Innovation in total defence

Building a modern and robust total defence requires innovation in a number of areas, both technical and organisational. Here are three examples:

Cyber security and digital defence

Critical infrastructure and communication channels need to be protected from cyber attacks, disinformation and sabotage. This requires cooperation between tech companies and authorities such as FRA and the Swedish Armed Forces.

Innovation: AI-based detection systems can identify attacks in real time. Blockchain technology that can be used for secure data management and communication between critical societal operations.

Materiel supply and logistics

Access to food, medicine and defence equipment needs to be secured. This requires cooperation between the relevant manufacturing industries, the Swedish Civil Contingencies Agency (MSB), the Swedish Food Agency and academia.

Innovation: AI can be used to identify deficiencies and optimise inventory management. In the event of import disruptions, 3D printing could be used to produce spare parts and medical equipment.

Psychological defence and countering disinformation

Society needs to be protected from propaganda and psychological influence operations. Cooperation is required between actors such as AI companies, the media and the Psychological Defence Authority.

Innovation: Tools for detecting deepfakes and disinformation. Platforms for real-time fact-checking.

Profile image

Contact Carl

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.

Melinda From

Transformationsledare
+46 10 516 56 18 Read more about Melinda
Profile image

Contact Melinda

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Total defence and crisis preparedness Sekundär områdes navigation:
Innovation management
Cybersecurity
Digitalisation

Projects in cybersecurity

Submitted by ElinH-admin on

Through research and development projects, RISE drives the development of cyber security forward. From new testing methods in Cyber Range to digital resilience in critical infrastructure – solutions are created here that strengthen both organisations and Sweden's security.

Services in cybersecurity

Submitted by ElinH-admin on

From penetration testing and vulnerability analyses to ISO 27001 certification and NIS2 compliance, RISE offers services that strengthen cyber security throughout your organisation. We combine technical protection with employee awareness to prevent attacks.

Expertise in cybersecurity

Submitted by ElinH-admin on

RISE brings together expertise in penetration testing, digital resilience, certifications and regulatory compliance. Our experts help you navigate NIS2 requirements, build secure management systems and protect critical infrastructure against growing threats.