What the EU CRA actually is
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the first EU-wide cybersecurity law for products with digital elements: hardware and software placed on the EU market. Its scope is broad; nearly every connected or software-bearing product, from industrial controllers to consumer IoT, falls under it.
What sets it apart from a guideline is the consequence. Without a CE mark, an EU Declaration of Conformity and an Annex VII technical file, an in-scope product cannot be lawfully sold on the EU market. There is no "do nothing" option — demand for compliance is created by law, not by persuasion.
For most teams, this is new ground: the text runs to more than 60 pages, the obligations are unfamiliar, and the deadlines are fixed.
Source: Regulation (EU) 2024/2847; European Commission CRA pages.