The CRA is principally a product-security and market-access regulation. The Cybersecurity Act establishes ENISA and an EU framework for cybersecurity certification. The two frameworks are intentionally connected: European cybersecurity certification schemes can support CRA conformity where the CRA conditions are met.
The Two Acts Have Different Primary Functions
The Cyber Resilience Act and the EU Cybersecurity Act both form part of the EU cybersecurity framework, but they are not interchangeable. Regulation (EU) 2024/2847 establishes mandatory cybersecurity requirements for products with digital elements and duties for manufacturers, importers, distributors and other relevant actors. Regulation (EU) 2019/881 has a different structure. It establishes the mandate and tasks of ENISA and creates the European cybersecurity certification framework for ICT products, ICT services, ICT processes and, following later amendment, managed security services. A manufacturer assessing whether a product can be placed on the Union market therefore starts with CRA scope and obligations. Certification under the Cybersecurity Act can become relevant as one method of demonstrating security assurance or supporting CRA conformity.
What the EU Cybersecurity Act Does
The Cybersecurity Act gives ENISA a permanent institutional role within the Union cybersecurity framework and establishes a common mechanism through which European cybersecurity certification schemes can be created. Instead of each Member State developing incompatible certification structures for the same technology, an EU scheme can define security objectives, assurance levels, assessment requirements and certificate conditions that are recognised across the Union. Regulation (EU) 2025/37 later extended the certification framework to managed security services. This certification system is broader than the CRA because it can address ICT products, services, processes and managed security services. At the same time, the Cybersecurity Act does not itself reproduce the CRA manufacturer lifecycle duties, Annex I product requirements, support-period duties or Article 14 reporting regime.
What the Cyber Resilience Act Adds
The CRA establishes a horizontal product-security framework for relevant software and hardware made available on the Union market. It requires manufacturers to assess cybersecurity risks, design and develop covered products in accordance with applicable essential cybersecurity requirements, handle vulnerabilities, provide security updates during the support period, prepare technical documentation and complete the appropriate conformity assessment. Importers and distributors also receive role-specific duties. Article 14 creates mandatory reporting for specified actively exploited vulnerabilities and severe incidents. These requirements operate whether or not a manufacturer chooses to obtain a voluntary European cybersecurity certificate, unless the CRA itself gives a particular certification scheme a defined conformity role. The CRA therefore creates the mandatory product baseline while the Cybersecurity Act supplies certification infrastructure that can interact with that baseline.
CRA Article 27 Creates a Certification Bridge
The CRA expressly creates synergies with certification schemes established under Regulation (EU) 2019/881. Article 27 allows products and manufacturer processes covered by an EU statement of conformity or European cybersecurity certificate under an identified European cybersecurity certification scheme to benefit from a presumption of conformity with CRA essential cybersecurity requirements to the extent that the certificate or statement actually covers those requirements. The scope limitation is important. A certificate that assesses one security property does not establish compliance with unrelated CRA obligations. The Commission can specify which European certification schemes may be used to demonstrate conformity with Annex I requirements or parts of them. Manufacturers therefore need to examine the legal status, assurance level, technical coverage and CRA recognition of the scheme rather than treating any cybersecurity certificate as a universal CRA compliance document.
Certification Can Affect the CRA Conformity Route
European cybersecurity certification can also affect the conformity assessment route available under the CRA. For important products with digital elements, Articles 27 and 32 connect identified certification schemes, harmonised standards and common specifications with the conditions for using particular conformity procedures. Critical products listed in Annex IV can be subject to European cybersecurity certification, and Article 8 empowers the Commission to require certification for specified critical-product categories through delegated acts where the statutory conditions are met. The practical consequence is that product classification comes before certification strategy. A manufacturer should determine whether the product is general, important class I, important class II or critical, identify the applicable assessment route and then determine what role an EU cybersecurity certification scheme can lawfully play in that route.
EUCC Shows How the Frameworks Can Interact
The European Common Criteria-based cybersecurity certification scheme, commonly called EUCC, is an example of a scheme established under the Cybersecurity Act framework. It was adopted through Commission Implementing Regulation (EU) 2024/482. The CRA specifically recognises that products falling within its scope can also fall within certification schemes such as EUCC and allows the Commission to specify how such schemes can provide a presumption of conformity for relevant CRA requirements. This does not mean that every product needs EUCC certification or that an EUCC certificate automatically resolves every CRA issue. The relationship depends on the product, the applicable CRA category, the assurance level, the requirements covered by the certification and any Commission act establishing the precise CRA conformity effect.
A Cybersecurity Certificate Does Not Replace the Manufacturer
Even where certification provides useful conformity evidence, the CRA continues to place responsibilities on the manufacturer. The manufacturer remains responsible for matters such as the cybersecurity risk assessment, technical documentation, vulnerability handling, product support, user information, post-market corrective action and Article 14 reporting where applicable. Certification can demonstrate that specified security requirements were assessed under a recognised scheme, but it does not transfer the manufacturer's legal role to the certification body. Teams should therefore keep certification evidence connected to the wider product file. If product architecture, components, intended purpose or cybersecurity risk change, the manufacturer also needs to determine whether existing certification evidence remains representative of the current product.
Cybersecurity Act 2 Is Still a Legislative Proposal in 2026
The legal comparison also needs a current-status note. The Commission proposed a revised Cybersecurity Act, commonly referred to as Cybersecurity Act 2, in January 2026. The proposal would replace Regulation (EU) 2019/881 and revise ENISA, certification and ICT supply-chain provisions. As of late September 2026, procedure 2026/0011(COD) remains in the ordinary legislative process and has not replaced Regulation (EU) 2019/881. CRA compliance work should therefore distinguish the current Cybersecurity Act from the proposed future framework. This article should be reviewed when the legislative process reaches a final act because amendments to the certification framework could change terminology, procedures or the way future schemes interact operationally with CRA conformity.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.