Discover the service
CRA (Regulation UE 2024/2847 - Cyber Resilience Act)
The Cyber Resilience Act is the European Regulation introducing mandatory cybersecurity requirements for products with digital elements placed on the EU market, including connected hardware and software, IoT devices, applications and digital components. For the first time, cybersecurity has become a mandatory requirement for the commercialization of digital products within the European Union.
The CRA shifts the focus from organizational security to the security of the entire product lifecycle, from design and development through to end-of-support. The Regulation applies to manufacturers, importers and distributors, each with specific responsibilities. Failure to comply may result in financial penalties, restrictions on market access or product withdrawal from the market.
The CRA classifies products according to their level of criticality:
- Default products: the majority of products with digital elements, subject to self-assessment procedures.
- Important products: higher-risk categories (e.g. password managers, detection systems, VPNs, microcontrollers) subject to enhanced requirements.
- Critical products: categories subject to the strictest conformity assessment obligations.
Argo Cyber conducts preliminary assessments to identify the relevant product risk category and determine the applicable regulatory obligations, supporting organizations in implementing the requirements set out by the Regulation.





















