The Digital Security Authority of Cyprus – NCCA in collaboration with Working Group 4: EU and National Legislations of NCC-CY, has prepared a new practical guide on the Cyber Resilience Act (CRA).
The Cyber Resilience Act introduces a new European framework for strengthening the cybersecurity of products with digital elements placed on the EU market. It applies to a broad range of hardware and software products and establishes obligations for key actors across the supply chain, including manufacturers, authorised representatives, importers and distributors.
The guide has been developed to support organisations, businesses and other stakeholders in Cyprus in understanding the main requirements of the CRA and preparing for its implementation. It provides an accessible overview of the Regulation, including who it applies to, the main obligations of economic operators, cybersecurity requirements, vulnerability handling and reporting, and conformity assessment requirements.
The publication is intended primarily as an awareness and preparedness tool designed to help stakeholders understand what the CRA is and why it matters, identify whether a product falls within scope, understand the stakeholders affected and their respective roles under the Regulation, recognise key milestones and obligations, understand the role of the relevant Cyprus authority, and help affected stakeholders plan their next actions related to CRA compliance. It does not constitute legal advice, is not a substitute for the Cyber Resilience Act, and should not be interpreted as a binding interpretation of the Regulation.
