{"id":8051,"date":"2026-09-22T12:59:35","date_gmt":"2026-09-22T09:59:35","guid":{"rendered":"https:\/\/lieke.com\/?p=8051"},"modified":"2026-09-22T14:14:17","modified_gmt":"2026-09-22T11:14:17","slug":"the-cyber-resilience-act-cra","status":"publish","type":"post","link":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/","title":{"rendered":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA)"},"content":{"rendered":"<h3>The EU has taken a very active role in developing cybersecurity regulation, particularly following the introduction of the EU\u2019s new cybersecurity strategy in 2020. Numerous instruments to promote cyber security have been adopted in recent years, and many of them have already come into force, at least in part. To ensure cyber security, the EU has introduced a range of tools, from the establishment of new authorities to funding and research in the cyber security sector, as well as the creation of certification schemes. These new cyber security regulations impose significant obligations on operators in both the private and public sectors.<\/h3>\n<h3>This three-part series of publications provides a concise overview of the most essential cybersecurity regulatory frameworks. The aim of the series is to help assess what kind of cybersecurity obligations one\u2019s own company or organisation may need to take into account.<\/h3>\n<h2>Entry into force and scope of the Cyber Resilience Act<\/h2>\n<p>The EU Cyber Resilience Act (EU) 2024\/2847 (&#8220;<strong>Cyber Resilience Act<\/strong>\u201d \/ \u201c<strong>CRA<\/strong>\u201d) was adopted in 2024, and, as a regulation, it is directly applicable in all EU Member States in stages, with the final provisions coming into force in the summer of 2028. In Finland, the CRA has been supplemented primarily by the national Cyber Resilience Act (439\/2026), which came into force in June 2026. As part of the legislative reform, the national Cyber Security Act (124\/2025) and the national Act on Electronic Communications Services (917\/2014), amongst others, were also updated to reflect the cyber resilience era. The national legislation supplementing the CRA primarily designates the competent authorities and organises the official duties laid down in the CRA at national level. In Finland, the duties of the competent authority are assigned to Traficom and the National Cyber Security Centre under its remit.<\/p>\n<p>The scope of the CRA is very broad. It covers all equipment and software \u2013 including their separate components \u2013 that contain digital elements \u2013 in other words, operate in a digital environment \u2013 and can be connected, directly or indirectly, to a network or to a piece of equipment. In the CRA, <em>connections<\/em> are defined as <em>logical connections<\/em> (software interfaces) and <em>physical connections<\/em> (electrical, optical and mechanical interfaces, cables, wires and radio waves). An <em>indirect connection<\/em> refers to a situation where a product or component does not have a direct connection, as described above, to a device or network, but is part of a wider system that can be connected to a device or network via such a connection.<\/p>\n<p>However, the following are excluded from the scope of the CRA: marine equipment subject to specific product safety regulations, aviation equipment, motor vehicles, their trailers and components, technical units for road transport, medical devices, and products relevant to national security. The CRA imposes obligations on operators of all sizes, ranging from product manufacturers and authorised representatives to importers and distributors. The Cyber Resilience Act also contains limited obligations applicable to open-source software stewards. However, in line with the EU\u2019s regulatory trend, the obligations applicable to micro-enterprises and SMEs have been partially relaxed.<\/p>\n<p><em>*On 27 July 2026, the Commission published detailed implementing guidelines which provide further clarification, in particular, on the interpretation of the concepts defined in the CRA (2026, 5252 final).<\/em><\/p>\n<h2>Key elements of the Cyber Resilience Act<\/h2>\n<p>The Cyber Resilience Act is a horizontal product safety regulation, meaning that its application is not limited to specific sectors. The regulation forms part of the EU\u2019s CE marking framework. The CE marking certifies that a product complies with the applicable product requirements, including the cybersecurity requirements set out in the CRA. Consequently, compliance with the requirements of the Cyber Resilience Act will, in future, be a prerequisite for products falling within its scope to be placed on the EU market.<\/p>\n<p>The cybersecurity requirements for products set out in the CRA will apply to products placed on the EU market on or after 11 December 2027. Furthermore, the cybersecurity requirements for products will also apply to products that are subject to a\u00a0substantial modification on or after 11 December 2027. However, where a product is covered by any other type-examination certificate or approval decision relating to cybersecurity based on EU legislation, such certificates and decisions may remain valid until 11 June 2028 at the latest.<\/p>\n<p>Manufacturers\u2019 reporting obligations regarding vulnerabilities and incidents apply to all products falling within the scope of the CRA, regardless of when the product was first placed on the EU market. These reporting obligations came into force on 11 September 2026.<\/p>\n<h3>Cybersecurity risk assessment<\/h3>\n<p>The first step towards complying with the CRA\u2019s product requirements is a cybersecurity risk assessment, which the manufacturer is responsible for carrying out. The aim of the risk assessment is to ensure that the product has been designed, developed and manufactured in accordance with the cybersecurity requirements set out in the CRA. The CRA is based on a risk-based approach. The higher the risk associated with a product, the greater the requirements for its cybersecurity. Based on the risk assessment, the manufacturer must draw up a plan setting out the necessary risk management measures.<\/p>\n<p>The assessment of cybersecurity risks can be divided into three distinct areas: (i) risk analysis based on intended use and operating conditions, (ii) compliance with cybersecurity requirements, and (iii) compliance with requirements concerning the handling of vulnerabilities. The risk assessment must be documented and included in the product\u2019s technical documentation. Furthermore, it must be kept up to date throughout the product\u2019s support period (i.e. the time the products are expected to be in use).<\/p>\n<h3>Conformity assessment<\/h3>\n<p>The manufacturer \u2013 or an authorised representative acting on the manufacturer\u2019s behalf \u2013 must carry out a conformity assessment for products falling within the scope of the Cyber Resilience Act. Class I and II important products and critical products as defined in the Cyber Resilience Act are subject to more stringent third-party assessment procedures \u2013 that is, those carried out by an assessment body or a notified body \u2013 whilst the conformity assessment of other products \u2013 including open-source essential products \u2013 may be carried out independently. Following the conformity assessment, the manufacturer \u2013 or an authorised representative acting on the manufacturer\u2019s behalf \u2013 draws up an EU Declaration of Conformity for the product and affixes the CE marking to it.<\/p>\n<h3>Placing the product on the market and post-market obligations<\/h3>\n<p><em>Manufacturer<\/em><\/p>\n<p>Before placing the product on the market, the manufacturer must also ensure that technical documentation meeting the CRA\u2019s requirements, as well as instructions and other information to be provided to users, has been drawn up for the product. Once the product has been placed on the market, the manufacturer is responsible for the effective handling of vulnerabilities throughout the support period. The manufacturer must also keep the technical documentation and security updates available for the duration of the support period, but for at least 10 years. The manufacturer also has extensive obligations to cooperate with the authorities, as well as an obligation to report vulnerabilities to component manufacturers within the supply chain and to open-source software stewards.<\/p>\n<p><em>Authorised Representative<\/em><\/p>\n<p>The authorised representative is obliged to carry out the tasks assigned to them by the manufacturer. The authorised representative may be assigned, in particular, the conformity assessment procedure (responsibility remains with the manufacturer), the inclusion of the necessary information with the product, the retention of technical documentation, and cooperation with the competent authority. The authorised representative must always keep the EU Declaration of Conformity and the technical documentation available to the market surveillance authority for the duration of the support period \u2013 but for at least 10 years \u2013 and must cooperate with the authority where necessary.<\/p>\n<p><em>Importer and distributor<\/em><\/p>\n<p>The importer must ensure that the conformity assessment procedure has been carried out, that the technical documentation for the product has been drawn up, that the product bears the CE marking, and that it is accompanied by the EU Declaration of Conformity as well as the information and instructions to be provided to the user. Once this has been verified, the importer must provide their own contact details in connection with the product. The importer has extensive obligations to cooperate with the competent authority, as well as an obligation to keep the EU Declaration of Conformity and technical documentation available to the competent authority for the duration of the product\u2019s support period, but for at least 10 years. The importer is also obliged to report vulnerabilities and significant cybersecurity risks to the manufacturer, including significant cybersecurity risks and the cessation of the manufacturer\u2019s operations, to the market surveillance authority.<\/p>\n<p>The distributor\u2019s obligations largely correspond to those of the importer. However, unlike the importer, the distributor is not required to ensure that technical documentation has been drawn up for the product \u2013 including other details concerning the conformity assessment procedure. Nor is the distributor responsible for ensuring that the technical documentation is made available to the authorities. In this regard, however, the distributor must ensure that the importer\u2019s details are marked on the product.<\/p>\n<h3>Reporting and notification obligations<\/h3>\n<p>The Cyber Resilience Act requires manufacturers to report serious incidents affecting the information security of products and actively exploited vulnerabilities to the competent authorities; in Finland, this is the CSIRT unit operating under Traficom\u2019s National Cyber Security Centre (Computer Security Incident Response Team). As a general rule, reporting follows a three-stage process. First, an early warning notification must be issued without delay and no later than 24 hours after the incident or vulnerability is detected. Within 72 hours, the manufacturer must provide a more detailed incident notification on the vulnerability or incident. The manufacturer must issue a final report on vulnerabilities within 14 days of a corrective or mitigating measure becoming available, and on incidents within one month of the incident report. The CSIRT may also, where necessary, request an interim report on a vulnerability or incident.<\/p>\n<p>In certain cases, the CSIRT may disclose information about an incident or require the manufacturer to do so. With regard to vulnerabilities, the disclosure of information is the general rule, from which exceptions may be made only in limited cases.<\/p>\n<p>In line with EU cybersecurity regulatory trends, the CRA has also adopted a voluntary reporting practice. Anyone can report product-related vulnerabilities, cyber threats, incidents and near-misses to the CSIRT unit. Where necessary, the CSIRT unit will notify the product manufacturer of the matter.<\/p>\n<h2>Transfer of liability and monitoring of supply chains<\/h2>\n<p>In accordance with established practice in product regulation, the manufacturer\u2019s obligations are transferred to the importer or distributor to the extent that the latter places the product on the market under their own name or trademark, or makes a substantial modification to a product already placed on the market.\u00a0 In limited cases, the manufacturer\u2019s obligations may also be transferred to a party other than the importer or distributor, provided that such party makes a substantial modification to the product and makes it available on the market. However, the manufacturer\u2019s liability may be transferred to a party other than a distributor or importer only in respect of the effects of such modifications.<\/p>\n<p>All economic operators under the CRA \u2013 that is, the manufacturer, authorised representative, importer and distributor \u2013 must keep records of the product\u2019s supply chain. Upon request, economic operators must provide the market surveillance authority with the name and address of every economic operator to whom they have supplied, or from whom they have received, a product containing digital elements during the last 10 years.<\/p>\n<h2>Penalties for infringements<\/h2>\n<p>The Cyber Resilience Act provides for three administrative fines of varying amounts:<\/p>\n<ul>\n<li>A manufacturer may be liable to pay an administrative fine of up to EUR 15 million or 2.5% of the company\u2019s total worldwide annual turnover for the preceding financial year, financial year, whichever is higher.<\/li>\n<li>An authorised representative, importer, distributor or conformity assessment body may be subject to an administrative fine of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher.<\/li>\n<li>The supply of incorrect, incomplete or misleading information to a notified bodies or market surveillance authorities, the administrative fine shall not exceed EUR 5 million or 1% of total worldwide annual turnover, whichever is higher.<\/li>\n<\/ul>\n<p>With regard to administrative fines, the standard public sector exemption applicable in Finland applies, under which no administrative fine may be imposed on a public sector entity. Furthermore, no administrative fine may be imposed on open-source software stewards as defined by the CRA. In such cases, however, it is possible to impose a penalty payment.<\/p>\n<p>With the new national Cyber Resilience Act, Finland has also implemented an administrative penalty relating to cybersecurity certification in accordance with the EU Cybersecurity Regulation (EU) 2019\/881. On this basis, a manufacturer whose product has been certified under a European cybersecurity certification scheme or who has issued an EU declaration of conformity may be subject to an administrative fine of up to EUR 100,000 for certain negligence, providing incorrect information and using a certificate that is not valid.<\/p>\n<p>As part of product safety regulation, the Act on the Market Surveillance of Certain Products (1137\/2016) will also be applied to products that contravene the Cyber Resilience Act. Under the Act, the market surveillance authority may order an economic operator in the supply chain of a product that does not comply with the requirements of the Cyber Resilience Act to take corrective measures. The market surveillance authority may also, under the conditions laid down in the Act, among other things, prohibit the manufacturing, placing on the market and exporting of a product, and order the economic operator to recall the product from the market and destroy it. To ensure compliance with a prohibition or order, the market surveillance authority may impose a penalty payment or a performance order, in which case the necessary measures shall be carried out at the expense of the operator who has failed to act.<\/p>\n<h3><\/h3>\n<h3>Read also:<\/h3>\n<p><a href=\"https:\/\/lieke.com\/en\/cer-act-in-finland-new-resilience-obligations-for-critical-entities\/\">A Brief Guide to Cybersecurity Regulation \u2013 Part 2: CER Act in Finland: New Resilience Obligations for Critical Entities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The EU has taken a very active role in developing cybersecurity regulation, particularly following the introduction of the EU\u2019s new cybersecurity strategy in 2020. Numerous instruments to promote cyber security have been adopted in recent years, and many of them have already come into force, at least in part. To ensure cyber security, the EU [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":8072,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[45],"tags":[783,784,782,780,781,785,779],"class_list":["post-8051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insight","tag-cra-placing-the-product-on-the-market-and-post-market-obligations","tag-cra-transfer-of-liability-and-monitoring-of-supply-chains","tag-cybersecurity-risk-assessment","tag-entry-into-force-and-scope-of-the-cyber-resilience-act","tag-key-elements-of-the-cyber-resilience-act","tag-penalties-for-infringements-of-cra","tag-the-cyber-resilience-act-cra"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke<\/title>\n<meta name=\"description\" content=\"This blog post discusses the Cyber Resilience Act (CRA).\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke\" \/>\n<meta property=\"og:description\" content=\"This blog post discusses the Cyber Resilience Act (CRA).\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/\" \/>\n<meta property=\"og:site_name\" content=\"Lieke\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T09:59:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-22T11:14:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1395\" \/>\n\t<meta property=\"og:image:height\" content=\"817\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Maiju Sokka\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Maiju Sokka\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/\"},\"author\":{\"name\":\"Maiju Sokka\",\"@id\":\"https:\\\/\\\/lieke.com\\\/#\\\/schema\\\/person\\\/4164ead79c3ee667823790ff262055d0\"},\"headline\":\"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA)\",\"datePublished\":\"2026-09-22T09:59:35+00:00\",\"dateModified\":\"2026-09-22T11:14:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/\"},\"wordCount\":2298,\"publisher\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CRA.jpg\",\"keywords\":[\"CRA Placing the product on the market and post-market obligations\",\"CRA TRANSFER OF LIABILITY AND MONITORING OF SUPPLY CHAINS\",\"Cybersecurity risk assessment\",\"ENTRY INTO FORCE AND SCOPE OF THE CYBER RESILIENCE ACT\",\"KEY ELEMENTS OF THE CYBER RESILIENCE ACT\",\"PENALTIES FOR INFRINGEMENTS of CRA\",\"The Cyber Resilience Act (CRA)\"],\"articleSection\":[\"Insight\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/\",\"url\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/\",\"name\":\"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CRA.jpg\",\"datePublished\":\"2026-09-22T09:59:35+00:00\",\"dateModified\":\"2026-09-22T11:14:17+00:00\",\"description\":\"This blog post discusses the Cyber Resilience Act (CRA).\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#primaryimage\",\"url\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CRA.jpg\",\"contentUrl\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CRA.jpg\",\"width\":1395,\"height\":817,\"caption\":\"CRA\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/lieke.com\\\/en\\\/the-cyber-resilience-act-cra\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/lieke.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/lieke.com\\\/#website\",\"url\":\"https:\\\/\\\/lieke.com\\\/\",\"name\":\"Lieke\",\"description\":\"LIEKE focuses on energy and construction, dispute resolution, data and technology, and transactions.\",\"publisher\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/lieke.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/lieke.com\\\/#organization\",\"name\":\"M\u00e4kitalo Attorneys Ltd\",\"url\":\"https:\\\/\\\/lieke.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lieke.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Lieke.jpg\",\"contentUrl\":\"https:\\\/\\\/lieke.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Lieke.jpg\",\"width\":1395,\"height\":818,\"caption\":\"M\u00e4kitalo Attorneys Ltd\"},\"image\":{\"@id\":\"https:\\\/\\\/lieke.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.instagram.com\\\/liekeattorneys\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/lieke-attorneys\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/lieke.com\\\/#\\\/schema\\\/person\\\/4164ead79c3ee667823790ff262055d0\",\"name\":\"Maiju Sokka\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke","description":"This blog post discusses the Cyber Resilience Act (CRA).","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/","og_locale":"en_US","og_type":"article","og_title":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke","og_description":"This blog post discusses the Cyber Resilience Act (CRA).","og_url":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/","og_site_name":"Lieke","article_published_time":"2026-09-22T09:59:35+00:00","article_modified_time":"2026-09-22T11:14:17+00:00","og_image":[{"width":1395,"height":817,"url":"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg","type":"image\/jpeg"}],"author":"Maiju Sokka","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Maiju Sokka","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#article","isPartOf":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/"},"author":{"name":"Maiju Sokka","@id":"https:\/\/lieke.com\/#\/schema\/person\/4164ead79c3ee667823790ff262055d0"},"headline":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA)","datePublished":"2026-09-22T09:59:35+00:00","dateModified":"2026-09-22T11:14:17+00:00","mainEntityOfPage":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/"},"wordCount":2298,"publisher":{"@id":"https:\/\/lieke.com\/#organization"},"image":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#primaryimage"},"thumbnailUrl":"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg","keywords":["CRA Placing the product on the market and post-market obligations","CRA TRANSFER OF LIABILITY AND MONITORING OF SUPPLY CHAINS","Cybersecurity risk assessment","ENTRY INTO FORCE AND SCOPE OF THE CYBER RESILIENCE ACT","KEY ELEMENTS OF THE CYBER RESILIENCE ACT","PENALTIES FOR INFRINGEMENTS of CRA","The Cyber Resilience Act (CRA)"],"articleSection":["Insight"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/","url":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/","name":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA) - Lieke","isPartOf":{"@id":"https:\/\/lieke.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#primaryimage"},"image":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#primaryimage"},"thumbnailUrl":"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg","datePublished":"2026-09-22T09:59:35+00:00","dateModified":"2026-09-22T11:14:17+00:00","description":"This blog post discusses the Cyber Resilience Act (CRA).","breadcrumb":{"@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#primaryimage","url":"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg","contentUrl":"https:\/\/lieke.com\/wp-content\/uploads\/2026\/09\/CRA.jpg","width":1395,"height":817,"caption":"CRA"},{"@type":"BreadcrumbList","@id":"https:\/\/lieke.com\/en\/the-cyber-resilience-act-cra\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lieke.com\/en\/"},{"@type":"ListItem","position":2,"name":"A Brief Guide to Cybersecurity Regulation \u2013 Part 1: The Cyber Resilience Act (CRA)"}]},{"@type":"WebSite","@id":"https:\/\/lieke.com\/#website","url":"https:\/\/lieke.com\/","name":"Lieke","description":"LIEKE focuses on energy and construction, dispute resolution, data and technology, and transactions.","publisher":{"@id":"https:\/\/lieke.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lieke.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lieke.com\/#organization","name":"M\u00e4kitalo Attorneys Ltd","url":"https:\/\/lieke.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lieke.com\/#\/schema\/logo\/image\/","url":"https:\/\/lieke.com\/wp-content\/uploads\/2022\/12\/Lieke.jpg","contentUrl":"https:\/\/lieke.com\/wp-content\/uploads\/2022\/12\/Lieke.jpg","width":1395,"height":818,"caption":"M\u00e4kitalo Attorneys Ltd"},"image":{"@id":"https:\/\/lieke.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.instagram.com\/liekeattorneys\/","https:\/\/www.linkedin.com\/company\/lieke-attorneys"]},{"@type":"Person","@id":"https:\/\/lieke.com\/#\/schema\/person\/4164ead79c3ee667823790ff262055d0","name":"Maiju Sokka"}]}},"_links":{"self":[{"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/posts\/8051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/comments?post=8051"}],"version-history":[{"count":4,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/posts\/8051\/revisions"}],"predecessor-version":[{"id":8066,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/posts\/8051\/revisions\/8066"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/media\/8072"}],"wp:attachment":[{"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/media?parent=8051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/categories?post=8051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lieke.com\/en\/wp-json\/wp\/v2\/tags?post=8051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}