Deep Dive | The EU Cyber Resilience Act (CRA)

CRA Countdown: Why Taiwan's ICT Manufacturers Should Prepare Now — Not in 2027

If your product has any connectivity — Wi-Fi, Bluetooth, or any form of data connection — then after December 2027, whether it can legally be sold into the European market is no longer decided by quality or price. It is decided by whether you hold a compliance document.

Key Takeaways

  • CRA timeline: In force Dec 2024 → EN 18031 mandatory Aug 2025 → vulnerability reporting from Sep 11, 2026 → fully applicable Dec 11, 2027
  • Penalties: Up to €15 million (≈ NT$510 million) or 2.5% of global annual revenue, whichever is higher
  • The bigger risk: Being dropped from brand supply chains — brands already require suppliers to submit SBOMs and test evidence
  • What EN 18031 tests: Three parts mapping to RED 3.3(d)(e)(f) — network protection, privacy protection, fraud prevention
  • What you can do now: Book a free gap analysis, or join the free "EU CRA Update" live session

The Regulatory Deadline Is at the Door — and the Clock Is Running

The timers below are calculated live. Every second you see is real.

CRA in force (Dec 2024)Fully applicable (Dec 11, 2027)
NOW
✓ December 2024

CRA Enters into Force

The EU Cyber Resilience Act takes effect, covering all products with digital elements (PDE).

✓ In force
✓ August 2025

EN 18031 Becomes Mandatory

The security requirements under the amended Radio Equipment Directive (RED) become mandatory — no longer voluntary.

✓ In force
● September 11, 2026

Vulnerability Reporting Obligations Begin

Actively exploited vulnerabilities must be reported to CSIRT/ENISA within 24 hours, with a full report within 72 hours.

--
Days
--
Hrs
--
Min
--
Sec
▲ December 11, 2027

CRA Fully Applicable

Every PDE product sold into the EU must comply. Fines up to €15M (≈ NT$510 million) or 2.5% of global revenue.

--
Days
--
Hrs
--
Min
--
Sec
⚠ Non-compliance costs more than the fine

For most ODM/OEM manufacturers, the real damage is being dropped from a brand's supply chain. Brand owners carry the final legal responsibility — even when a vulnerability originates with a single supplier — so they have already begun demanding SBOMs (software bills of materials) and test evidence as a new condition of market entry. Notified Body certification typically takes 12 to 18 months; wait until 2027 and you join a global queue the NBs cannot absorb.

CRA and EN 18031 Overlap Heavily — So What Exactly Gets Tested?

RED 3.3 × EN 18031

The good news: nothing you invest now is wasted. EN 18031 is the harmonized standard under Article 3.3 of the Radio Equipment Directive (RED) — RED 3.3 is the parent regulation, EN 18031 is the technical standard used to demonstrate compliance; they are two layers of the same thing. The CRA's own harmonized standards are still in draft, but they are widely expected to extend EN 18031's technical architecture — prepare for EN 18031 now and the foundation for the CRA is already laid.

EN 18031 is not a single standard. It splits into three independent parts, each mapping to a different security requirement in RED Article 3.3(d), (e) and (f):

EN 18031-1 | RED Art. 3.3(d)

Network Protection

Ensures the device and its network connections resist intrusion — the broadest of the three parts.

Applies to: virtually every connected wireless device (Wi-Fi, Bluetooth and similar)
EN 18031-2 | RED Art. 3.3(e)

Privacy Protection

Examines how personal data is protected through collection, storage and transmission.

Specifically covers: children's connected products, toys, wearables
EN 18031-3 | RED Art. 3.3(f)

Fraud Prevention

Confirms the device cannot be used as a tool or springboard for fraud.

Specifically covers: connected devices handling virtual currency or monetary value

💡 Practical advice for decision-makers

Full conformity with all three parts of EN 18031 allows self-declaration — no Notified Body (NB) review — a realistic acceleration option for manufacturers weary of the NB queue. Use other standards, or fall short anywhere, and NB review is still required.

The CRA does not directly adopt EN 18031 as its official harmonized standard. Under standardization Mandate M/606, the EU is drafting a new series — prEN 40000 and EN 304 6xx — still at draft stage, but built as an extension of EN 18031's technical architecture. Complete EN 18031 now and the groundwork for the CRA harmonized standards is already done.

Worth noting: EN 18031-3 is designed specifically for connected devices handling virtual currency or monetary value — squarely within the payment-security domain Secure Vectors Surveillance has worked in for over a decade. If your product touches payment flows, stored value or transactions, this part deserves particular attention.

Note: this page focuses on general ICT connected devices. The MDR × EN 18031 dual-compliance challenge for smart medical devices is a larger topic we will cover in a dedicated deep dive.

Ready to Act? Here Is the Path

Secure Vectors Surveillance and Applus+ Laboratories propose a three-level strategy for getting ahead of the change:

1

Regulatory Awareness

Track CRA developments and clarify your products' risk classification and scope

2

Implementation Capability

Build a vulnerability-disclosure SOP that meets the 24-hour alert / 72-hour report requirement, and complete a gap analysis

3

Industry Ecosystem

Local testing × global certification through a partner network, so compliance is not a solo fight

FREE

Secure Vectors Surveillance and Applus+ Laboratories present “EU CRA Update” — a one-hour live online session, completely free, unlimited seats, built for decision-makers, export sales leads and compliance officers.

★ 30 seats · By application · Free

Don't scramble after the regulation fully applies — complete your gap analysis now

Keep your time for the product work that matters.

Frequently Asked Questions

When did the CRA enter into force — and when does it become fully mandatory?

The CRA entered into force in December 2024. EN 18031's security requirements became mandatory in August 2025; vulnerability-reporting obligations begin September 11, 2026; and on December 11, 2027 the CRA becomes fully applicable to every product with digital elements sold into the EU.

What are the penalties for non-compliance?

Up to €15 million (≈ NT$510 million) or 2.5% of global annual revenue, whichever is higher. In practice, the bigger risk for most ODM/OEM makers is being dropped from brand supply chains.

How do EN 18031 and RED 3.3 relate — and what do the three parts test?

EN 18031 is the harmonized standard under RED Article 3.3, in three parts mapping to 3.3(d)(e)(f): Part 1 network protection (general connected devices), Part 2 privacy protection (children's products, toys, wearables), Part 3 fraud prevention (devices handling virtual currency or monetary value). Full conformity allows self-declaration with no Notified Body review.

How long does certification take? Is there still time?

Notified Body certification typically takes 12 to 18 months. Apply on the eve of full enforcement in 2027 and you risk a global queue the NBs cannot absorb — start the gap analysis now.

Secure Vectors Surveillance is a subsidiary of Secure Vectors Information Technologies Inc. Since 2010 the group has specialized in financial payment security certification, with deep PCI DSS expertise, and operates one of the few ISO 17025-accredited security labs able to run the full EN 18031 test series in Taiwan. In alliance with Applus+ Laboratories, a global leader in testing, inspection and certification (TIC), it builds a “local testing × global certification” compliance chain.