Attached are our detailed comments. The keys aspects to address are the descriptions of the critical products, ensuring that open-source solutions are not biassed against, and that certified and non-certified products are treated equally with respect to the CRA annex I part II requirements.
EU consultation
Technical description of important and critical products with digital elements
67 submissions from 67 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 122 submissions on this file. Shown here: the 67 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
Who showed up
46 submissions from industry — companies and their trade associations — against 8 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.8 industry submissions for every one from civil society.
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
What the room declares
- 36 of 67
- in the EU Register
- 178
- full-time lobbying staff
- €27.7M+
- declared costs a year
- 133
- EP accreditations declared
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.
The file, right now
The consultation closed on 18 Apr 2025 — it ran from 13 Mar 2025.
- Policy area
- Digital & tech (DG CNECT)
- Where it stands
- Awaiting adoption
- Adoption expected
- 30 Sept 2025
How it got here
- Draft implementing regulation18 Apr 2025
Also on the Commission’s pipeline for this file, with no date recorded: Initiative planned, Implementing regulation.
67 positions · showing 25
From the perspective of a supplier of products with digital elements, one core assumption is that any product with digital elements is brought into scope under Regulation 2024/2847 due to its inclusion in at least one class under Annex III or Annex IV. Where a product with digital elements might require a conformity assessment based on multiple classes, only the first class need apply.
The Open Regulatory Compliance (ORC) Working Group of the Eclipse Foundation thanks the European Commission for the opportunity to provide input to this draft implementing regulation. We take the opportunity to thank the Commission for the clarifications provided by the recitals which shine a light on areas that were a source of concern and confusion for the open source community.
The attached document compiles the feedback provided by Eurosmart on the draft Implementing Regulation concerning the technical description of the categories of important and critical products with digital elements.
We thank the European Commission for this opportunity to provide our feedback to an essential Implementing Regulation of the CRA. LightingEurope would like to request clarification regarding the classification of 10. Physical and virtual network interfaces under Class I (Important Products) in Annex I of the draft Implementing Regulation on product categories for the Cyber Resilience Act (CRA).
TrustCB B.V.
· · filed 18 Apr 2025 · source
We value the CRA and the impulse it will give to bringing state of the art security to a vast spread of devices. The assignment of various devices in categories still requires more clarification and consensus building with the stakeholders, with priority on the biggest impact devices already having an existing industrywide aligned and operational schemes.
NMi Certin B.V.
· · filed 18 Apr 2025 · source
Implications of the Cyber Resilience Act on Manufacturers and Integrators The Cyber Resilience Act (CRA) aims to enhance the cybersecurity of products with digital elements within the EU. This paper discusses how manufacturers can comply with the CRA, focusing on the implications for different types of products and the responsibilities of integrators. Manufacturers' Compliance with the CRA 1.
WindEurope Feedback Summary on the Draft Implementing Regulation (Cyber Resilience Act) WindEurope welcomes the European Commissions initiative to develop a harmonized framework for identifying important and critical products with digital elements under the Cyber Resilience Act (CRA). We support the effort to enhance cybersecurity across sectors and appreciate the opportunity to provide input.
Orgalim represents Europes technology industries, comprised of 770 000 innovative companies spanning the mechanical engineering, electrical engineering, electronics, ICT and metal technology branches. Together they represent the EUs largest manufacturing sector.
Euralarm is pleased to provide their feedback on the proposal from the European Commission for the technical description of 2 categories of products with digital elements: - Annex I, Class I, 17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems - Annex II, 1. Hardware Devices with Security Boxes. See the feedback attached.
Panasonic welcomes the opportunity to provide feedback to the European Commission's public consultation on the Cyber Resilience Act Implementing Act. We acknowledge the significance of this act in providing clarity and practical guidance for the CRA's effective implementation. Stakeholder input is crucial for robust and technically sound legislation that fosters a secure digital ecosystem.
Thank you very much for the opportunity to react to this draft implementing act. Whilst we are appreciative of the substantial work already done, we see a need for further improvements to the both the recitals and technical descriptions, predominantly to provide greater legal certainty.
Despite the very good effort to technically clarify the family of products under Class I, II and III, some uncertainties and unclear elements are still present. Special attention should be given to class III equipment where the description is still very vague and , in some cases , not bringing the needed clarification of scope.
GIE Cartes Bancaires CB (CB for short) is an economic interest grouping (GIE) which has, in France, sovereign authority over all CB-branded payments. Among the many tasks entrusted to it, it grants CB the approval of products that operate in the CB system, including card products, payment terminals and payment HSMs. Please find attached our comments.
Executive Summary Semiconductors are key components of everyday electronic devices that make life easier, safer, more secure, and greener. From ground and air transportation to pass-ports, payment cards, terminals, servers in data centres, desktop computers, sensors, etc., semiconductors are ubiquitous, fulfilling a crucial role in the whole domain of the Cyber Resilience Act (CRA).
From a Siemens AG perspective, it is essential that companies are being given sufficient time to prepare the implementation of the CRA. We feel that the current deadlines are very challenging and force companies to allocate significant resources to it. This is also valid for the European standardisation activities which will rely on those technical descriptions. Simplification of the framework is therefore critical.
NXP thank you for the opportunity to provide comments to the Draft Implementing Regulation. Please find our contribution in the attached document, addressing the semiconductors listed as Products with Digital Elements in Class I, Class II, and Critical products within the Cyber Resilience Act, and the proposed Implementing Regulation.
Dear Members of the European Commission, The Enel Group, a multinational company and a leading operator in the power and renewables markets of Europe, welcome the public consultation on the possibilities to build up a holistic European Cyber Resilience Act. Please find attached the complete response to the consultation. Best regards, [name removed]
As representative of the rail supply industry, UNIFE is very active in making the implementation of the CRA in the railway sector streamlined and efficient. Collaborating to the production of implementing acts and guidelines for the CRA is a key part of this process. The CRA encompasses a very broad ensemble of products in very different sectors, all with their own specificities.
Associazione Italiana Internet Provider (AIIP) welcomes the opportunity to provide feedback on the draft implementing regulation of the Cyber Resilience Act (CRA) and wishes to highlight critical aspects that may significantly impact small and medium-sized enterprises (SMEs), especially those that develop software internally for self-consumption or contribute to the open-source ecosystem.
The Cyber Security Platform (CSP) is an Austrian public-private partnership that was founded in 2015 as part of the Austrian Strategy for Cybersecurity (ÖSCS) and counts 500+ security experts as members. The CSP supports the Cyber Security Steering Group (CSS) in improving cybersecurity in Austria below the political and above the technical level.
We appreciate the opportunity to contribute to the consultation on the draft implementing regulation under Article 24(9) of the Cyber Resilience Act (CRA). Fujitsu, as a global Japanese company with a significant presence in Europe and deep expertise in B2B services, cloud and on-premise infrastructure, IoT, and cutting-edge fields such as quantum computing and artificial intelligence, we fully support the…
Dear madams or sirs, please find attached our comments on the available draft Commission Implementing Regulation on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council. Please do not hesitate to come back to our research institute for further dialogue on this topic.
Thank you for the opportunity to provide comments on the draft Implementing Act concerning the technical descriptions of the categories of important and critical products with digital elements pursuant to the Cyber Resilience Act. Please find attached the response of the Information Technology Industry Council (ITI).
Knorr-Bremse supports the objectives of the Cyber Resilience Act (CRA) and acknowledges the European Commissions efforts to clarify the technical descriptions of the categories of important and critical products with digital elements listed in Annexes III and IV of the Regulation, through its review of stakeholder feedback.
Dear Sir/Madam, Please find attached the recommendations of the European Heating Industry (EHI) on the draft Implementing Act on technical descriptions of the categories of important and critical products with digital elements listed in Annex III and IV of the Cyber Resilience Act.
Dear Sir/Madam, Please find attached ETSI's feedback to the draft Commission implementing decision on technical description of the categories of important and critical products with digital elements listed in Annex III and IV to the Cyber Resilience Act. ETSI remains at your disposal at any time for further dialogue on this matter.
Dear Sir/Madam, Thank you for the opportunity to provide feedback to this Draft Implementing Regulation. Please find enclosed our recommendations for the technical descriptions of the categories of important and critical products with digital elements listed in Annex III and IV of the Cyber Resilience Act.
The CUSTODES project, (a project dedicated to supporting cybersecurity certification), celebrates the creation of the draft documents on the technical description of the categories of products with digital elements under classes I and II listed in Annex III of the CRA and the technical description of the categories of products with digital elements listed in Annex IV of the CRA.
Logitech welcomes the Commissions proposal for the Cyber Resilience Act (CRA) and supports its goal to enhance cybersecurity across the EU. As a leading global manufacturer of digital products, we strongly support risk-based, horizontal requirements to improve consumer trust, product security, and industry accountability.
Microsoft Corporation (Microsoft) appreciates the opportunity to comment on the proposed implementing act to the EU Cyber Resilience Act regarding product category definitions. Please find attached our feedback in the requested template. Microsoft first addresses comments applicable to the entirety of the proposed implementing act, followed by product category-specific feedback.
On top of the specific comments in the attachment, some of our members raised questions concerning whether the draft implementing regulation should clarify if a product might full under more than one category. In addition, could we confirm that: - Industrial Automation and Control Systems (i.e. PLC, SCADAS) - industrial IEDs, such as, relays and actuators for smart grids Are falling under default products?
The Smart Payment Association (SPA) is the trade body of the cards and mobile payments industry. SPA addresses the challenges of a fast-evolving payment ecosystem, promoting innovation, security and interoperability of payment instruments.
ESMIG - The European association of smart energy solution providers welcomes the opportunity to comment on the European Commission's draft implementing regulation that contains draft technical descriptions of the products with digital elements in the important and critical categories of the Cyber Resilience Act. Our comments are listed in the document attached.
mioty alliance e.V.
· · filed 17 Apr 2025 · source
The mioty alliance is a community of people, businesses, and institutes that provides an open, standardized and interoperable ecosystem across the entire IoT (Internet of Things) value chain based on the mioty technology.
BEUC - The European Consumer Organisation welcomes the opportunity to comment on the European Commission's draft implementing regulation that aims to specify the technical description of the categories of important and critical products with digital elements under the Cyber Resilience Act. Please find BEUC's contribution in the document attached.
The CURIUM project, (a project dedicated to support CRA implementation by developing the Compliance Continuum a suite of cybersecurity-focused tools and services designed to facilitate security testing, regulatory compliance, and risk mitigation), celebrates the creation of the drafts documents on the technical description of the categories of products with digital elements under classes I and II listed in Annex III…
Thank you for the possibility to provide feedback on this aspect of CRA implementation. The CRA is an extremely important legislation that will have a profound impact in the European market. Attached you will find some comments on the proposed definitions in an effort to ensure clarity and consistency with other provisions of CRA and current market/technological realities.
DECATHLON welcomes the opportunity to provide feedback on the European Commissions draft implementing act, the technical description of the categories of important and critical products with digital elements listed in Annex III and IV of the Cyber Resilience Act (CRA).
Kamstrup thanks the commission for the opportunity to have insights and comment on the draft implementing act defining the technical descriptions of important and critical product categories under the CRA. We appreciate the possibility to provide constructive comments for specific categories where we have some expertise and that may affect our business. Please find our feedback in the attachment.
Due to the expected growth in the number of recharging points for electric vehicles in Europe, considering the obligations in AFIR and the Fitfor55 package, the potential impact of a cyber attack on recharging infrastructure is increasing.
The French banking sector fully understands the objective pursued by this European regulation to secure such products for a better consumers protection. This objective is indeed part of the broader strategy to enhance cybersecurity level in Europe, which the banking sector greatly supports, provided that it does not add unnecessary complexity and burdens for operators.
On behalf of Cisco, please find attached our analysis of the draft CRA Implementing Regulation. Our comments include revised definitions aimed at enhancing clarity, consistency with international frameworks, and practical implementation for manufacturers. We hope you will find this useful and remain available for any follow-up questions.
The European Signature Dialog (ESD) stands as the pinnacle consortium of leading European Qualified Trust Service Providers (QTSPs), facilitating secure digital interactions across Europe every day. ESD has successfully collaborated with all institutions leading up to the adoption of eIDAS 2.
Hangzhou Hikvision Digital Technology Co., Ltd.
· · filed 16 Apr 2025 · source
Hangzhou Hikvision Digital Technology Co., Ltd. (Hikvision, EU Transparency Register No. 181069237409-88) is a world leading security product and solution supplier with offices in many EU Member States. In an era where cyber threats are becoming increasingly sophisticated, Hikvision understands the critical importance of cybersecurity in safeguarding the whole AIoT systems.
On behalf of the Centre for Cybersecurity Belgium (CCB), we hereby submit our analysis of the CRA Implementing Regulation and its associated requirements. In the attached document, you will find revised definitions aimed at enhancing clarity, consistency, and practical implementation for manufacturers.
Being a major supplier of products that are in scope of CRA, Renesas is welcoming the review possibilities for all various EU and DG Connection documentation. CRA will bring many new challenges in the development and release of microcontrollers and microprocessors to the market and definitions of terms such as Product, Component, Device need careful consideration to avoid any confusion.
As a member organization representing 29 distribution and transmission system operators in Europe, ENCS is concerned about the possible impact of two of the definitions of critical products on the electricity sector. For smart meter gateway, the current definition does properly reflect the implicit definitions used in the sector.
Assuralia considers that the applications (web and mobile) and client portals that are currently used by insurance companies to support the provision of insurance services do not fall within the scope of the CRA regulation.
Dedalus S.p.A., as a group developing and distributing medical software within the European Union, would like to express our sincere appreciation for the European Commission's efforts in advancing cybersecurity through the Cyber Resilience Act (CRA). We welcome the orientation, clarity, and strategic foresight demonstrated by the CRA.
Attached is the feedback from the Open Source Security Foundation (OpenSSF) on the Technical description of important and critical products with digital elements for the CRA. We used the comment template as requested. Thank you for the opportunity to comment.
This implementing act to provide a better technical description of the different categories is welcomed. However, the attempt to clarify goes somtimes into more questions as the scope is extended beyond what is described in the Cyber Resilience Act. Please refer to the enclosed file.
MAFEX, the Spanish Railway Association, is the association that represents the Spanish railway industry, currently bringing together 112 companies that account for 84% of rail exports in our country. Established 2004, we implement activities around 4 major areas: - Internationalisation - Competitiveness and Innovation - Institutional Relations and Strategic Positioning - Marketing and Communication In order to…
The sheer ubiquity and deep integration of smartphones into modern society further amplify the potential impact of security failures, aligning with the criteria for Class 2 designation which considers the scale and severity of potential adverse effects.
The Test & Measurement Coalition (TMC, represented by its permanent secretariat EPPA) welcomes the Commissions draft implementing regulation on the technical specifications of important and critical products with digital elements under the Cyber Resilience Act (CRA). This text represents an important step in setting the stage for the implementation of the CRA.
EUROMOT - The European Association of Internal Combustion Engine and Alternative Powertrain Manufact
· · filed 14 Apr 2025 · source
EUROMOT, the European Association of Internal Combustion Engine and Alternative Powertrain Manufacturers, represents the key manufacturers of internal combustion engines and alternative powertrains installed in industrial non-road mobile machinery, marine and stationary applications that are operating in Europe and worldwide. See feedback form attached.
Best digital express of identity of each product should include all toxicity awareness & all chemical components We Can recognise as a substance to analyse the subject with support from municipalities who Can register side effects & all good caracters included in the reports to have AI support from companies WHO Can easily colloborate with the concept of healing via intraoral scanners creating regulations to remove…
We appreciate the further elaboration of the CRA through the technical description provided. From the perspective of financial institutions, which are already subject to a lex specialis framework under DORA, many of the outlined requirements naturally apply, given the already very high security standards fulfilled by the financial sector.
Various unclear definitions exist in the Important and Critical products descriptions in Annexes. We, as a research group on IoT cyber security in Japan, have huge concerns over such newly established legislations, which pose a very new type of challenge for the manufacturing industry to produce appropriate products in terms of cyber security.
Giesecke+Devrient Mobile Security Germany GmbH, a subsidiary of the Giesecke+Devrient group, specializes in delivering highly secure solutions in Connectivity & IoT. Our offerings include technologies for pluggable SIM, eSIM, and iSIM, along with associated embedded operating systems and lifecycle management services. It also provides global connectivity services and comprehensive IoT solutions.
Trusted Connectivity Alliance (TCA, https://trustedconnectivityalliance.org/) is a global industry association working to enable trust in a connected future. The organisation evolved from the SIMalliance in 2020, reflecting the continued expansion of the global SIM industry and the need for broader collaboration.
SolarPower Europe is the leading solar association in Europe. In our July 2024 position paper "Setting a Harmonised Cybersecurity Baseline for Solar PV", we called for recognition of internet-connected solar inverters as critical infrastructure.
Association for Computing Machinery- Europe Technology Policy Committee
· · filed 2 Apr 2025 · source
Whilst the illustrative lists in the Annexes are helpful, it would be better to characterise the different types of component as in Articles 7(2) and 8(2) of the CRA. Stating the characteristices will ensure some future proofing of the Regulation. Add the following text to Article 1:The criteria for important products (CRA Art.7): 1.
The draft implementing regulation to define the technical descriptions of important and critical products with digital elements under Regulation (EU) 2024/2847 (Cyber Resilience Act) marks a vital step in operationalizing Europe's horizontal cybersecurity framework. It provides much-needed clarity for manufacturers, consumers, and regulators across a range of digital product categories.
DigiCert Inc.
· · filed 17 Mar 2025 · source
The act is vague in several areas: 1) https://www.cyberresilienceact.eu/cra-guide-for-software-developers/ it states "The Cyber Resilience Acts main focus in on companies developing and commercializing non-embedded software". The act should define what "non-embedded software" is. Is this Linux and Windows devices? Or includes RTOS platforms such as FreeRTOS or Zephyr?
wecon.it-consulting
· · filed 14 Mar 2025 · source
In Annex I, Class 1, No. 2, it should be clarified that the internet is only an example and that the case intranet based web(service)server (whereby access from outside is then possibly enabled by a VPN) should also be covered. One could also consider whether the term browser engine instead of browser would be more suitable.
Tauri Programme within the Commons Conservancy
· · filed 14 Mar 2025 · source
There has been a good deal of speculation in the various working groups that suggests that the regulator considers SaaS or other Browser-based software as being exempted from the CRA because they are covered elsewhere (NIS2, DSA, etc.) In the description of password managers here, we see for the first time that some browser-based software is to be explicitly considered under the regime of the CRA, e.g.
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.