LEGAL: The EU is undergoing a comprehensive reform of the rules for smart products that will affect the electronics industry, from product design to sales on shop shelves.
Sunniva Nicole RebbestadSunniva NicoleRebbestadSenior lawyer, Ræder Bing law firm
Bleona BalajBleonaBalajTrainee lawyer, Ræder Bing law firm
Two key initiatives are the EU’s green growth strategy and the international digitalisation strategy. These have led to a number of new requirements relating to sustainability, consumer rights and cybersecurity. In Europe, the cyber threat is increasing in volume and complexity. In response, the EU has adopted a cybersecurity strategy and launched initiatives to increase security and resilience.
The EU is addressing the growing cyber threat with specific requirements for how products are to be designed, documented, updated and made available on the market. For manufacturers, importers and distributors, this means that cybersecurity is increasingly becoming a prerequisite for market access.
In 2024, the EU adopted the so-called Cyber Resilience Act (CRA), concerning the resilience of digital products and services. The CRA means that products with digital elements may only be sold in the EU if they meet essential cybersecurity requirements and requirements for vulnerability management. This is one of the first EU regulations to impose security requirements on the Internet of Things (IoT). The rules cover a wide range of products, including computers, smart TVs, smartwatches, routers and other equipment with digital or network-connected functionality. In the EU, the CRA will apply in full from December 2027. The regulation is relevant to the EEA, and corresponding requirements can therefore be expected in Norway.
Annonse
US ban on robots
Trainee lawyer Bleona Balaj. Photo: Ræder
The EU is not alone in starting to consider cybersecurity in electronic products. The US recently introduced a ban on foreign-manufactured advanced robotic devices (such as humanoid robots and quadruped robots), as well as connected foreign-manufactured inverters. This could affect robot lawn mowers, robot vacuum cleaners and other connected household products that navigate using sensors, cameras or mapping technology. The reason is that US authorities believe these products may pose a risk to national security interests, including due to supply chain vulnerabilities, remote-control functions and data collection. As a result, new models of products covered by the ban will generally not receive the necessary approval in the US. In practice, this will prevent the import, marketing and sale of new devices on the US market.
Who the CRA applies to
Annonse
The requirements of the CRA are aimed primarily at manufacturers, but also at importers and other operators that make relevant products available on the EU/EEA market. The purpose is to raise the security level of digital products throughout their lifetime.
For manufacturers, the CRA includes requirements to identify, manage and follow up vulnerabilities, as well as to ensure necessary security updates. Manufacturers and importers are required to address cybersecurity already at the development and design stage. Vulnerabilities and security incidents must also be reported to the relevant authorities. In Norway, the Norwegian Communications Authority (Nkom) has been delegated supervisory responsibility for the CRA.
The requirements of the regulation apply not only to the functionality of the end product, but also to the development process, technical documentation, vulnerability management, support period, security updates and reporting of exploited vulnerabilities. The product must be designed, developed and manufactured to provide an appropriate level of cybersecurity based on a specific risk assessment.
Furthermore, manufacturers must determine a support period that reflects how long the product is expected to be in use. As a general rule, this support period must be at least five years, but if the product is expected to be used for less than five years, the support period must correspond to its expected period of use.
Products covered
The Cyber Resilience Act applies to products with digital elements. This includes both software and hardware products and associated remote data processing solutions, including software or hardware components placed on the market separately.
Annonse
At the same time, there are exemptions, including for products already covered by other EU regulations, such as medical devices. Spare parts, as defined in the regulation, are also exempt.
In practice, however, the regulations cover the vast majority of consumer electronics that are connected or digitally controlled, including smartphones, wearables, smart home devices, smart TVs, network equipment and smart household appliances. Such products may only be made available on the market if they meet the essential cybersecurity requirements and the manufacturer's processes meet the requirements for vulnerability handling.
Some products with digital elements may also be categorised as important products or critical products. The classification affects how straightforward or demanding the route to CE marking and market access will be.
The main requirements of the CRA
Among other things, the product must be supplied with a level of cybersecurity proportionate to the risk, without known exploitable vulnerabilities and with a secure default configuration, so that the user does not have to correct insecure factory settings before the product is put into use.
Furthermore, the product must have appropriate control mechanisms against unauthorised access, and it must protect both the confidentiality and integrity of data. The requirements also cover availability and resilience, so that the product's essential functions can be maintained even after an incident, and so that the product does not unnecessarily impair the availability of other connected devices or networks.
In addition, the product must be designed, developed and manufactured with a limited attack surface, including by reducing exposed interfaces, services and functions that are not necessary for the product’s intended purpose.
Technical documentation
The CRA also requires the manufacturer to prepare technical documentation containing relevant information on compliance with the CRA. This must be in place before the product is made available on the market and must be kept up to date throughout the specified support period.
As a general rule, products covered by the regulations must bear CE marking as documentation that the relevant requirements have been met. This represents a significant development, as cybersecurity is now becoming an integral part of the CE marking process for digital products – something that has not previously been the case.
The article was previously published in the print edition of the trade journal Elektronikkbransjen No. 4/2026, which was distributed in week 35. Here you can read the article and browse the digital edition of the magazine. You can read all issues of the magazine digitally, from No. 1/1937 onwards, at elektronikkbransjen.no/historiskarkiv.