European Product Regulation Gets a Security Update – The EU Cyber-Resilience Act as an Adaptation to a Highly Digitised Product Market
Pratham AjmeraAbstract
In late 2024, the EU Cyber-Resilience Act (CRA) was adopted, setting essential cybersecurity requirements for products entering the European market. With a wide material scope, it harmonises essential cybersecurity requirements for digitally enabled products. The CRA stands upon a product regulatory framework called the New Legislative Framework (NLF). Since the late 2000s, the European Union has relied on the NLF to harmonise product regulation across the Union market. Since then, the product market has evolved rapidly and significantly, characterised by widespread digitisation, servicification and connectivity, exemplified best through the Internet of Things (IoT). These developments led to a review of the NLF in 2022, wherein questions were raised regarding its efficacy in contemporary markets. This article investigates the CRA as a possible NLF adaptation to current market considerations. It consists of two parts, first investigating what the CRA does differently vis-a-vis conventional NLF legislation, whether that procures benefits and where may these benefits be attributed. Second, it explores cybersecurity as a novel product harmonisation objective, weighing it against product safety as a more developed regulatory objective. This article finds that there are adaptive elements; their benefits are incidental to the NLF and heavily reliant on private regulatory avenues, while proposing areas for further research.