Choosing and using digital products more safely
The CRA is intended to help users consider cybersecurity when choosing and using hardware and software. Most product requirements start to apply on 11 December 2027. This checklist is practical guidance; it does not create new user duties or guarantee the security of a particular product.
Before purchase or deployment
Check whether the following are clearly available:
- the exact product name, model and version;
- the manufacturer’s name and contact and, for a third-country product, relevant importer details;
- the CE marking and EU declaration of conformity where required;
- the support end date or a way to find it;
- information about security updates and how they will be delivered;
- instructions for secure installation, configuration, operation and removal;
- a contact or process for reporting a vulnerability to the manufacturer;
- dependencies, compatibility and end-of-support implications relevant to your environment.
For public or business procurement, document the required support period, time to remediate critical vulnerabilities, incident notifications, data export, secure service exit and supplier responsibilities. These are risk-management recommendations, not automatically legal duties on a buyer under the CRA.
After installation
- change default passwords and disable functions or remote access you do not need;
- install trusted security updates without unnecessary delay;
- verify updates and instructions through the manufacturer’s official channel;
- limit the product’s permissions and network access to what it needs;
- back up important data and retain configuration needed for recovery;
- monitor manufacturer security notices and the support end date;
- securely remove data and accounts before sale, transfer or disposal.
When a manufacturer announces a vulnerability or fix
Check which versions are affected, the risk and the manufacturer’s recommended action. Install the fix or apply the mitigation. If the product cannot be updated securely or is no longer supported, consider isolating, replacing or retiring it based on the risk.
Where to report a problem
- Possible CRA non-compliance: Report possible product non-compliance.
- Technical vulnerability or incident: Report an incident — SK-CERT (Slovak), or the manufacturer’s designated vulnerability channel. The linked SK-CERT service page is currently available in Slovak.
- Mandatory manufacturer report: the official process in CRA reporting.
- Refund, repair or other individual remedy: contact the seller or the relevant consumer mechanism; a market-surveillance tip is not an individual claims process.
What the CE marking means
The CE marking signifies that the manufacturer declares compliance with applicable EU requirements. It is not a security rating for every future software state and does not mean that the product can never contain a vulnerability. The current version, secure configuration, available updates and continuing support also matter.