Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Choosing and using digital products more safely

Last updated:

Choosing and using digital products more safely

The CRA is intended to help users consider cybersecurity when choosing and using hardware and software. Most product requirements start to apply on 11 December 2027. This checklist is practical guidance; it does not create new user duties or guarantee the security of a particular product.

Before purchase or deployment

Check whether the following are clearly available:

For public or business procurement, document the required support period, time to remediate critical vulnerabilities, incident notifications, data export, secure service exit and supplier responsibilities. These are risk-management recommendations, not automatically legal duties on a buyer under the CRA.

After installation

When a manufacturer announces a vulnerability or fix

Check which versions are affected, the risk and the manufacturer’s recommended action. Install the fix or apply the mitigation. If the product cannot be updated securely or is no longer supported, consider isolating, replacing or retiring it based on the risk.

Where to report a problem

What the CE marking means

The CE marking signifies that the manufacturer declares compliance with applicable EU requirements. It is not a security rating for every future software state and does not mean that the product can never contain a vulnerability. The current version, secure configuration, available updates and continuing support also matter.