ENISA, the EU’s cybersecurity agency, published a practical self-check this week to help smaller businesses assess where they stand against the Cyber Resilience Act (CRA) — the EU law that sets mandatory cybersecurity requirements for any product with digital elements sold into the European market. It’s easy for UK businesses to assume EU legislation is someone else’s problem post-Brexit, but the CRA doesn’t work that way: it applies to the product’s market, not the manufacturer’s location. If you make or sell connected devices, embedded software, or apps with network-connected functionality anywhere in the EU, the CRA’s obligations land on you regardless of where your business is headquartered.
Why this lands differently to most EU rules
Most EU regulation UK businesses can genuinely ignore unless they trade there directly. The CRA is different because it treats “digital elements” broadly — smart devices, IoT hardware, connected industrial equipment, and standalone software products with network functionality can all be in scope, not just obviously “tech” products. A lot of SMEs who think of themselves as manufacturers or retailers, not tech companies, are still building or reselling something with a chip and a network connection in it. The self-check ENISA released is aimed precisely at that audience: businesses who haven’t been through a formal cybersecurity compliance exercise before and need a plain-language way to work out whether the CRA applies to them, and if so, how much work is involved.
What the self-check actually covers
The assessment walks through the practical basics: whether your product handles security vulnerability disclosure and patching over its expected lifetime, whether you document security-relevant design decisions, whether you have a defined support period communicated to customers, and whether your incident-reporting processes meet the CRA’s timelines. None of this is exotic security engineering — it’s closer to product governance discipline that most software and hardware businesses should have anyway, but very few smaller manufacturers currently document formally. Running the self-check is a low-cost way to find out whether you’re already most of the way there or facing a genuine gap, before a customer, distributor, or regulator asks the question for you.
What to do if the gap is real
If the self-check flags meaningful gaps — no formal vulnerability handling process, no documented support period, no incident response plan — treat it as a scoping exercise rather than a fire drill. KeepSafe monitors for exactly this kind of incident and disclosure obligation, which is useful groundwork for the CRA’s reporting requirements specifically. And if the gap is more about the product’s underlying software architecture — patchability, secure update mechanisms, dependency management — that’s a build and engineering question worth raising with CoolCoding or BuildApps before it becomes a compliance deadline under time pressure.
Two traps worth naming directly
First: the CRA’s obligations phase in on a schedule, with reporting duties for actively exploited vulnerabilities landing before the full conformity requirements bite — which is exactly why a self-check now beats the same exercise in twelve months, giving you room to close gaps before enforcement pressure arrives. Second: if you sell through a distributor, marketplace, or EU-based reseller, it’s tempting to assume the compliance burden sits with them. It generally doesn’t — the CRA places core obligations on whoever puts the product on the market under their own brand, which in most cases is still you as manufacturer even when a third party handles EU distribution. Confirm this explicitly with your distribution partners rather than assuming a silent contract has it covered.
The takeaway
The Cyber Resilience Act doesn’t care that you’re a UK business — it cares whether your connected product is sold in the EU. Run ENISA’s self-check this week if there’s any chance it applies to you, and treat a gap as a planning problem to solve now, not a surprise to manage later when enforcement timelines start to bite.