In short
The CRA (Regulation (EU) 2024/2847) requires that "products with digital elements" (software, firmware, connected hardware) are built, documented and updated securely across their entire lifecycle. Think of it as CE marking for cybersecurity.
Does it apply to me?
If you place a product with digital elements on the EU market commercially, yes, including manufacturers outside the EU, such as UK, US or Swiss companies. Pure cloud SaaS without an installable or connected component is usually out of scope.
What happens if I don’t comply?
From late 2027, non-compliant products can no longer be sold in the EU. Fines reach up to €15 million or 2.5% of global annual turnover. In practice the biggest lever is market access: large buyers demand conformity evidence from their suppliers.