Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
REGULATION (EU) 2024/2847 - CYBER RESILIENCE ACT

Your digital products
compliant with the Cyber Resilience Act

The Cyber Resilience Act imposes cybersecurity requirements on all products with digital elements (hardware and software) placed on the market of the European Union. SYAGA supports you in understanding your obligations and building your compliance file, without improvising.

2024/2847
Regulation (EU), EUR-Lex reference
10/12/2024
Date of entry into force
3 roles
Manufacturer, importer, distributor
Tiers
Progressive application over time

The regulation

The Cyber Resilience Act (CRA) is a horizontal European text on the cybersecurity of digital products

A very broad scope

The CRA covers products with digital elements (connected hardware, software, firmware) intended to be placed on the EU market, with cybersecurity requirements throughout the product's lifecycle.

📋

Obligations that depend on your role

Manufacturer, importer or distributor: the regulation distributes different obligations depending on your position in the placing-on-the-market chain, following the model already used by other European product regulations.

A progressive application, already under way

The text entered into force on 10 December 2024 and provides for a tiered application over time. The precise deadlines that concern you must be verified against the official text for your situation.

🛠

Few companies have already formalised their approach

As with other recent European cyber texts, CRA compliance requires a method (product mapping, gap analysis, technical documentation) that most software vendors and manufacturers have not yet undertaken due to a lack of dedicated internal resources.

Who is affected?

The CRA is addressed to economic operators who place digital products on the EU market

Manufacturers

Companies that design or have designed products with digital elements (hardware, software, firmware) marketed under their name or trademark.

Importers

Companies that place on the EU market a digital product designed outside the Union.

Distributors

Companies that make a product available on the EU market without being its manufacturer or importer.

Our support

A structured approach to map your products, measure gaps and build your compliance action plan

1
Scoping

Interview and scope

Interview with management or the R&D team to identify the products potentially affected by the CRA (connected hardware, embedded software, firmware) and your role as an economic operator (manufacturer, importer, distributor).

2
Diagnosis

Gap analysis against the regulation

Mapping of your digital products and their current cybersecurity elements (vulnerability management, security updates, existing documentation), compared against the regulation's requirements.

3
Action plan

Prioritisation and roadmap

Prioritised compliance plan: what needs to be handled first, what can wait for upcoming regulatory deadlines, and the resources to mobilise internally.

4
Documentation

Support for building the technical file

Support in structuring the technical documentation expected by the regulation (product description, cybersecurity risk management, vulnerability handling procedures).

5
Handover

Presentation and knowledge transfer

Presentation of the diagnosis and action plan to management, with delivery of editable materials for your teams to take ownership of.

What you receive

A diagnosis and a roadmap to steer your CRA compliance

📋

Mapping of affected products

Inventory of your products with digital elements and qualification of their exposure to the regulation.

  • List of products and versions
  • Identified economic operator role
  • Digital elements inventoried (hardware/software)
🔍

Gap analysis

Summary of the gaps between your current practice and the regulation's requirements.

  • Existing vulnerability management
  • Security update process
  • Available technical documentation
📈

Compliance action plan

Prioritised roadmap to close the identified gaps.

  • Prioritised actions
  • Internal resources to mobilise
  • Points of attention per product
📄

Technical file support

Support in structuring the documentation expected by the regulation.

  • Product description template
  • Cybersecurity risk management template
  • Vulnerability handling template
🔐

Regulatory watch

Monitoring of implementing texts and official clarifications published on the CRA.

  • Points of attention on deadlines
  • Alerts on changes to the text
  • Recommendations for anticipation
💻

Editable deliverables

All documents in formats you can modify and maintain internally.

  • HTML and PDF formats
  • Editable documents for your teams
  • Reusable structure for your future products

A regulation that fits with your other obligations

The CRA does not replace your other compliance efforts, it complements them

N2

NIS2 (Directive (EU) 2022/2555)

NIS2 governs cyber risk management for essential and important entities; the CRA governs the security of the digital products they use or market. The two texts are complementary.

ISO

ISO 27001:2022

An information security management system already in place makes it easier to structure the vulnerability management processes required by the CRA.

GD

GDPR (Regulation (EU) 2016/679)

If your digital product processes personal data, the CRA's security requirements partly overlap with the technical and organisational measures expected under Article 32 of the GDPR.

AI

AI Act (Regulation (EU) 2024/1689)

If your product incorporates artificial intelligence components, the CRA and the AI Act may apply jointly depending on the nature of the product. A point to clarify case by case with your legal counsel.

Support on a quote basis

Every product, every scope is different: we prepare a quote tailored to your situation

Diagnosis

One product, a limited scope

On quote
Tailored to your situation
  • Mapping of the affected product
  • CRA gap analysis
  • Summary of points of attention
Request a quote

Complete file

Product range, continuous compliance cycle

On quote
Tailored to your situation
  • Everything in Support +
  • Multi-product tracking
  • Update with every change to the text
  • Priority support
Request a quote
Important: we do not display a fixed price because the effort depends on the number of products, their complexity and your role as an economic operator. Every quote request is reviewed individually.

Frequently asked questions

Is my company affected by the Cyber Resilience Act?
If you design, import or distribute a product with digital elements (connected hardware, software, firmware) intended for the European Union market, you are potentially affected. The exact scope (possible exemptions, product categories) must be confirmed case by case with your legal counsel against the official text.
When does the regulation actually apply?
The regulation entered into force on 10 December 2024 and provides for a progressive tiered application. The precise deadlines for your product category must be verified against the official text (EUR-Lex) at the time of your project, as these deadlines may evolve or be clarified by subsequent implementing acts.
What happens in case of non-compliance?
The regulation provides for a regime of financial penalties for breaches of the obligations it sets out. The exact amounts and procedures must be verified against the official text; we do not display them here to avoid any approximation on a legal matter.
Does this diagnosis replace legal advice?
No. Our support is a tool to help structure your compliance approach. It does not constitute legal advice and does not replace the analysis of your counsel (lawyer, jurist) on your particular situation.
How much time do I need to mobilise my teams?
This depends on the number of products and the current maturity of your vulnerability management processes. An initial scoping interview and a final handover are always included; the exact volume is specified in the quote.
What makes SYAGA legitimate for this support?
SYAGA Consulting has carried out information system security audits since 2009. We follow European cybersecurity texts (NIS2, GDPR, DORA, CRA, AI Act) for our clients and build structured diagnostic methods, without replacing legal counsel.

Regulatory watch - official sources

What the CRA text really says, explained simply. Each point links to its official source (EUR-Lex or the European Commission) so you can verify for yourself.

📜

The CRA in one sentence

The Cyber Resilience Act is a European regulation (Regulation (EU) 2024/2847) that sets cybersecurity rules for digital products - hardware and software - sold in the European Union. It entered into force on 10 December 2024.
official source ↗

🔍

Who is affected, in plain terms

Any product with digital elements intended to connect, directly or indirectly, to a device or network. Products already covered by other European texts are excluded: medical devices, vehicles, aviation, marine equipment, identical spare parts, or products designed exclusively for defence/national security.
official source (Article 2) ↗

The dates to remember

10 December 2024: the text entered into force. 11 June 2026: the authorities responsible for enforcing it must be in place. 11 September 2026: vulnerability and incident reporting obligations start. 11 December 2027: most obligations, including CE marking, become applicable.
official source (Article 71) ↗

🚨

In the event of a security breach, there are deadlines

If an actively exploited vulnerability or a serious incident affects your product, the regulation requires you to notify the authorities: an initial early warning within 24 hours, a more detailed notification within 72 hours, then a final report no later than 14 days after a fix becomes available.
official source (Article 14) ↗

🔐

Some products are watched more closely

The text distinguishes categories of products considered more sensitive (for example antivirus, VPNs, password managers, operating systems, routers, connected home security devices) and "critical" products (for example smart cards, smart metering gateways), subject to reinforced requirements.
official source (Annexes III and IV) ↗

The penalties, in plain terms

Up to 15 million euros or 2.5% of worldwide turnover (whichever is higher) for the most serious breaches of essential security requirements. Up to 10 million or 2% for other obligations, and up to 5 million or 1% for providing misleading information to the authorities. Micro and small enterprises benefit from a specific waiver regarding delays on the 24-hour reporting deadline.
official source (Article 64) ↗

🛡

How it fits with the rest

The CRA complements the NIS2 directive and builds on the EU's 2020 cybersecurity strategy. CE marking will be required to attest compliance, and national market surveillance authorities will oversee its enforcement.
official source (European Commission) ↗

Reading note: this page summarises and simplifies the official text to make it understandable in a few minutes. In case of doubt about your situation, only the consolidated text published on EUR-Lex is authoritative - to be verified with your legal counsel.

CRA penalties, in plain terms

The regulation sets 3 fine tiers depending on the severity of the breach. Here is exactly what the official text says, with no rounding or approximation.

Most serious breach
Up to €15 M
or 2.5% of worldwide turnover
(whichever is higher)

Essential security requirements + reporting obligations

Non-compliance with basic cybersecurity requirements (Annex I) or manufacturers' obligations (Articles 13 and 14: secure design, vulnerability management, incident reporting).

Other obligations
Up to €10 M
or 2% of worldwide turnover
(whichever is higher)

Representatives, CE marking, notified bodies

Breaches of authorised representatives' obligations, of the EU declaration of conformity (CE marking), of requirements relating to notified bodies, and of data access requested by the authorities (Articles 18 to 53 depending on the case).

Misleading information
Up to €5 M
or 1% of worldwide turnover
(whichever is higher)

Incorrect or incomplete response to an authority

Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority questioning you.

official source - Regulation (EU) 2024/2847, Article 64, paragraphs 2 to 4 ↗

📌 Who imposes the fine?

It is each Member State's national market surveillance authority that applies these fines (not the European Commission directly). Depending on the country's legal system, the fine may also be imposed by a competent national court. Authorities in different Member States communicate fines applied to each other.

official source - European Commission ↗

⚖️ What is taken into account to set the amount

The text does not impose an automatic amount: the authority must take into account, on a case-by-case basis:

  • the nature, gravity and duration of the breach, and its consequences;
  • any fine already applied for a similar breach;
  • the size of the company (particular attention is given to micro, small and medium-sized enterprises, including start-ups) and its market share.

official source - Article 64(5) ↗

🔑 A narrowly targeted SME exception (not a general waiver)

The text provides for a single quantified derogation: manufacturers that are micro or small enterprises are not exposed to tier 2 and tier 3 fines if they only exceed the incident reporting deadline set out in Article 14 (24h/72h/final report). For everything else (security requirements, CE marking, misleading information...), the same caps apply, regardless of company size. Open source software stewards, for their part, benefit from a broader exemption.

official source - Article 64(10) ↗

📅 From when are these fines applicable?

The penalty regime (Article 64) follows the regulation's general date of application, i.e. 11 December 2027 - it is not part of the few exceptions that apply earlier (manufacturers' reporting obligations from 11 September 2026, authorities set up from 11 June 2026). In practice: as of 18 July 2026, this penalty regime is not yet in force, and no CRA fine has therefore been issued yet. This is also why we do not display an example of a real penalty here: there isn't one yet, and we will not invent one.

official source - Article 71 ↗

Reading note: fines can be combined with other corrective or restrictive measures taken by the authority for the same breach (product recall, market withdrawal...). This summary simplifies Article 64 of the regulation to make it readable in a few minutes; in case of doubt about your situation, only the consolidated text published on EUR-Lex is authoritative - to be verified with your legal counsel.

The questions a business leader really asks about the Cyber Resilience Act

No legal jargon: simple answers, each backed by the official text it is based on.

My company manufactures or sells a connected product: am I affected by the CRA?
Yes, in most cases. The official text is broad: it covers any "product with digital elements" whose intended or reasonably foreseeable use "includes a logical or physical connection, direct or indirect, to a device or a network". In practice: a connected device, a piece of software, a mobile app that talks to a server. A few product families are explicitly excluded because they already have their own security regulation: medical devices, vehicles, aeronautics, marine equipment, defence products. If you operate in one of these sectors, the CRA does not add on top, it gives way to the sector-specific text. Source: Regulation (EU) 2024/2847, Article 2 →
I only do SaaS or cloud, with no physical object: am I still affected?
No, in principle. The European text states it in black and white: cloud services (SaaS, PaaS, IaaS) fall under another text, the NIS2 directive, not the CRA. A website that does not control a connected product is also outside the scope of the CRA. The nuance worth knowing: if your cloud service is the essential building block for a connected product you sell (for example, the app that remotely controls an object you manufacture), that building block is then considered part of the product and falls under the CRA. Source: Regulation (EU) 2024/2847, Recital 12 →
Specifically, which dates should I note in my diary?
Four dates, no more. The regulation entered into force on 10 December 2024. The chapter on notified bodies (those that certify the most sensitive products) applies from the 11 June 2026. The obligation to report exploited vulnerabilities starts on 11 September 2026: this is the first deadline that really affects your day-to-day operations. The rest of the obligations (CE marking, technical documentation, security requirements) generally apply from 11 December 2027. Source: Regulation (EU) 2024/2847, Article 71 →   Source: European Commission →
If a vulnerability in my product is being actively exploited by an attacker, what do I have to do and within what timeframe?
The clock is tight. As soon as you become aware that a flaw in your product is being actively exploited, you have 24 hours to send an initial early warning to ENISA and the designated CSIRT, then 72 hours to submit a more detailed notification. The same timing logic (24h then 72h) applies in the event of a severe security incident affecting your product. This is exactly the kind of process we help you prepare in advance, so as not to discover it on the day the alert lands. Source: Regulation (EU) 2024/2847, Article 14 →
What happens in case of non-compliance, specifically, in euros?
Three tiers, depending on the severity of the breach. The heaviest: up to 15 million euros or 2.5% of annual worldwide turnover (whichever is higher), for a breach of the essential security requirements or the reporting obligation. A second tier at 10 million euros or 2% for other obligations (marking, documentation, cooperation with the authorities). And 5 million euros or 1% if you provide incorrect or misleading information to a supervisory authority. The text also provides an easing for micro-enterprises and small enterprises in case of a simple delay on a notification deadline. Source: Regulation (EU) 2024/2847, Article 64 →
My product is already on the market today: am I protected until 2027?
Partially, and it is a trap worth knowing about. A product already on the market before 11 December 2027 is only subject to the new security requirements if it undergoes a "substantial modification" after that date. But there is an important exception: the obligation to report exploited vulnerabilities (the 24h/72h one) applies to all products within the scope of the regulation, including those already sold, from 11 September 2026. In other words, the deferral to 2027 does not cover everything. Source: Regulation (EU) 2024/2847, Article 69 →
I maintain a free open source project or component: am I affected?
No, if your activity remains voluntary and non-commercial: the text explicitly excludes code contributors who do not act under their own commercial responsibility, and specifies that the development of free software by non-profit organisations is "not considered a commercial activity". However, if you are a foundation or a body that maintains a project widely reused commercially by others, a lighter, specific regime applies (the "open-source software steward" status): a documented cybersecurity policy and cooperation with the authorities, but not the full set of obligations of a standard manufacturer. Source: Regulation (EU) 2024/2847, Recital 18 and Article 24 →

The CRA calendar, explained simply

The regulation does not apply all at once: it advances in stages, over several years. Here are the dates that really matter, in order, with what they concretely mean for you. Each date links to the official text for verification.

11/24
ALREADY PASSED

20 November 2024 - publication in the Official Journal

The text of regulation (EU) 2024/2847 is published in the Official Journal of the European Union. This is the starting point of the countdown: all subsequent deadlines are calculated from this date.
official source (EUR-Lex, publication) ↗

12/24
IN FORCE

10 December 2024 - entry into force of the text

The regulation enters into force twenty days after its publication (the standard rule for European texts). The text has therefore legally existed since this date - but the vast majority of concrete obligations for companies are not yet due: they arrive in stages, see the rest of the calendar.
official source (Article 71 §1) ↗

06/26
IN FORCE

11 June 2026 - the supervisory authorities get organised

The chapter of the regulation dedicated to the bodies responsible for assessing product conformity ("notified bodies") applies from this date. This is an organisational step on the Member States' side: it is not yet a direct deadline for your company.
official source (Article 71 §2, Chapter IV) ↗

09/26
FIRST CONCRETE DEADLINE

11 September 2026 - reporting of flaws becomes mandatory

This is the first deadline that really concerns you. From this date, any actively exploited vulnerability or any serious incident affecting one of your digital products must be reported to the authorities within strict deadlines: an initial alert within 24 hours, a detailed notification within 72 hours, then a final report (14 days after the fix for a vulnerability, 1 month after the notification for an incident).
official source (Article 71 §2, Article 14) ↗

12/26
STATES' TARGET

11 December 2026 - a sufficient network of notified bodies

Member States must "endeavour" to have set up enough notified bodies to avoid administrative bottlenecks, one year before the general date of application. This is not a binding obligation for companies, but an organisational milestone on the administrations' side.
official source (Article 35 §2) ↗

12/27
MAJOR DEADLINE

11 December 2027 - most of the regulation applies

This is THE structuring date to remember. CE marking, compliance with essential cybersecurity requirements (technical documentation, vulnerability lifecycle management, security updates...): almost all of the CRA's obligations become enforceable on this date for products placed on the market.
official source (Article 71 §2) ↗

06/28
TRANSITIONAL

11 June 2028 - end of the transitional period for products already certified elsewhere

If your products are already covered by another European regulation (for example radio equipment or machinery) and already hold a cybersecurity certificate obtained under that text, it remains valid at the latest until this date, unless it expires earlier.
official source (Article 69 §1) ↗

Good to know: two rules that coexist. A product already on the market before 11 December 2027 is only subject to the new requirements if it undergoes a substantial modification after that date (Article 69 §2). But be careful: the obligation to report vulnerabilities and serious incidents (Article 14, from 11 September 2026) applies, by derogation, to all products already on the market, without exception (Article 69 §3). In other words, "already sold product" does not mean "no reporting obligation".
official source (Article 69) ↗
The countdown that matters to you, today: there is a little less than 2 months left before the flaw-reporting obligation (11 September 2026), and a little less than 17 months before the regulation's general application (11 December 2027). This is a good time to map your affected products and prepare your technical file, rather than discovering the topic at the last minute.

Who is affected, in detail: the CRA's official scope

Beyond the three roles (manufacturer, importer, distributor), here is exactly what the text says: the criterion that triggers the regulation, what is excluded from it, and concrete examples of products to help you know whether you are affected, without jargon.

The criterion used by the regulation is not a list of sectors, it is a technical criterion: connectivity. The text applies to any "product with digital elements" whose intended, or reasonably foreseeable, use includes a direct or indirect, logical or physical connection to a device or a network. An object that never connects to anything remains outside the scope; a piece of software, an app, an embedded component that talks to a network falls within it, regardless of its size or sector.
official source, Regulation (EU) 2024/2847, Article 2 §1 ↗

The three roles, in the regulation's exact words

Manufacturer

The one who develops or has developed a digital product and markets it under their name or trademark. The text explicitly states that manufacturer status applies "whether for payment, through monetisation or free of charge": offering a free product is not enough to fall outside the scope.

official source, Article 3(13) ↗

Importer

Any person established in the EU who places on the European market a product bearing the name or trademark of a person established outside the Union. An SME that resells, under its own name, connected hardware manufactured outside the EU takes on this role, with the obligations that come with it.

official source, Article 3(16) ↗

Distributor

Any person in the supply chain, other than the manufacturer or importer, who makes a product available on the EU market without altering its properties. This is the default role of a reseller or integrator who does not modify the product.

official source, Article 3(17) ↗

What is explicitly outside the CRA's scope

🏥 Medical devices and in vitro diagnostics

Already covered by their own safety regulation (Regulations (EU) 2017/745 and 2017/746): the CRA does not add on top.

official source, Article 2 §2 ↗

🚗 Type-approved motor vehicles

Covered by the type-approval regulation (EU) 2019/2144, which already addresses vehicle cybersecurity.

official source, Article 2 §2(c) ↗

✈️ Certified aeronautics

Products certified under regulation (EU) 2018/1139 on civil aviation remain under this dedicated sector-specific framework.

official source, Article 2 §3 ↗

⚓️ Marine equipment

Equipment covered by directive 2014/90/EU on marine equipment has its own regime and is outside the CRA.

official source, Article 2 §4 ↗

🔧 Identical spare parts

A replacement part manufactured to the same specifications as the original component it replaces is not a new product within the meaning of the CRA.

official source, Article 2 §6 ↗

🛡️ National defence and classified information

Products developed or modified exclusively for defence or national security, or designed to handle classified information, fall outside the scope.

official source, Article 2 §7 and §8 ↗

Concrete examples: if you manufacture or sell this, you are very likely affected

The regulation itself lists categories of products considered "important" (reinforced surveillance) or "critical" (the highest level of requirements). These are only illustrative examples among all the connected products covered, but they give a very concrete idea of the sectors targeted as a priority.

"Important" products, class I, reinforced requirements
Password managers Antivirus and anti-malware VPN software and appliances Browsers Operating systems Routers, modems, switches Identity and access management (IAM) SIEM Home voice assistants Connected locks, cameras and alarms Connected baby monitors Connected toys with a microphone, camera or geolocation Connected health wearables
"Important" products, class II, further reinforced assessment
Firewalls and intrusion detection systems Hypervisors and container runtimes Tamper-resistant microprocessors and microcontrollers
"Critical" products (Annex IV), the highest level of requirements
Hardware security boxes Smart metering gateways Smart cards and secure elements

full list, official source, Annexes III and IV of the regulation ↗

And if you are a small business? The official definition

Category Headcount Annual turnover or balance sheet total
Micro-enterprise fewer than 10 employees €2 million maximum
Small enterprise fewer than 50 employees €10 million maximum
Medium-sized enterprise fewer than 250 employees turnover €50 M maximum, or balance sheet €43 M maximum

This official definition is the one the regulation uses everywhere it mentions micro, small and medium-sized enterprises (simplified documentation, targeted derogations on the fines already detailed above). official source, Recommendation 2003/361/EC, Article 2 of the annex ↗

In practice: the connectivity criterion makes the CRA's scope very broad, and the size of your company does not take you out of scope - it mainly influences the level of documentation and certain targeted derogations. The reasonable starting point remains the same: map your products against these official criteria before acting, which is precisely the first step of our CRA-Express support.

Your supervisory authority, by country

In Europe, every country has its own authorities. Below, for the 30 countries of the European Economic Area, are the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official site.

CountryData protectionCybersecurity
AllemagneBfDI - Die Bundesbeauftragte für den Datenschutz und die InformationsfreiheitBSI - Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security)
AutricheOsterreichische Datenschutzbehorde (DSB)CERT.at
BelgiqueAutorite de la protection des donnees - Gegevensbeschermingsautoriteit (APD-GBA)Centre for Cybersecurity Belgium (CCB)
BulgarieCommission for Personal Data Protection (CPDP)CERT Bulgaria (National Cybersecurity Incident Response Team, State e-Government Agency)
ChypreOffice of the Commissioner for Personal Data Protection (Cyprus Data Protection Authority)Digital Security Authority (DSA)
CroatieAgencija za zastitu osobnih podataka (AZOP) - Croatian Personal Data Protection AgencyNational Cyber Security Centre (NCSC-HR), operating under the Security and Intelligence Agency (SOA)
DanemarkDatatilsynetForsvarets Efterretningstjeneste (FE) - Cybersituationscenter, national CSIRT (Danish Defence Intelligence Service)
EspagneAgencia Espanola de Proteccion de Datos (AEPD)INCIBE - Instituto Nacional de Ciberseguridad (Spanish National Cybersecurity Institute)
EstonieEstonian Data Protection Inspectorate (Andmekaitse Inspektsioon)Information System Authority (RIA) - National Cyber Security Centre of Estonia (NCSC-EE), heberge CERT-EE
FinlandeOffice of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)National Cyber Security Centre Finland (NCSC-FI)
FranceCNIL (Commission Nationale de l'Informatique et des Libertes)ANSSI (Agence Nationale de la Securite des Systemes d'Information)
GrèceHellenic Data Protection Authority (HDPA) - Arkhi Prostasias Dedomenon Prosopikou KharaktiraNational Cybersecurity Authority (NCSA) - Ethniki Arkhi Kyvernoasfaleias
HongrieNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - Hungarian National Authority for Data Protection and Freedom of InformationNational Cyber Security Center of Hungary (NCSC-HU / NKI), operant au sein du Special Service for National Security (SSNS)
IrlandeData Protection Commission (DPC)National Cyber Security Centre (NCSC-IE), incluant le CSIRT-IE
IslandePersonuvernd (Icelandic Data Protection Authority)CERT-IS
ItalieGarante per la protezione dei dati personaliAgenzia per la Cybersicurezza Nazionale (ACN)
LettonieData State Inspectorate (Datu valsts inspekcija)CERT.LV - Cyber Incident Response Institution of the Republic of Latvia
LiechtensteinDatenschutzstelle Fürstentum LiechtensteinCSIRT.LI (Computer Security Incident Response Team Liechtenstein / National Cyber Security Unit)
LituanieState Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija - VDAI)National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras - NKSC)
LuxembourgCommission Nationale pour la Protection des Données (CNPD)Agence nationale de la sécurité des systèmes d'information (ANSSI Luxembourg), sous le Haut-Commissariat à la protection nationale (HCPN)
MalteOffice of the Information and Data Protection Commissioner (IDPC)CSIRTMalta (Critical Information Infrastructure Protection Unit, Ministry for Home Affairs and National Security)
NorvegeDatatilsynetNSM (Nasjonal sikkerhetsmyndighet / National Security Authority) (à confirmer)
Pays-BasAutoriteit Persoonsgegevens (AP)National Cyber Security Centre (NCSC-NL)
PologneUrząd Ochrony Danych Osobowych (UODO)CSIRT NASK (CERT Polska)
PortugalComissão Nacional de Proteção de Dados (CNPD)Centro Nacional de Cibersegurança (CNCS)
RoumanieANSPDCP - Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (National Supervisory Authority for Personal Data Processing)à confirmer
SlovaquieUrad na ochranu osobnych udajov Slovenskej republikyNarodny bezpecnostny urad (National Security Authority) - SK-CERT / National Cyber Security Centre
SlovénieInformation Commissioner of the Republic of Slovenia (Informacijski pooblascenec)Government Information Security Office (GISO / URSIV - Urad Vlade RS za Informacijsko Varnost)
SuedeIntegritetsskyddsmyndigheten (IMY) - Swedish Authority for Privacy ProtectionNationellt cybersakerhetscenter (NCSC-SE), rattache a FRA, integre CERT-SE (CSIRT national)
TchéquieUrad pro ochranu osobnich udaju (UOOU) - Office for Personal Data ProtectionNarodni urad pro kybernetickou a informacni bezpecnost (NUKIB) - National Cyber and Information Security Agency

Sources: official authority websites and the list of EDPB members (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" mentions indicate an official source not yet stabilised as of this date.

Ready to map your CRA compliance?

Contact us to receive a quote tailored to your products and your situation.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu