The European Union is prioritising the security of all products with digital elements as well as the protection of end-users with a view to safeguard our shared connected ecosystem from cyber threats.
ENISA works to strengthen cybersecurity by promoting secure by design and secure by default principles in the EU market. With this approach, the Agency aims not only to support the implementation of regulatory provisions but also to foster trust and strengthen the overall cyber resilience of the EU Digital Single Market.
Among its key initiatives is the publication of regular Technical Advisories on product security. Technical Advisories provide practical, actionable guidance to help organisations address emerging cybersecurity risks, implement secure by design practices over the entire development lifecycle and support the consistent implementation of the CRA.
The Cyber Resilience Act (CRA) is the EU’s horizontal regulatory framework that sets out the guidelines and requirements to make sure that devices are all designed, updated, and maintained in a uniform way where security comes first. The Act introduces mandatory cybersecurity requirements that should be met throughout products’ lifecycle, with the main obligations introduced applying from 11 December 2027.
ENISA operates and maintains the CRA Single Reporting Platform (SRP), a technical tool for the reporting of actively exploited vulnerabilities and incidents impacting products with digital elements operating in the EU Digital Single Market. ENISA has been also tasked to prepare bienniallya technical report on emerging trends regarding cybersecurity risks in products with digital elements.
Micro, Small, Medium Enterprises (SMEs)
Micro, Small and Medium Enterprises (SMEs) make up a large part of the EU´s digital ecosystem. Since SMEs account for the vast majority of EU manufacturers, they play a central role in the EU economy.
As the CRA introduces new cybersecurity requirements for products with digital elements, their ability to understand and enforce those requirements is critical to its successful implementation. Supporting SMEs is a priority for ENISA, and the Agency is committed to helping them build the knowledge and capabilities needed to meet these obligations.
This is particularly important as smaller organisations often face practical challenges related to limited resources, expertise, time and implementation capacity.
To help address these challenges, ENISA provides practical guidance, tools and support activities tailored to the needs of smaller organisations, also as part of the European Commission's SME cybersecurity strategy.
Explore our publications
![]() |
![]() |
![]() |
![]() |



