SC ShopCompliance
Open in App Store
← All modules
New EU waves 2026+ Legal basis: Regulation (EU) 2024/2847 (CRA)

Cyber Resilience Act: Mandatory Information for Connected Products in Your Shop

The Cyber Resilience Act (Regulation (EU) 2024/2847) introduces binding cybersecurity requirements for products with digital elements for the first time. Anyone selling connected devices must transparently state support periods and security contacts.

Also relevant around CRA, cra regulation, connected product security, cyber resilience act online shop, mandatory security updates.

Deadline

The main obligations of the CRA apply from 11.12.2027. The reporting obligations for vulnerabilities take effect earlier.

What Cyber Resilience Act means

The CRA requires manufacturers of products with digital elements to provide security updates over the entire lifecycle, report vulnerabilities, and inform consumers about the security support period. Retailers must ensure that this information is available and that a reporting contact for vulnerabilities exists.

Who it applies to

Affected are manufacturers, importers, and retailers of products with digital elements, meaning hardware and software that is connected to a network directly or indirectly. This includes smart home devices, wearables, connected toys, and IoT hardware.

What must be shown in the shop

How ShopCompliance solves this automatically

ShopCompliance stores the support period and a central vulnerability reporting contact per product and renders both automatically in the product display. That way you meet the CRA information obligations without manual theme adjustments.

Implementing Cyber Resilience Act in your Shopify store

  1. 1
    Store the support period

    Enter the security support period and information on update provision for each connected product.

  2. 2
    Set up a reporting contact

    Store a central contact for reporting vulnerabilities that applies to all affected products.

  3. 3
    Display the mandatory information

    ShopCompliance renders the support period and vulnerability reporting contact automatically in the listing of connected products.

Checklist: Cyber Resilience Act

Risks of non-compliance

Products with digital elements without the required cybersecurity and information details may no longer be placed on the market once the CRA applies. Violations can trigger market surveillance measures, recalls, and fines that can be substantial under the regulation.

Legal notice: This article and the ShopCompliance templates are general information and non-binding samples, not legal advice. Content is provided automatically and not reviewed by a lawyer for your individual case. For a legal assessment of your specific situation, consult a lawyer. No warranty for completeness, accuracy or timeliness.

Meet it automatically with ShopCompliance

Activate the Cyber Resilience Act module in a few clicks. ShopCompliance manages the mandatory information centrally and renders it automatically on your storefront, no theme code.

Open in the Shopify App Store

Frequently asked questions about Cyber Resilience Act

What is a product with digital elements?+

Any hardware or software product that can establish a data connection to a device or network, such as smart home hardware, apps, or connected toys.

When does the Cyber Resilience Act apply?+

The core requirements apply from 11.12.2027. Certain reporting obligations take effect earlier in stages.

Am I affected as a retailer as well?+

Yes. Retailers must check whether the CRA mandatory information is present and may not continue to sell products without this information.

What must I show in the shop?+

At least the security support period and a contact for vulnerability reports. ShopCompliance handles the rendering.

Related compliance modules