A small Swiss company that manufactures connected thermostats, routers, industrial sensors, or even embedded software often sells part of its production in the European Union. Now the EU has adopted a regulation that changes the rules of the game for these products: the Cyber Resilience Act, or CRA. And it makes no distinction based on nationality.

What it’s about

The Cyber Resilience Act is a European regulation that imposes cybersecurity requirements on products with digital elements. This category is very broad: it covers hardware and software intended to connect to other devices or to a network. In practical terms, this ranges from laptops to smartphones, including drones, routers, smart home devices, and connected machinery.

The regulation entered into force on 11 December 2024. It does not apply all at once, however: obligations roll out in stages until it becomes fully applicable on 11 December 2027.

Why a Swiss manufacturer is affected

The essential point to understand is this: the CRA follows the product, not the manufacturer’s flag. A Swiss manufacturer that places a connected product on the EU market is treated exactly like a European manufacturer. Refusing to comply means losing access to that market.

The obligations are substantial. The manufacturer must build security in by design, carry out a continuous, documented risk assessment throughout the entire support period (at least five years), keep the technical documentation for ten years, and report actively exploited vulnerabilities as well as serious incidents. This reporting must happen within 24 hours for the early warning, then within 72 hours for the detailed report.

A vulnerability, here, means a security flaw in a product that an attacker can exploit. Most products will be eligible for self-assessment of conformity, but products deemed critical will require the involvement of a third-party body.

Deadlines to watch

Three dates matter for a Swiss exporter. From 11 June 2026, the rules on conformity assessment bodies apply. From 11 September 2026, the obligations to report vulnerabilities and incidents become mandatory. Finally, on 11 December 2027, the regulation applies fully to all products concerned.

In other words, the most immediate obligation, reporting exploited flaws, arrives in autumn 2026. That is not a distant prospect.

Deterrent penalties

Non-compliance with the CRA is not a minor matter. Administrative fines can reach 15 million euros or 2.5% of the company’s worldwide annual turnover, whichever is higher. On top of this, authorities have the power to ban or recall a non-compliant product. For an SME, this last scenario, being pulled from the market, is often the most concrete threat.

And what about Switzerland

Switzerland is not just a bystander. On 20 August 2025, the Federal Council instructed the administration to prepare a draft law on the cyber resilience of digital products. The National Cyber Security Centre (NCSC), together with the Federal Office of Communications (OFCOM) and the State Secretariat for Economic Affairs (SECO), must draw up a draft for consultation by autumn 2026.

The stated goal is twofold: to establish security rules for the design and placing on the market of digital products, while taking the European CRA into account in order to avoid conflicting standards that would penalise internationally active Swiss companies. In plain terms, Switzerland is seeking to align itself without creating a double regulatory burden.

What this means for your SME

If you manufacture or integrate connected products, anticipation is your best ally. You can already draw up an inventory of the products concerned, check whether you export to the EU, and start documenting your vulnerability management processes. This groundwork is within your reach and will save you precious time.

It does not, however, replace a detailed analysis. Determining whether a product is deemed critical, mapping your exact obligations against the deadlines, and building technical documentation that will withstand an audit are exercises that depend entirely on your product range. Every case is different, and a misinterpretation can cost you access to a market.

In perspective

The CRA marks a turning point: cybersecurity is becoming a condition for market access, on the same footing as CE marking (the certificate of conformity with European standards already found on countless products). For a Swiss manufacturer, preparing early is not one more constraint, it is a competitive advantage. Targeted support makes it possible to turn this obligation into a sales argument, rather than scrambling to meet it in the autumn of 2026.