Cyber Resilience Act: «We are in Switzerland» is not enough
A Swiss machine sold in the EU may be subject to the CRA, even if its software is located in a simple subsystem. Does your Council know which products are affected?
The calendar has already begun
Since the September 11, 2026, The manufacturers concerned must declare actively exploited vulnerabilities and serious incidents affecting the security of their products: a first warning in the 24 hours, then a more complete notification in the 72 hours. This obligation can also apply to products already marketed in the EU. Therefore, it's no longer just about preparing for 2027.
Regulations should cover products, not just cyberattacks.
The Cyber Resilience Act (CRA) is the European regulation that sets cybersecurity requirements for products containing digital elements. It requires manufacturers to integrate security into the design and development process, manage vulnerabilities, and provide updates throughout the product support period.
The main compliance requirements will apply from the December 11, 2027. Before placing a product in question on the European market, its manufacturer will notably have to assess cybersecurity risks, document the measures taken and demonstrate its compliance.
Who is affected in Switzerland?
The criterion is the product made available on the EU market, not the address of the head office. A Swiss company must therefore review the CRA if it markets, directly or through an importer, machines or equipment incorporating software that can exchange data with a device or network, directly or indirectly. The software can be located in a subsystem; the machine does not need to be presented as a "digital product.".
Software and hardware or software components sold separately may also fall within the scope. A product sold under the company's brand may engage the manufacturer's liability even if its development or manufacturing was outsourced to a third party.
Simply using digital tools within a company does not make it a manufacturer subject to the CRA. A Swiss supplier whose component is integrated into a European customer's product must, however, examine its own situation and the requirements stipulated by that customer. Certain products already subject to other European regulations are excluded: the scope is thus verified product by product.
The question to ask at the next council meeting
Can management present The list of products concerned, their role, a designated person in charge, and a compliance schedule The council should also ensure that a vulnerability can be detected, qualified and reported within current timeframes, and then ask how documentation, updates and support for products will be provided after their sale.
The CRA is thus transforming cybersecurity into condition of access to the European market and commitment to the product's lifespan. For a Swiss company concerned, waiting until December 2027 would already be too late.
Edouard Lambelet, Member of the Steering Committee, Apia Swiss
To go further
- European Commission — The Cyber Resilience Regulation: Summary of the text and obligations
- Federal Council — Strengthening the cyber resilience of digital products in Switzerland : the draft Swiss legislation and its relationship with the European CRA.
