"Cybersecurity is an abstract IT topic, it has nothing to do with the physical protection of people."
I hear this from manufacturers preparing for the EU Cyber Resilience Act (CRA), and it reveals a fundamental misconception about what the CRA actually regulates. Because the CRA is not a pure IT security law. It is a product safety law. And the difference matters.

What does "vulnerable consumers" mean in the CRA?
The CRA follows the New Legislative Framework (NLF), the EU framework for product safety that also sits behind CE marking, the Machinery Regulation, and the Toy Directive. That means the central question is not whether a product is "digital", but what risks it brings for people.
CRA Annex III classifies products into two categories of important products (class I and class II) and a group of critical products. The decisive criterion for the classification is risk potential. The question of who uses the product plays a central role here.
Connected toys, baby monitors, and health monitoring wearables are explicitly listed in Annex III as important products class I. Not because they contain particularly complex software, but because their user groups, children, patients, elderly or sick people, are particularly vulnerable. An attack on these devices hits people who can hardly protect themselves.
The legislator has thereby made a clear statement: cybersecurity is not an abstract IT property. It is a safety feature with direct impact on life and limb.
Why equating "digital" with "abstract" is dangerous
Many manufacturers think about cybersecurity in categories of enterprise security: data loss, operational disruption, reputational damage. Those are legitimate risks, but they describe only part of the harm picture.
For products with direct access to vulnerable people the harm picture is different.
A hacked baby monitor can be used to surveil or manipulate infants. A compromised health wearable can deliver false readings and skew medical decisions. A connected toy can be misused to locate, eavesdrop on, or interact with a child, without the parents' knowledge.
These are not theoretical scenarios. There are documented incidents with connected toys where attackers were able to establish voice connections with children. The CRA responds to a reality that already exists, and draws regulatory consequences from it.
Manufacturers that underestimate this connection risk more than just fines. They risk placing products on the market that put concrete people in concrete danger.
Myth vs. fact
Myth: Cybersecurity is an abstract IT topic with no connection to the physical protection of people.
Fact: The CRA explicitly treats cybersecurity as a product safety feature. Vulnerable consumers are a central classification criterion. Connected toys, baby monitors, and health wearables count as important products class I, with correspondingly elevated requirements for conformity assessment, vulnerability management, and update obligations.
Concrete consequences for manufacturers
1. Check product classification before development starts. Whether your product falls under important products class I is not a question that can be settled at the end of development. The classification influences the entire conformity assessment procedure. Manufacturers of important products class I cannot rely on self-assessment alone. They must apply harmonised standards or go through a third-party procedure with a notified body. Note: harmonised standards for the CRA have not been adopted as of May 2026. As long as they are missing, the path through a notified body is in practice the relevant option. That costs time, resources, and planning. It does not work retroactively. Check early which Annex III categories may apply to your product. In doubtful cases a legal opinion is advisable. The CRA leaves interpretive room in some places, but the categories for vulnerable users are comparatively clearly worded. For an overview of the full conformity procedure, see our article on CRA conformity assessment and CE marking.
2. Establish vulnerability management as an ongoing process. For important products class I it is not enough that they are secure at the moment of placing on the market, the first actual availability on the EU market. The CRA obliges manufacturers to actively monitor and remediate vulnerabilities across the entire pre-declared product lifetime. For a toy that sits in a child's room for five years, that means five years of active vulnerability management. This is not a one-time effort, but a continuous operational process. For more on structuring this process, see our guide to vulnerability management under the CRA.
3. Plan update delivery as a product feature. Security updates are not a voluntary service under the CRA, they are a legal duty. Manufacturers must ensure that updates can be reliably installed on the device, and that users are informed about them. For products used by vulnerable people this is particularly critical. An un-patched vulnerability in a child monitoring device is not a comfort issue, it is a safety risk. Plan update mechanisms from the start, as an architectural decision, not as a retrofitted feature.
What does this mean for your CRA roadmap?
Two deadlines drive CRA compliance planning.
11 September 2026: The reporting duties enter into force. Manufacturers must report actively exploited vulnerabilities and severe incidents to the competent authorities, in Germany the BSI, at EU level ENISA (the EU Agency for Cybersecurity). Anyone who has not built functioning vulnerability monitoring by then risks breaching reporting duties without noticing.
11 December 2027: Full CRA applicability. From that date, only compliant products may be placed on the market. For important products class I that means conformity assessment completed, technical documentation complete, CE marking lawfully affixed.
Both deadlines are closer than they appear. The conformity assessment for an important class I product is not a two-week project. Anyone who has not started structured preparation by 2026 will be under pressure in 2027. For a detailed view of the milestones, see our CRA compliance roadmap.
Frequently asked questions
Does every connected toy automatically fall under important products class I? Yes, if it qualifies as a "connected toy" in the sense of CRA Annex III. The category is explicitly listed in the CRA. What matters is whether the product is designed as a toy for children and has a network connection, not whether it is primarily marketed as a toy or as an IoT device. In doubt: if the product is used by children and transmits data, you should assume important products class I.
What does "third-party conformity assessment" specifically mean for manufacturers of important products class I? Manufacturers of important products class I have two paths. They either apply fully harmonised European standards and can then, under certain conditions, perform self-assessment, or they go through a conformity assessment procedure with a notified body. In practice this means more effort compared to standard products, which can rely on self-assessment alone.
Important note on the current state (May 2026): Harmonised standards for the CRA do not yet exist. They have not been adopted so far. As long as that is the case, the path via harmonised standards is practically not open to manufacturers of important products class I. In this transition phase they must either go through a notified body or choose other suitable evidence procedures. This state can change once the EU Commission recognises corresponding standards.
A frequently mentioned example in the industry is IEC 62443, the family of standards for cybersecurity in industrial automation. It is expected not to be among the harmonised standards under the CRA initially. Manufacturers betting on IEC 62443 conformity today should therefore not assume that this standard automatically simplifies or replaces the CRA conformity assessment. This may change long-term, but is not certain at the moment.
Does the update duty also apply when the product is no longer actively sold? Yes. The duty to provide security updates applies for the full product lifetime, so not only as long as it is on sale, but as long as it can be in use. Manufacturers must declare the expected product lifetime in advance and ensure they can deliver updates during that period.
Is a health wearable that does not transmit medical data still relevant under the CRA? Yes. CRA classification does not depend on whether the device transmits medical data or is regulated as a medical device. If a wearable is designed for health monitoring, for example measuring vital signs and connecting to a network, it falls under the important products class I category in CRA Annex III. The Medical Devices Regulation (MDR) may also apply additionally, but that is a separate regulation.
What happens if I misclassify my product's status as important class I? Significant exposure. The CRA provides for fines of up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. On top of that comes a market ban for non-compliant products. For more on sanctions, see our article on CRA penalties for non-compliance.
Conclusion
The CRA is not an IT law. It is a product safety law that treats digital risks as physical risks, because in many cases that is exactly what they are. Anyone developing products for children, patients, or other vulnerable groups carries elevated responsibility. Legally through the classification as an important product class I, and morally through the reality of what a safety failure in these products can cause.
If you are not yet sure which class your products fall into, and what that means concretely for your conformity procedure, now is the right time for a structured inventory. A free CRA assessment helps systematically place your own product landscape, before the deadlines tip from calendar into practice.
Every Friday I debunk a CRA myth here.