← Back to CRA Insights
CRA and other regimes

CRA vs. US Cyber Trust Mark: A Manufacturer's Side-by-Side Guide

Generated image

If your company makes connected products and sells them on both sides of the Atlantic, you are now operating under two distinct cybersecurity frameworks - one mandatory, one voluntary, and both demanding real engineering effort. Understanding where they diverge, and where they share common ground, is the fastest way to avoid duplicating work.

This article is general guidance on the Cyber Resilience Act and the US Cyber Trust Mark program, not legal advice. Confirm specifics against Regulation (EU) 2024/2847 and the FCC's official program page.


The short version

TL;DR for dual-market manufacturers

CRA: Mandatory EU law. Applies to all products with digital elements. Full application from 11 December 2027, with vulnerability reporting obligations from 11 September 2026. Fines up to €15 million or 2.5% of worldwide annual turnover.

Cyber Trust Mark: Voluntary US FCC labeling program. Applies to wireless consumer IoT products only. No penalty for not participating — it's a market differentiator. ioXt Alliance named Lead Administrator in April 2026.

The overlap: Secure-by-design practices, vulnerability handling, and SBOM-adjacent documentation are required or strongly encouraged by both. CRA compliance work carries over.


1. Legal status: mandatory vs. opt-in

This is the most fundamental difference.

The CRA is a regulation - directly binding in all EU Member States. Regulation (EU) 2024/2847 entered into force on 10 December 2024 and applies in full from 11 December 2027. There is no opt-out. If your product has digital elements and you place it on the EU market, you must comply. The obligation falls on whoever puts the product on the market - manufacturer, importer, or distributor - regardless of where they are headquartered.

The US Cyber Trust Mark is a different animal entirely. In March 2024, the FCC established a framework for a voluntary cybersecurity labeling program for consumer wireless IoT products. Participation is entirely optional. Not carrying the label does not prevent you from selling in the United States. The program's logic is market pull, not legal compulsion: consumers who recognise the shield logo may prefer labeled products, creating a commercial incentive for manufacturers to seek it.

One nuance worth noting: a June 2025 Executive Order means that by January 4, 2027, all vendors supplying consumer IoT products to the US government will be required to carry the Cyber Trust Mark. For manufacturers targeting federal procurement, "voluntary" is becoming a more complicated word.


2. Scope: broad vs. narrow

The CRA casts a deliberately wide net. Products with digital elements are defined as any software or hardware product - including remote data processing solutions - that can be directly or indirectly connected to a device or a network. That definition captures consumer smart devices, B2B software, industrial systems, mobile applications, operating systems, and software libraries. The German Federal Office for Information Security (BSI) puts it plainly: the CRA covers everything from low-cost consumer gadgets to complex high-end industrial systems, unless a specific exclusion applies (medical devices and vehicles have their own regimes).

The Cyber Trust Mark is narrower by design. It applies to wireless consumer IoT products - think smart thermostats, baby monitors, connected appliances, and home security cameras. It does not cover enterprise or industrial IoT, wired-only devices, or software products without a hardware component. If your product is a B2B gateway or an embedded industrial controller, the Cyber Trust Mark is simply not relevant to it, even if the CRA is.

Scope comparison at a glance
DimensionEU CRAUS Cyber Trust Mark
Legal basisRegulation (EU) 2024/2847FCC rulemaking (PS Docket 23-239)
Mandatory?Yes — market access requirementNo — voluntary (except federal procurement from Jan 2027)
Products coveredAll products with digital elements (hardware + software)Wireless consumer IoT products only
Geographic reachEU market (all 27 Member States)US market
Key deadline11 Sep 2026 (reporting); 11 Dec 2027 (full application)Program accepting applications once FCC announces readiness
Enforcement bodyNational market surveillance authorities in each Member StateFCC; third-party Cybersecurity Label Administrators (CLAs)
Penalty for non-complianceUp to €15M or 2.5% of worldwide annual turnoverNone (loss of label eligibility only)
Technical baselineAnnex I essential requirements; harmonised standards under M/606NIST IR 8425 (IoT Core Baseline for Consumer Products)

3. Enforcement and penalties

The CRA has teeth. Article 64 sets three penalty tiers, each expressed as the higher of a fixed ceiling or a percentage of worldwide annual turnover:

  • Tier 1 - €15 million or 2.5% of worldwide annual turnover: Breaching the essential requirements in Annex I, or the obligations in Articles 13 (manufacturer duties) and 14 (vulnerability and incident reporting).
  • Tier 2 - €10 million or 2%: Other obligations under the regulation.
  • Tier 3 - €5 million or 1%: Providing incorrect, incomplete, or misleading information to authorities.

Micro and small enterprises are exempt from fines for missing the 24-hour early-warning reporting deadline; open-source stewards are also not fined. But for most commercial manufacturers, the exposure is real. Market surveillance authorities in each Member State will have the power to require conformity demonstrations, order product withdrawals, and impose fines. The fine ceiling is high enough that product security needs to be a board-level concern.

The Cyber Trust Mark carries no financial penalty for non-participation. The enforcement mechanism is reputational and commercial: if a product is found to misuse the label, the CLA can revoke authorization. For the vast majority of manufacturers, the risk calculus is about market differentiation, not regulatory exposure.


4. Where the work overlaps - and how to carry it over

Despite the structural differences, the underlying security practices demanded by both frameworks are strikingly similar. This is where dual-market manufacturers can be smart about effort.

Secure-by-design

The CRA mandates security by design as a core obligation under Annex I. The Cyber Trust Mark, drawing on NIST IR 8425, similarly expects manufacturers to establish a company-wide security process from the earliest stages of development. The NIST IR 8425 consumer profile requires manufacturers to create, gather, and store information relevant to the cybersecurity of the IoT product and its components prior to customer use and throughout the product's entire lifecycle. If you have built a CRA-compliant secure development lifecycle, you have already done the heavy lifting for Cyber Trust Mark eligibility.

Vulnerability handling and disclosure

The CRA requires manufacturers to handle vulnerabilities actively throughout the support period and to report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware. The Cyber Trust Mark requires manufacturers to maintain a coordinated vulnerability disclosure policy and to keep the product's registry entry updated with public disclosures for all fixed security vulnerabilities. The underlying process - triage, patch, disclose - is the same. Document it once; it serves both.

SBOM-adjacent documentation

The CRA requires manufacturers to maintain a software bill of materials (SBOM) as part of their technical documentation. The Cyber Trust Mark's registry data elements require disclosure of whether the manufacturer maintains an SBOM or HBOM. The FCC's IoT Labeling Order (FCC 24-26) requires registry data element 10 to include disclosure of whether the manufacturer maintains a Hardware Bill of Materials (HBOM) and/or a Software Bill of Materials (SBOM). CRA-driven SBOM work therefore directly supports Cyber Trust Mark registry obligations.

Support period transparency

Both frameworks require manufacturers to communicate clearly how long security updates will be provided. The CRA mandates this as part of the information accompanying the product. The Cyber Trust Mark requires a formal attestation to the CLA specifying the product's defined software security support period. Same commitment, two disclosure channels.

lightbulb Tip

Practical sequencing for dual-market manufacturers: Build your CRA compliance backbone first — it is mandatory, the deadlines are fixed, and the penalties are real. Once your secure-by-design process, vulnerability handling procedure, SBOM, and support-period documentation are in place, assess your consumer wireless products against NIST IR 8425. The delta is likely smaller than you expect.


5. The interactive check: does your product qualify for both?

Use the widget below to quickly assess whether a given product sits under the CRA, the Cyber Trust Mark, or both - and what the priority actions are.


6. Program status as of mid-2026

A brief operational update on each framework:

CRA: The CRA vulnerability and incident reporting obligations apply from 11 September 2026, with full product compliance required from 11 December 2027. ENISA's Single Reporting Platform is being stood up ahead of the September deadline. Harmonised standards under mandate M/606 are still being finalised, meaning most manufacturers are currently working directly against Annex I essential requirements.

Cyber Trust Mark: The program has had some administrative turbulence. UL Solutions withdrew as Lead Administrator in December 2025. ioXt Alliance was named as Lead Administrator of the US Cyber Trust Mark program, effective April 13, 2026. The FCC has indicated it will announce when the program is ready to accept product applications. Manufacturers should monitor fcc.gov/CyberTrustMark for that announcement.


What to do next

For manufacturers selling in both markets, the priority order is clear: the CRA is mandatory and the clock is running. Start by confirming whether your products are in scope and what class they fall into.

info Note

Not sure if your product is in CRA scope? Use our CRA scope and class checker to get a fast, structured answer — it covers product classification (Default, Important Class I/II, or Critical) and flags which conformity assessment route applies.

For monthly plain-English updates on CRA deadlines, harmonised standards, and implementing acts, subscribe to The CRA Brief.


This article is general guidance only, not legal advice. The regulatory landscape for both frameworks is still evolving. Always verify current requirements against Regulation (EU) 2024/2847 and the FCC's Cyber Trust Mark program page.