|
||
|
||
The EU Cyber Resilience Act is being publicly promoted by the European Commission “to make sure all digital products are safe from cyber threats.” Initial reporting obligations came into effect a few weeks ago. The remainder will apply from December next year. The vast mandatory obligations with severe non-compliance penalties apply to all producers and distributors of all the world’s “digital elements” including remote processes that may potentially enter the EU market. The economic impacts of the requirements are enormous—potentially in hundreds of billions of Euros.
The endgame of the CRA is the imposition of an EU CRA Compliance Firewall around the Union’s geopolitical boundaries to prevent the delivery of digital elements that have not complied with the thousands of still evolving, ever expanding costly requirements. Aside from the blatant human rights abridgements, lack of transparency and ludicrous impossible assertions about the benefits of the CRA, the unlawful economic effects have only been lightly treated. That is beginning to change.
The European Commission’s only treatment of CRA economic costs were superficially undertaken almost five years ago prior to availability of the original proposal. To sell the world’s most expansive cybersecurity regulatory regime in September 2022, the EC CRA Proposal asserted that the estimated global annual cost of cyber crime was EUR 5.5 trillion in 2021, that aggregated compliance costs would be about EUR 29 billion, and would “lead to a cost reduction” of EUR 180 to 290 in saved incident reduction costs. No details were provided, and the amounts appeared to be simply made up as vague assertions to advance the proposal.
No other economic analysis appears to have been undertaken, and 2021 was before a considerable number of impacting technology, market evolution, and amendments to the CRA were made. Nor was any analysis or rationale given for singling out 38 “critical product” markets enumerated for extensive costly requirements—many of them utterly vague—other than the assertion that they were “high risk”. It is apparent, however, that most of these markets are those largely occupied by U.S. vendors.
The fundamental economic norms of the European Union are primarily implemented at the highest level through the formative EU treaty provisions known as the TFEU regarding proportionality and competition. However, the only treatment of proportionality in the original CRA proposal consists of several vague assertions—plus one that is plainly false. Notably, the EC asserted that “the intervention considered would ensure that products with digital elements would be secured throughout their whole life cycle…” It is simply not possible to ensure digital products are secured because of their inherent complexities and degree of security that is constantly evolving is primarily dependent on the context and end user.
Notwithstanding the enormous monies involved and the questionable efficacy of many of the requirements, the EC summarises its proportionality assertion with the hand-waiving remark that “any compliance costs for businesses would be outweighed by the benefits brought by a higher level of security of products with digital elements and ultimately an increase of trust of users in these products.”
The EU treaty provisions on competition are extensive and prohibit “practices…that prevent, restrict, or distort competition within the internal market.” However, the potential significant adverse impacts on competition of the CRA practices were simply brushed away with meaningless comments that competition will be monitored and that “the impact on SMEs would depend on their presence in the market of these specific product categories.” A key EU legislator recently noted the potential exclusion of U.S. companies from the EU market if they “didn’t have a good track record in following EU rules.”
Over the past four years as the attempt to implement the CRA’s provisions have unfolded, no subsequent analysis or even attempts to meet the fundamental economic norms in the EU Treaty have occurred. This omission has ensued even as the scores of requirements in the enacted CRA regulations have grown to many thousands of requirements by serial references via the EC employing specification writers who toil away in obscure groups under CEN/CENELEC and ETSI. The 41 specifications now contain thousands of constantly recurrent testing, certification, and notification requirements that are imposed on every new digital product/remote process or significant iteration for its lifetime.
There is no differentiation among the requirements that address the significant variances in available product provider resources required for compliance—thus significantly skewing competition and potentially putting SMEs out of business. The requirements come into effect in December 2027 - enforced through broad surveillance powers and enormous non-compliance penalties.
The EC implementing instrument for this enormous undertaking requires the deliverables are “in conformity with the legal framework of the Union and its objectives and values” and “builds consensus among all interested parties” and “the utmost transparency”. Yet no proportionality cost-benefit analysis, consideration of resources of those required to comply, or effects on competition has occurred or enforced.
As the CRA’s implementation dates have grown closer, a number of quantitative analyses of the economic effects as well as costs of specific actions have emerged from diverse parties.
In April 2023, the UK Parliament in a report on the CRA flagged multiple concerns—noting that “there is also a likely, and potentially costly, impact of the CRA for British businesses exporting digital products to the EU”.
In July 2023, one of the world’s largest regulatory research firms, UK based Frontier Economics Ltd., published an extensive 46-page research report—Assessing the Economic Impact of EU Initiatives on Cybersecurity. Covering both the NIS2 and CRA, it treated costs, impacts on prices, trade implications, enforcement costs, and impacts on innovation and competition. Notably, the report also considered the negative economic effects on the EU resulting from inhibiting transfer of technology, innovation, competition from overseas supplier investment. Without having access to the full expanded array of thousands of additional requirements, the report was unable to develop an estimate of CRA compliance costs. However, NIS2 compliance costs were estimated at Euros 31 billion and a negative effect on European GDP of Euros 9 billion.
In July 2025, the Computer & Communications Industry Association (CCIA), published a report from its research center that even in advance of the CRA specifications, the costs and revenue loss for American companies alone for new EU digital services regulation could approach 100 billion dollars annually.
In January 2026, the Spanish company CRA Evidence published its exhaustive Framework for CRA Compliance Cost. The Framework was based on baseline CRA requirements rather than the full suite of 7,000 extended requirements yet to be finalised. Its summary notes that “CRA compliance costs range from € 20K (simple product, self-assessment) to over € 500K (complex product, third-party assessment)”. “An industrial firewall requiring a Notified Body will spend € 200,000—500,000 before you count ongoing obligations.” The CRA Evidence Framework provides a useful structure for analysing one-time and ongoing costs with breakdowns of the variations in different European countries. Even original CRA baseline self-assessment costs of simple IoT sensor was estimated at an initial cost up to EUR 80,000 and annual ongoing costs of up to EUR 90,000.
Several years ago, the Czech company I46.S.R.O began analysing CRA compliance costs and providing implementation advisories. It now hosts the site CyberResilienceAct.EU to provide a CRA compliance cost calculator and blog. Its estimates, however, are not based on the thousands of extended harmonised standards. It estimates a default one-off cost of € 78,300 for a basic digital product and an ongoing per year cost of € 13,500 for maintaining compliance. A critical product class—which includes a large number of ordinary products—raises the amounts to € 147,900 and € 37,000, respectively.
The EC has a record for spending large sums of money for grand cybersecurity schemes that do not work. However, the CRA involves compelled spending of enormous sums of other people’s money. The only assured significant benefactors are the approved European certification authorities who get to charge for their services forever at the expense of all the world’s digital product manufacturers.
The new third-party economic analyses—some of which are quite detailed—underscore the lack of a credible excuse for the EC and their contractors who have produced nearly 4,000 pages of extended CRA requirements, not also doing due diligence analysis of the cost-effectiveness and competitive effects of the deliverables they are authoring. Long-standing economic norms long established in fundamental European law, international treaty instruments and equivalents in other nations should not be ignored.
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byCSC
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byRadix