Cyber Resilience Act (CRA): What does this mean for you as a CCV customer?
The digital world is becoming increasingly connected. Payment solutions, software, apps and online services play an important role in everyday business operations. To strengthen the cybersecurity of these products, the European Union has introduced the Cyber Resilience Act (CRA).
From 11 December 2027, the CRA will introduce mandatory cybersecurity requirements for products with digital elements placed on the European market. Manufacturers must demonstrate that their products are securely designed, that cybersecurity risks are properly managed, and that actively exploited vulnerabilities and severe security incidents are reported to the relevant authorities. These reporting obligations will already take effect on 11 September 2026. CCV is already working to implement the new requirements across our processes and payment solutions, ensuring we continue to comply with the legislation.
| Date | What does this mean? |
|---|---|
| 11 September 2026 | Manufacturers must report actively exploited vulnerabilities and severe security incidents to the relevant authorities. |
| 11 December 2027 | The Cyber Resilience Act becomes fully applicable to products with digital elements placed on the European market. |
What does this mean for you?
CCV's payment solutions already meet high cybersecurity standards. As a result, the introduction of the CRA will have little impact on your day-to-day business. The CRA provides additional assurance that:
- security is built into products from the very beginning (Security by Design);
- known vulnerabilities are actively managed;
- necessary security updates are made available;
- the support period for a product is clearly defined;
- information is available on the secure use of the product.
For CCV partners
Partners play an important role in the distribution chain. The CRA also introduces requirements for organisations that make products available to end users. This means that products must be supplied with the required documentation, instructions and conformity information. Products must also not be modified in a way that affects compliance with the legislation.
We expect our partners to:
- inform customers about the importance of installing security updates;
- pass on the documentation and instructions provided by CCV without alteration.
What is CCV doing to comply with the CRA?
Cybersecurity has long been an integral part of the development, delivery and management of CCV's payment solutions. We continuously review our processes and strengthen them where necessary to ensure full compliance with the CRA.
Our focus includes:
- Security by Design – Security is embedded into our products and services from the earliest stages of design and development.
- Risk Assessments – We perform cybersecurity risk assessments throughout the entire product lifecycle.
- Vulnerability Management – We monitor, register and remediate security vulnerabilities through a structured vulnerability management process.
- Security Updates – Where necessary, we provide security updates in a timely manner.
- Documentation and Compliance – We maintain the required technical documentation and declarations of conformity.
- Continuous Improvement – We continue to invest in processes, technology and expertise to keep our payment solutions secure, reliable and future-ready.
Would you like to learn more about how CCV safeguards the security of its payment solutions? Visit our Security | CCV EU page.
Building cyber resilience together
Cybersecurity is a shared responsibility. The Cyber Resilience Act strengthens the foundation for secure digital products across Europe. CCV remains committed to delivering secure, reliable and future-ready payment solutions, so you can continue to focus on running your business with confidence.