The Cyber Resilience Act (CRA) in relation to Pentests
Does the Cyber Resilience Act Make Penetration Testing Mandatory?
No — and yet hardly any manufacturer will get by without structured security testing. Why both are true at the same time, and what question really matters.
“Does the Cyber Resilience Act now require penetration testing?” — we’ve been getting this question for months. The honest answer is: No. And yet, for most manufacturers, there is no way around structured security testing. Both are true at the same time — and it’s precisely in this apparent contradiction that the point lies, one that many companies are still underestimating in 2026.
The Cyber Resilience Act (Regulation (EU) 2024/2847) is deliberately method-neutral. It does not name any specific testing technique — neither “penetration test” nor “fuzzing” nor “DAST” appear as […]
