Compare / CRA vs Cyber Trust Mark
Regulation comparison
CRA vs Cyber Trust Mark
Same product category, opposite philosophies. The CRA is mandatory, lifecycle-long and penalised; the Cyber Trust Mark is voluntary, point-in-time and a retail badge. A device can carry the mark and still be unsellable in the EU, and vice versa.
| EU Cyber Resilience Act | US Cyber Trust Mark | |
|---|---|---|
| Applies when | Any product with digital elements placed on the EU market, consumer or industrial | Consumer wireless IoT sold in the US, by choice |
| Who demands it | Market access, mandatory (CE marking) | Retail shelf positioning; no legal duty |
| What it is | Regulation | Voluntary label |
| Scope | Security by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period | FCC labelling programme modelled on Energy Star; testing against NIST IR 8425 criteria by accredited labs |
| In force | In force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027 | Programme launched Jan 2025 |
| Penalties | Up to EUR 15M or 2.5% of global turnover | None; misuse of the mark is an FCC matter |
| Authoritative text | CRA text โ ยท on this site | Cyber Trust Mark text โ |
What a product team should do
For a US-first consumer launch the mark is a marketing decision; for an EU launch the CRA is a legal one. Engineering for the CRA will exceed the NIST IR 8425 criteria the mark tests against.
Check your own product
The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.
Sources: EU Cyber Resilience Act (official text) and US Cyber Trust Mark (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.
โ All comparisons