← Blog

Does the CRA apply to Swiss companies?

The CRA applies to any product sold in the EU, Swiss headquarters or not. Your obligations, the Swiss bill in preparation, our answer from Le Locle (Neuchâtel).

crasecurityswitzerland

Yes, as soon as your product is made available on the European Union market. The CRA (Cyber Resilience Act, Regulation (EU) 2024/2847) attaches to the product and to the market where it is sold, not to the manufacturer’s country. A company in Neuchâtel, Vaud or Jura that sells a connected device, a firmware-driven machine or a piece of software in Germany, France or Italy is a manufacturer within the meaning of the regulation, with the same obligations as a manufacturer established in the EU.

In Le Locle, in the canton of Neuchâtel, we hear the question in three forms: we are in Switzerland, are we concerned? Doesn’t our German distributor take care of it? We only sell a component, so what? This page answers all three. For the offer itself, see CRA: turn compliance into an advantage.

➡️ Check whether your product is in scope: 3 minutes, no email


What Switzerland does not change

Three things hold, Swiss headquarters or not:

  1. The deadlines. Reporting actively exploited vulnerabilities to ENISA, the EU cybersecurity agency, applies from 11 September 2026 (Article 14: early warning within 24 hours). The technical requirements of Annex I (secure design, component inventory, vulnerability handling throughout the support period) will apply from 11 December 2027.
  2. No SME exemption. The regulation sets no size threshold. A ten-person company exporting a product in scope has the same obligations as a group.
  3. CE marking. From December 2027, your EU declaration of conformity will also have to cover the CRA. You keep your CE marking, and the access to the European market that comes with it, by building these requirements into your development chain rather than into a binder.

Your obligations by case

The regulation distinguishes roles. Three situations cover most of the Swiss companies we meet.

You sell directly to customers in the EU

You are the manufacturer (Article 13). The product’s conformity is on you: assessment, technical documentation, CE marking, vulnerability handling during the support period and reporting to ENISA from September 2026. You may appoint a representative established in the EU to keep the documentation available to the authorities (Article 18); it is not an obligation, and it does not transfer your responsibility. A representative keeps a file, it does not fix your firmware.

You go through a European importer or distributor

Your partner has obligations of their own (Articles 19 and 20): they must verify that you carried out the conformity assessment, compiled the technical documentation and affixed the CE marking, and they cannot place a product on the market that does not meet these requirements. In practice, they are the ones who will ask you for the evidence: component inventory (SBOM, Software Bill of Materials), vulnerability handling policy, EU declaration of conformity. Without these documents, your product may sit on the loading dock, and you are not the one deciding when it leaves.

You supply a component or software integrated by a European manufacturer

Your customer is the manufacturer of the final product; the regulation requires them to exercise due diligence on the components they integrate (Article 13). They will therefore ask you for the same things: an up-to-date SBOM, a channel to report and fix vulnerabilities, a commitment on updates. Answering fast, and with evidence, becomes a criterion for staying on their supplier panel. Put differently: the supplier who sends their SBOM the same day keeps their place in the bill of materials.


What if you only sell in Switzerland?

The CRA does not apply directly to a product that stays on the Swiss market. Two points still deserve your attention:

  • Switzerland is preparing its own law. On 20 August 2025, the Federal Council tasked the Federal Office for Cybersecurity (NCSC), together with OFCOM and SECO, with preparing by autumn 2026 a draft bill on the cyber resilience of digital products, taking the CRA into account. Security requirements, market surveillance and a ban on importing insecure devices are part of it.
  • Your Swiss customers export. A Swiss integrator or manufacturer selling into the EU will ask you for the same evidence as a European customer.

Building your development chain on the CRA requirements today therefore also puts you ahead of Swiss law: one method for both markets, and no second project in two years.


CRA compliance in Neuchâtel, the Jura and French-speaking Switzerland: where we work

ADNT is based in Le Locle, in the canton of Neuchâtel, ten minutes from La Chaux-de-Fonds, at the heart of the Jura Arc and its industries: watchmaking, microtechnology, instrumentation, medical devices. In other words, products that carry firmware and ship to Europe. We travel across French-speaking Switzerland: Neuchâtel and La Chaux-de-Fonds, Vaud (Lausanne, Yverdon-les-Bains, the Riviera), Jura, Biel/Bienne and the Bernese Jura, Fribourg, Geneva. For the rest of Switzerland and customers established in the EU, we work remotely, directly in your development chain and your code: a pipeline does not need us in the same room.

Our way of working is detailed on the offer page: a free one-hour first read, then a fixed-fee industrialisation plan and, if you wish, its implementation inside your existing continuous integration chain.

See the CRA offer and indicative budget →


Frequently asked questions

Does a Swiss company have to appoint a representative in the EU?

No. It is an option provided for in Article 18, not an obligation. The representative keeps the documentation available to the authorities and cooperates with them; responsibility for the product remains yours.

Is my European distributor liable in my place?

No. The importer and the distributor have their own verification duties (Articles 19 and 20), but the conformity assessment, the technical documentation, the CE marking and vulnerability reporting remain the manufacturer’s responsibility.

Is my current CE marking enough?

Not beyond December 2027: the EU declaration of conformity will have to cover the cybersecurity requirements of Annex I of the CRA, on top of the texts you already apply. Reporting under Article 14, for its part, applies from 11 September 2026, including to products already shipped.

Is a product sold only in Switzerland concerned?

Not by the CRA. But a Swiss bill aligned with the CRA is in preparation (draft expected in autumn 2026), and your Swiss customers who export will ask you for the same evidence.

Is there mutual recognition between Switzerland and the EU for the CRA?

Not to date. The CRA is a recent EU regulation; absent a specific agreement, a Swiss manufacturer is treated like any manufacturer established outside the EU.

You are in Le Locle: do you work outside the canton of Neuchâtel?

Yes. From Le Locle, we cover all of French-speaking Switzerland (Neuchâtel, Vaud, Jura, Bern, Fribourg, Geneva) on site, and we work remotely for the rest of Switzerland and customers established in the EU.


References