Cyber Resilience Act
Cyber resilience regulatory sandboxes
Practical term
Cyber resilience regulatory sandboxes are controlled testing environments for innovative products with digital elements. Their job is to make development, design, validation and testing easier for a limited period before placing on the market, and expressly for the purpose of complying with the Cyber Resilience Act (CRA). A single paragraph governs them, Article 33(2).
That paragraph sits inside an article on support measures for microenterprises and small and medium-sized enterprises, including start-ups, which shapes what a sandbox is. It is not an authorisation procedure and not a testing body, but an offer a Member State is free to make.
What Article 33(2) lays down
The paragraph makes seven statements and no more:
- Member States may, where appropriate, establish cyber resilience regulatory sandboxes.
- What they provide are controlled testing environments for innovative products, limited to a period before the product is placed on the market.
- The Commission and, where appropriate, ENISA may provide technical support, advice and tools for setting a sandbox up and running it.
- Sandboxes are set up under the direct supervision, guidance and support of the market surveillance authorities.
- Member States inform the Commission and the other market surveillance authorities of an establishment through Administrative cooperation group (ADCO).
- The supervisory and corrective powers of the competent authorities are unaffected.
- Access must be open, fair and transparent, and access by micro and small enterprises, including start-ups, must be facilitated.
“May” means may
The discretion lies in the setting up, not in the rest. Whether a Member State creates a sandbox is its own choice. Once it has, the duties in the same paragraph bite: the sandbox is set up under the direct supervision, guidance and support of the market surveillance authorities, the establishment must be notified to the Commission and the other market surveillance authorities through ADCO, and access must be kept open, fair and transparent.
The contrast with paragraph 1 of the same article is about exactly that point: there Member States shall, where appropriate, run awareness raising and training, open a dedicated communication channel and support testing and conformity assessment activities. Sandboxes, by contrast, they may establish where appropriate.
The Regulation names no minimum number and sets no deadline. The CRA applies from 11 December 2027, and a Member State may still get by with no sandbox at all after that date. Building a product plan around one means relying on a commitment that was never given.
No safe harbour
A sandbox suspends no obligation. The paragraph says so itself: the supervisory and corrective powers of the competent authorities remain untouched. There is no derogation from the essential cybersecurity requirements, no extended deadline and no presumption of conformity.
Everything that would otherwise be due before placing on the market is still due: the applicable conformity assessment procedure under Article 32, the technical documentation under Article 31, the EU declaration of conformity and the CE marking. Feedback obtained in a sandbox is not a certificate and substitutes for none of those steps.
Who gets in
The paragraph applies two yardsticks, one to the participants and one to the product. On access, Member States must ensure openness, fairness and transparency, and in particular facilitate access by micro and small enterprises, including start-ups. That is not a restriction to such companies: recital 97 gives improved legal certainty for all actors within the scope of the Regulation as an objective. Whether a company belongs to the group whose access is facilitated follows from the size classification for micro, small and medium-sized enterprises in Article 3, point (19), not from any decision of the sandbox.
The product has to be “innovative”. The CRA never defines that word, Article 3 included. What counts as innovative is therefore left to national practice.
Testing without a sandbox
Two routes are open regardless, and neither involves an authority. Under Article 4(2), Member States may not prevent the presentation or use of a non-compliant product at trade fairs, exhibitions, demonstrations or similar events, prototypes included, provided a visible sign clearly indicates that it does not comply. Article 4(3) allows unfinished software to be made available in the same spirit, for the limited period required for testing and with the same visible sign.
One exception sits in paragraph 4: paragraph 3 does not apply to safety components within the meaning of Union harmonisation legislation other than the CRA.
What the Regulation leaves open
Article 33(2) lays down no procedure. There are no eligibility criteria, no application or admission route, no maximum length for the “limited period”, no exit report and nothing at all about cost.
The comparison with paragraph 5 of the same article is instructive. For the simplified technical documentation form, the Regulation obliges the Commission to adopt an implementing act under the examination procedure in Article 62(2). For sandboxes it imposes no such duty. Support from the Commission and ENISA is drafted as a possibility, with no deadline and no minimum scope, and ADCO serves as the channel for notifying an establishment rather than as an approving body.
Practical questions
-
Article 63(1) binds all parties involved in the application of the Regulation to confidentiality, and it names intellectual property rights, confidential business information and trade secrets expressly including source code. The only carve-out is the cases referred to in Article 5 of Directive (EU) 2016/943. The CRA contains no confidentiality rule specific to sandboxes. What gets logged during operation, who may read those records and how long they are kept all follow from national arrangements, so ask before you sign up.
-
The text is silent. Article 33(2) sets out no fee rule, neither a ceiling nor a prohibition on charging. The reduction in Article 32(6) does not help here, because it covers fees for conformity assessment procedures rather than the running of a sandbox. Article 33(4) only requires the Commission to advertise financial support available under existing Union programmes. Whether participation carries a price is therefore decided by the Member State that sets the sandbox up.
-
Both may be open to you, and they belong to different legal acts. Article 12(4) CRA confirms that manufacturers of products with digital elements classified as high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 may take part in the AI regulatory sandboxes referred to in Article 57 of that Regulation. That participation runs on the AI Act’s rules, not on Article 33(2) CRA. A cyber resilience sandbox under the CRA stays available alongside it, provided your Member State has established one.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.