Skip to content

Cyber Resilience Act (CRA): obligations, deadlines and implementation for software manufacturers

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU. Reporting obligations for actively exploited vulnerabilities and severe incidents apply since 11 September 2026; all other obligations apply from 11 December 2027.

Last updated:

What is the CRA?

The Cyber Resilience Act is an EU regulation that entered into force on 10 December 2024. It applies directly in all member states and requires manufacturers to design, develop and maintain products with digital elements securely across their whole lifecycle. Compliance is shown through a conformity assessment, technical documentation, an EU declaration of conformity and the CE marking.

Who is affected?

The CRA covers products with digital elements: software or hardware whose intended use includes a direct or indirect data connection to a device or network. This includes installable software, apps, firmware and connected devices, and their remote data processing solutions.

  • Manufacturers carry most obligations: whoever develops or has a product developed and places it on the market under their own name or trademark.
  • Importers and distributors must check that products they make available comply and that the manufacturer has met its duties.
  • Pure SaaS is generally outside the scope. It falls under the CRA only where it is a remote data processing solution without which a product with digital elements could not perform one of its functions.
  • Non-commercial open source is excluded. Open-source stewards that support commercially used projects follow a lighter regime.

Deadlines

DateWhat applies
10 Dec 2024CRA enters into force
11 Jun 2026Rules on conformity assessment bodies (notified bodies) apply
11 Sep 2026Reporting obligations (Art. 14) for actively exploited vulnerabilities and severe incidents apply, also for products already on the market
11 Dec 2027Full application: essential requirements, conformity assessment, CE marking

Essential requirements (Annex I)

Annex I has two parts. Part I covers product properties: secure by default configuration, no known exploitable vulnerabilities at release, protection of confidentiality and integrity, access control, minimised attack surface, security logging and the ability to deliver security updates. Part II covers vulnerability handling: an SBOM, remediation without delay, regular testing, a coordinated vulnerability disclosure policy and secure update distribution. Manufacturers must also carry out and document a cybersecurity risk assessment and provide security updates for a support period of at least five years, unless the product is expected to be used for a shorter time.

Product categories and conformity assessment

Most products are in the default (standard) category and can use internal control (Module A), a self-assessment by the manufacturer. Important products (Class I and II, Annex III) and critical products (Annex IV) require harmonised standards, third-party assessment or, for critical products, possibly European certification. As of September 2026, no harmonised CRA standards have been cited in the Official Journal yet.

Penalties

Infringement (Art. 64)Maximum fine
Essential requirements (Annex I), manufacturer obligations (Art. 13, 14)EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher
Other obligations under the CRAEUR 10 million or 2% of worldwide annual turnover
Incorrect, incomplete or misleading information to authoritiesEUR 5 million or 1% of worldwide annual turnover

Micro and small enterprises cannot be fined for missing the 24-hour early warning deadline.

First steps

  1. Inventory your products and decide which are in scope and in which category.
  2. Set up reporting readiness now, since Art. 14 already applies.
  3. Generate and maintain an SBOM for every product.
  4. Establish a vulnerability handling process.
  5. Work through the CRA checklist towards full conformity by December 2027.

Yes. Standalone software placed on the EU market, such as installable applications or firmware, is a product with digital elements. Pure SaaS is generally outside the scope unless it is the remote data processing solution of such a product.

Yes. Under Art. 69(3), the Art. 14 reporting obligations also apply to products placed on the market before 11 December 2027.

Not for most products. Standard-category products can use internal control (Module A). Important and critical products have stricter assessment routes.

For the support period, which must be at least five years unless the product is expected to be in use for a shorter time.

Join the waitlist

We launch in November. Be the first to get access.