01What the CRA is
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide law to set mandatory cybersecurity requirements for products with digital elements; hardware and software; across their entire lifecycle. It shifts responsibility for security onto the organisations that place these products on the market, rather than leaving it to users. Art. 1
In practice, a product may only be made available on the EU market if it meets the essential requirements set out in Annex I and the manufacturer has fulfilled the obligations attached to it. Compliance is demonstrated through a conformity assessment, an EU declaration of conformity and the CE marking. You can read the binding wording in the full text of the regulation.
If your product has digital elements and reaches the EU market, it must be designed, built and maintained to a defined cybersecurity standard; and you must be able to demonstrate it.
Unsure whether any of this applies to you? The two-minute CRA Fast Check establishes scope and likely class before you read any further.
02Who it applies to
The Regulation covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection. That definition is deliberately broad: connected consumer devices, business hardware, mobile and desktop applications, operating systems, libraries and components all fall within it unless a specific exclusion applies. Obligations are distributed across the supply chain: Art. 13–28
- Manufacturers; bear the primary obligations: secure design, technical documentation, conformity assessment and vulnerability handling. The manufacturer guide and the software-developer guide set out the full path.
- Importers; may only place compliant products on the market and must verify the manufacturer's duties were met before doing so.
- Distributors; must act with due care and check that the CE marking and documentation are present. The importer & distributor guide covers these duties.
The CRA applies regardless of where the manufacturer is established: a company outside the EU that sells into the Union is in scope and must ensure an economic operator in the EU is responsible for the relevant obligations. Remote data-processing solutions that are necessary for a product to perform its functions are treated as part of that product and are covered too. Art. 2 · 3(2)
Products already covered by sector-specific rules; such as medical devices, motor vehicles and civil aviation; are excluded. Non-commercial open-source software developed outside a commercial activity is largely outside the scope, and open-source stewards have a lighter, tailored set of obligations.
03Product classes
The required conformity route depends on how critical the product is. Most products self-assess; higher-risk categories listed in the annexes face stricter procedures. Classification follows the product's core functionality, not every feature it happens to include. Art. 6–7 · Annex III–IV
| Class | Examples | Conformity route |
|---|---|---|
| Default | The majority of products with digital elements | Self-assessment |
| Important; I | Password managers, network management, VPNs | Standards or third-party |
| Important; II | Operating systems, firewalls, microprocessors | Third-party assessment |
| Critical | Smart meters, smart cards, secure elements | Mandatory certification |
Where more than one category could apply, the stricter class applies. To match your product against the Annex III and IV categories, use the product-class finder.
04Key obligations
The essential requirements in Annex I fall into two groups; properties the product must have, and processes the manufacturer must run. The compliance matrix tracks every one of them with its article reference. Annex I
- Secure by design & default; delivered with a secure configuration and a minimised attack surface.
- No known exploitable vulnerabilities; shipped free of known exploitable flaws.
- Vulnerability handling; a process to identify, document, remediate and disclose issues.
- Security updates; free, timely updates throughout the defined support period; generally expected to be at least five years unless the product's expected use is shorter.
- Software bill of materials; maintain an SBOM covering the product's components in a commonly used, machine-readable format.
- Reporting; notify actively exploited vulnerabilities and severe incidents to ENISA and the relevant CSIRT, with an early warning within 24 hours (see below).
05Conformity & CE marking
Demonstrating compliance follows a fixed sequence, and the route through it is set by the product class. Art. 28 · 32 · Annex V · VII
- Compile the technical documentation; the evidence file described in Annex VII, kept for ten years after the product is placed on the market.
- Carry out the conformity assessment; default products may self-assess (Module A); important products use harmonised standards or a notified body; critical products require certification.
- Draw up the EU declaration of conformity; a signed statement structured to Annex V. The declaration-of-conformity generator produces one for you.
- Affix the CE marking; the visible sign that the above is complete.
The step-by-step CE marking guide walks through each route in detail, and the cost calculator gives an indicative figure for reaching compliance for your class.
06Reporting duties
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products to ENISA and the relevant national CSIRT, through the single reporting platform established under Article 16. This is the earliest of the CRA's major obligations to bite. Art. 14 · 16
- 24 hoursEarly warning, from the moment you become aware of an actively exploited vulnerability or a severe incident.
- 72 hoursFuller notification, including corrective or mitigating measures taken.
- 14 daysFinal report once the vulnerability is fixed, or for an incident, once it is handled.
Meeting these windows in practice means knowing your components and watching them continuously. The SBOM & vulnerability analyzer tracks your bill of materials against the NVD and the EU vulnerability database so you can act inside the 24-hour window. For a full breakdown of what counts as reportable and who receives each report, see the incident & vulnerability reporting guide.
07Timeline & penalties
The Act is already in force; its obligations phase in over the following years. Art. 71
- Dec 2024Entered into force (10 December 2024).
- Sep 2026Reporting obligations apply (11 September 2026).
- 2026Core harmonised standards and product-classification dates fall due (30 August / 30 October 2026).
- Dec 2027Full application; most provisions apply (11 December 2027).
Non-compliance with the essential requirements or manufacturer obligations can attract fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Lower ceilings apply to other infringements and to supplying incorrect information.
08Common questions
Does the Cyber Resilience Act apply to my product?
If your product contains software or firmware and is made available on the EU market with a direct or indirect data connection, it is very likely in scope. Sector-specific products (medical devices, vehicles, aviation) and non-commercial open source are the main exceptions. The Fast Check confirms it in two minutes.
When does the CRA actually apply?
It entered into force on 10 December 2024. The reporting obligations apply from 11 September 2026 and the bulk of the obligations apply from 11 December 2027.
What is the difference between default, important and critical products?
Default products self-assess. Important products (Annex III, Class I or II) need harmonised standards or a notified body. Critical products (Annex IV) require mandatory certification. Classification follows the product's core function; the stricter class applies where more than one fits.
Do I need a software bill of materials (SBOM)?
Yes. Manufacturers must identify and document the product's components, including by drawing up an SBOM in a commonly used, machine-readable format. Annex I · II(1)
What are the penalties for non-compliance?
Up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaches of the essential requirements or manufacturer obligations.
More answers, each with its article reference, are on the full FAQ page.
09What to do next
Begin by confirming whether the Act applies to your product, then follow the guidance written for your role and track the requirements to done.
