Cyber Resilience Act

Cybersecurity becomes a condition for selling almost every product with digital elements in the EU — reporting duties already apply since 11 September 2026.

Reference
Regulation (EU) 2024/2847
Status
Applies in stages
Sources last checked

What it is

The CRA is the first horizontal EU law with cybersecurity requirements for hardware and software products with digital elements. Products must be secure by design, receive security updates during a defined support period and carry the CE marking based on these requirements. It applies in stages until full application on 11 December 2027.

Who is affected

Manufacturers, importers and distributors of products with digital elements — from smart sensors and PLCs with network interfaces to routers, apps and firmware. Whoever substantially modifies a product or sells it under their own name or trademark is considered the manufacturer.

What you have to do

  • Manufacturers: risk assessment, secure-by-design product, no known exploitable vulnerabilities, secure default configuration.
  • Manufacturers: vulnerability handling with a contact point for reports, SBOM and free security updates for the support period (normally at least five years).
  • Manufacturers: report actively exploited vulnerabilities and severe incidents via the ENISA Single Reporting Platform — early warning within 24 h, notification within 72 h, final report no later than 14 days after a corrective measure is available (vulnerabilities) or within one month of the notification (severe incidents).
  • Importers: place on the market only products for which the manufacturer has carried out the conformity assessment, drawn up the technical documentation and affixed the CE marking; add own name and address; keep a copy of the EU declaration of conformity for 10 years or the support period, whichever is longer, and ensure the technical documentation can be provided on request; inform the manufacturer of vulnerabilities.
  • Distributors: check CE marking, documentation and support period; do not make available products they consider, or have reason to believe, are non-compliant.

Fact check

Not correct “The CRA only starts in December 2027 — nothing to do before.”

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents — and this also applies to products placed on the market before December 2027.

Not correct “We only import — cybersecurity is the factory’s job.”

Importers have their own duties: they may only place compliant products on the market, must verify documentation and CE marking, keep the EU declaration of conformity for at least 10 years and act on known vulnerabilities. If you sell under your own name or trademark, you are considered the manufacturer.

Partly correct “Open-source components make our firmware exempt.”

Non-commercial open-source software itself is largely outside scope. But a manufacturer that integrates open-source components into a commercial product is responsible for them and must exercise due diligence.

Not correct “Every CRA product needs a notified body.”

Most products allow self-assessment. Only “important” products (classes I and II, e.g. routers, microcontrollers with security functions, firewalls) may need third-party assessment; “critical” products may require European cybersecurity certification once a delegated act requires it — until then the class II procedures apply. The categories are listed in Annexes III and IV of the CRA; their technical descriptions are set out in Implementing Regulation (EU) 2025/2392.

Sources

  1. Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal text (opens external website) ↗EUR-Lex · Legal text · English version · checked
  2. Cyber Resilience Act — implementation timeline (opens external website) ↗European Commission · Official · in English · checked
  3. CRA reporting obligations (opens external website) ↗European Commission · Official · in English · checked
  4. The CRA Single Reporting Platform is launched (opens external website) ↗ENISA · Official · in English · checked
  5. Implementing Regulation (EU) 2025/2392 — important and critical products (opens external website) ↗EUR-Lex · Legal text · English version · checked

General information, not legal advice. Authentic are only the texts published in the Official Journal of the EU and the Austrian Federal Law Gazette.

Not sure where your product stands?

Send us the product and its documents. We check the technical file against the rules on this radar and tell you what is missing — and source an EU-ready alternative if needed.