Skip to content
Zyberum Cyber Security Firm
Menu

EU Cyber Resilience Act

Make your products CRA-compliant, without slowing development.

The Cyber Resilience Act sets mandatory cybersecurity requirements for every hardware and software product with digital elements sold in the EU. We help manufacturers close the gaps with consulting, testing and a secure development lifecycle that fits your teams.

  • Regulation (EU) 2024/2847
  • Reporting since 11 Sep 2026
  • Full application 11 Dec 2027

In short

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to design them securely, handle vulnerabilities for the product’s support period and report actively exploited vulnerabilities. Reporting obligations apply from 11 September 2026; all other requirements apply from 11 December 2027. Zyberum provides CRA gap analyses, secure development lifecycle implementation, vulnerability handling processes and penetration testing.

Timeline

Key CRA dates

  1. Entry into force

    The CRA was published and entered into force. The transition period started.

  2. Conformity assessment bodies

    Rules for notified bodies apply, so third-party assessments can be prepared.

  3. Reporting obligations

    Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the CSIRT within 24 hours (early warning).

  4. Full application

    All essential requirements apply. Products without CE marking under the CRA can no longer be placed on the EU market.

Our services

Our services to support CRA compliance

CRA gap analysis

We classify your products (default, important class I/II, critical), map them against Annex I and deliver a prioritised roadmap.

Secure development lifecycle

Security requirements, threat modelling, secure coding and code review integrated into your existing development process.

Penetration testing

Independent security testing of devices, firmware, apps and cloud interfaces to find and fix vulnerabilities before market launch.

Vulnerability handling

Coordinated vulnerability disclosure, PSIRT processes and 24h/72h reporting workflows for ENISA.

SBOM & documentation

Software bill of materials, technical documentation and EU declaration of conformity prepared for audits.

Team enablement

Training for product owners and developers so CRA requirements become part of everyday engineering.

Why Zyberum

Regulation know-how plus hands-on testing

Our team combines extensive experience in product security with a deep understanding of EU regulation. We have implemented similar frameworks in automotive (UN R155, ISO/SAE 21434) and industry (IEC 62443), and we test products ourselves instead of only writing policies.

The result: compliance work that engineers accept, evidence that holds up in an assessment, and fewer vulnerabilities in the field.

FAQ

Cyber Resilience Act FAQ

Which products fall under the Cyber Resilience Act?

Almost all hardware and software products with digital elements that are placed on the EU market and can connect to a device or network: IoT devices, industrial controllers, routers, apps and desktop software. Some sectors with their own rules, such as medical devices, motor vehicles and aviation, are excluded.

When do I have to comply with the CRA?

Reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026. All other requirements, including CE marking under the CRA, apply from 11 December 2027.

What are the penalties for non-compliance?

Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for violations of the essential requirements. Market surveillance authorities can also order non-compliant products to be withdrawn.

Do I need a third-party assessment?

Most products can be self-assessed. Important products of class II and critical products need a notified body or a certification scheme, and class I products need one if harmonised standards are not fully applied.

Get started

Free 1-hour CRA readiness check

One hour with a CRA expert: we classify your product and show you what is missing before December 2027.

  • Is your product in scope, and in which class?
  • Your biggest gaps against the essential requirements
  • A realistic roadmap and first steps
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074cra@zyberum.com

Or send us a message

We reply within one business day.

Call usFree CRA readiness check

Pick a time that suits you

Open in a new tab