Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryCRACompliance

Cyber Resilience Act (CRA)

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.

Updated This page as Markdown

In short

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It requires every product with digital elements sold in the EU, from a smart plug to an industrial controller to a software package, to meet essential cybersecurity requirements, to receive security updates for its support period and to carry the CE marking for it. Reporting of actively exploited vulnerabilities applies from 11 September 2026, the full regulation from 11 December 2027.

What is the Cyber Resilience Act?

The Cyber Resilience Act is the EU regulation that makes cybersecurity a condition for placing hardware and software on the EU market. Regulation (EU) 2024/2847 applies to “products with digital elements”: anything with a direct or indirect logical or physical data connection to a device or network, so routers, smart appliances, industrial controllers, ECUs sold as spare parts, operating systems, libraries and applications, including their remote data processing. Like the Radio Equipment Directive it works through essential requirements, conformity assessment and CE marking. Unlike it, the duties do not end at the sale: manufacturers must handle vulnerabilities and ship security updates throughout the support period.

Out of scope are products already covered by sector rules with equivalent requirements, among them medical devices under the MDR and IVDR, vehicles under the type-approval framework (UN R155), civil aviation and marine equipment, plus free and open-source software that is not commercialised.

Where is it defined?

The regulation is on EUR-Lex. The parts you will read most: Article 13 (manufacturer obligations, including the support period of at least five years), Article 14 (reporting of actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report within 14 days of a corrective measure), Annex I Part I (essential cybersecurity requirements, from secure defaults, no known exploitable vulnerabilities at release and access control to logging and secure updates), Annex I Part II (vulnerability handling: SBOM, coordinated disclosure policy, regular testing, free security updates), Annexes III and IV (important and critical product classes), Article 32 (conformity assessment routes) and Article 64 (fines up to 15 million euro or 2.5 percent of worldwide turnover).

The timeline is in Article 71: in force since 10 December 2024, the reporting obligations of Article 14 apply from 11 September 2026, the chapter on notified bodies from 11 June 2026, and everything else from 11 December 2027.

What it means in practice

Most products fall in the default category and are self-assessed by the manufacturer. Important products in Annex III (for example routers, password managers and smart locks in Class I, firewalls and hypervisors in Class II) need a harmonised standard or a third-party assessment; critical products in Annex IV may need a European certificate. What we see in CRA gap analyses:

  • The product is closer than the process. Many devices already have secure boot, encrypted communication and access control. What is missing is the vulnerability handling process: a monitored contact address, an SBOM, triage with deadlines, updates for every unit in the field and the 24-hour reporting path.
  • The SBOM exposes the real problem. Once you list your components you find the old kernel and the TLS library with twelve open CVEs, and Annex I asks for products to ship without known exploitable vulnerabilities.
  • Testing is required, not optional. Annex I Part II point 3 asks for effective and regular security tests and reviews. A penetration test per major release is the straightforward evidence.

Zyberum does gap analyses, builds the vulnerability-handling process and tests the product. We are not a notified body and issue no CE certificates.

Common misunderstandings

The CRA is not a certification scheme for most products; the manufacturer declares conformity. Legacy products are not fully exempt: anything placed on the market before 11 December 2027 stays out of scope only until it is substantially modified (Article 69(2)), and the reporting duty of Article 14 applies to it regardless (Article 69(3)). And 11 September 2026 is not the start of everything: it is the date from which you must report actively exploited vulnerabilities and severe incidents in your products.

FAQ

Frequently asked questions

When does the Cyber Resilience Act apply?

The regulation entered into force on 10 December 2024. The reporting obligations of Article 14 apply from 11 September 2026, the provisions on notified bodies from 11 June 2026, and all other obligations from 11 December 2027 (Article 71). Products placed on the market before 11 December 2027 stay out of scope unless substantially modified, but the reporting duty applies to them too (Article 69).

Does my product need third-party certification under the CRA?

Most products do not. The default route is self-assessment by the manufacturer (Article 32). Important products listed in Annex III need either a harmonised standard or a third-party assessment (Class I), or a third-party assessment in any case (Class II); critical products in Annex IV may require a European certificate. Zyberum prepares you for these routes but is not a notified body.

How long must I provide security updates?

For the support period, which must reflect the time the product is expected to be in use and must be at least five years, unless the product is expected to be used for less (Article 13(8)). Updates must be available free of charge and, where feasible, be separate from feature updates (Annex I, Part II).

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab