Cyber Resilience Act (CRA)
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.
Updated This page as Markdown
In short
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It requires every product with digital elements sold in the EU, from a smart plug to an industrial controller to a software package, to meet essential cybersecurity requirements, to receive security updates for its support period and to carry the CE marking for it. Reporting of actively exploited vulnerabilities applies from 11 September 2026, the full regulation from 11 December 2027.
What is the Cyber Resilience Act?
The Cyber Resilience Act is the EU regulation that makes cybersecurity a condition for placing hardware and software on the EU market. Regulation (EU) 2024/2847 applies to “products with digital elements”: anything with a direct or indirect logical or physical data connection to a device or network, so routers, smart appliances, industrial controllers, ECUs sold as spare parts, operating systems, libraries and applications, including their remote data processing. Like the Radio Equipment Directive it works through essential requirements, conformity assessment and CE marking. Unlike it, the duties do not end at the sale: manufacturers must handle vulnerabilities and ship security updates throughout the support period.
Out of scope are products already covered by sector rules with equivalent requirements, among them medical devices under the MDR and IVDR, vehicles under the type-approval framework (UN R155), civil aviation and marine equipment, plus free and open-source software that is not commercialised.
Where is it defined?
The regulation is on EUR-Lex. The parts you will read most: Article 13 (manufacturer obligations, including the support period of at least five years), Article 14 (reporting of actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report within 14 days of a corrective measure), Annex I Part I (essential cybersecurity requirements, from secure defaults, no known exploitable vulnerabilities at release and access control to logging and secure updates), Annex I Part II (vulnerability handling: SBOM, coordinated disclosure policy, regular testing, free security updates), Annexes III and IV (important and critical product classes), Article 32 (conformity assessment routes) and Article 64 (fines up to 15 million euro or 2.5 percent of worldwide turnover).
The timeline is in Article 71: in force since 10 December 2024, the reporting obligations of Article 14 apply from 11 September 2026, the chapter on notified bodies from 11 June 2026, and everything else from 11 December 2027.
What it means in practice
Most products fall in the default category and are self-assessed by the manufacturer. Important products in Annex III (for example routers, password managers and smart locks in Class I, firewalls and hypervisors in Class II) need a harmonised standard or a third-party assessment; critical products in Annex IV may need a European certificate. What we see in CRA gap analyses:
- The product is closer than the process. Many devices already have secure boot, encrypted communication and access control. What is missing is the vulnerability handling process: a monitored contact address, an SBOM, triage with deadlines, updates for every unit in the field and the 24-hour reporting path.
- The SBOM exposes the real problem. Once you list your components you find the old kernel and the TLS library with twelve open CVEs, and Annex I asks for products to ship without known exploitable vulnerabilities.
- Testing is required, not optional. Annex I Part II point 3 asks for effective and regular security tests and reviews. A penetration test per major release is the straightforward evidence.
Zyberum does gap analyses, builds the vulnerability-handling process and tests the product. We are not a notified body and issue no CE certificates.
Common misunderstandings
The CRA is not a certification scheme for most products; the manufacturer declares conformity. Legacy products are not fully exempt: anything placed on the market before 11 December 2027 stays out of scope only until it is substantially modified (Article 69(2)), and the reporting duty of Article 14 applies to it regardless (Article 69(3)). And 11 September 2026 is not the start of everything: it is the date from which you must report actively exploited vulnerabilities and severe incidents in your products.
FAQ
Frequently asked questions
When does the Cyber Resilience Act apply?
The regulation entered into force on 10 December 2024. The reporting obligations of Article 14 apply from 11 September 2026, the provisions on notified bodies from 11 June 2026, and all other obligations from 11 December 2027 (Article 71). Products placed on the market before 11 December 2027 stay out of scope unless substantially modified, but the reporting duty applies to them too (Article 69).
Does my product need third-party certification under the CRA?
Most products do not. The default route is self-assessment by the manufacturer (Article 32). Important products listed in Annex III need either a harmonised standard or a third-party assessment (Class I), or a third-party assessment in any case (Class II); critical products in Annex IV may require a European certificate. Zyberum prepares you for these routes but is not a notified body.
How long must I provide security updates?
For the support period, which must reflect the time the product is expected to be in use and must be at least five years, unless the product is expected to be used for less (Article 13(8)). Updates must be available free of charge and, where feasible, be separate from feature updates (Annex I, Part II).
Sources
Related pages
- GlossaryNIS2NIS2 (Directive (EU) 2022/2555) sets cybersecurity duties for essential and important entities in 18 sectors. Scope, ten measures, reporting deadlines, German law.
- GlossarySBOMAn SBOM lists every software component in a product with version and supplier. Formats, minimum elements, what the Cyber Resilience Act requires and how to use one.
- ComparisonsNIS2 vs Cyber Resilience Act: Which One Applies to You, and What Each DemandsNIS2 regulates operators of essential services; the CRA regulates products with digital elements. Who falls under which, duties, deadlines and penalties side by side.
- InsightsCyber Resilience Act: What Manufacturers Must Do by 2027A practical guide to the EU Cyber Resilience Act: scope, product classes, deadlines, reporting duties and the concrete steps manufacturers should take now.
- InsightsThe CRA 24-Hour Reporting Duty: What Manufacturers Must DoThe Cyber Resilience Act reporting duty applies since 11 September 2026. The deadlines (24 hours, 72 hours, 14 days, one month), what triggers them, and how to be ready.
- ServicesMake your products CRA-compliant, without slowing development.Get CRA-ready: gap analysis, secure development lifecycle, vulnerability handling, SBOM and penetration testing for products with digital elements.
