Cyber Resilience Act: What Manufacturers Must Do by 2027
A practical guide to the EU Cyber Resilience Act: scope, product classes, deadlines, reporting duties and the concrete steps manufacturers should take now.
Zyberum Security Team · Published · 8 min read
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, is the first EU law that sets mandatory cybersecurity requirements for almost every product with digital elements. From 11 December 2027, products that do not comply can no longer carry the CE mark or be sold in the EU. Reporting obligations already apply since 11 September 2026.
This guide summarises what the CRA requires and what manufacturers should do now.
Who is affected?
The CRA applies to manufacturers, importers and distributors of products with digital elements, meaning hardware or software that can connect directly or indirectly to a device or network. That includes:
- IoT and smart-home devices, wearables and consumer electronics
- Industrial controllers, sensors, gateways and HMIs
- Routers, firewalls and network equipment
- Desktop and mobile applications, operating systems and firmware
Excluded are products already covered by sector-specific rules with equivalent security requirements, such as medical devices, motor vehicles (covered by UN R155 type approval), civil aviation and marine equipment, as well as non-commercial open-source software.
Product classes
The CRA sorts products by risk. The class determines how conformity is assessed:
| Class | Examples | Conformity assessment |
|---|---|---|
| Default | Most products, e.g. smart speakers, games, image-editing software | Self-assessment (module A) |
| Important, Class I | Browsers, password managers, VPNs, routers, smart-home security devices | Self-assessment only if harmonised standards are fully applied, otherwise third party |
| Important, Class II | Firewalls, intrusion detection, hypervisors, tamper-resistant microprocessors | Third-party assessment by a notified body |
| Critical | Smart meter gateways, smart cards, hardware security boxes | European certification scheme (where available) or notified body |
The key deadlines
- 10 December 2024: the CRA entered into force.
- 11 June 2026: provisions on notified bodies apply.
- 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours and a final report later, via ENISA’s single reporting platform.
- 11 December 2027: all essential requirements apply.
What the essential requirements mean in practice
Annex I of the CRA lists two groups of requirements.
Security properties of the product, for example:
- No known exploitable vulnerabilities when placed on the market
- Secure-by-default configuration, including the option to reset to the original state
- Protection against unauthorised access (authentication, access control)
- Confidentiality and integrity of stored and transmitted data
- Minimal attack surface and data minimisation
- Security updates, ideally automatic, separable from functional updates
Vulnerability handling for the entire support period:
- A software bill of materials (SBOM) of at least the top-level dependencies
- Regular security testing and review
- A coordinated vulnerability disclosure policy and a contact point
- Timely, free security updates with advisories
Penalties
Violations of the essential requirements can be fined up to €15 million or 2.5% of global annual turnover, whichever is higher. Market surveillance authorities can also require products to be withdrawn or recalled.
A pragmatic roadmap
Based on our projects, these steps work well for most manufacturers:
- Inventory and classify your product portfolio: which products are in scope, and in which class?
- Set up vulnerability reporting now. The 24-hour obligation is already in force. Define a PSIRT, an intake channel (e.g.
security.txt) and an escalation path to ENISA. - Run a gap analysis against Annex I for each product family.
- Integrate security into development: threat modelling, secure coding guidelines, code review and dependency management with SBOM generation.
- Test independently. Penetration testing and fuzzing demonstrate that there are no known exploitable vulnerabilities, and they are the strongest evidence in your technical documentation.
- Prepare the technical documentation and EU declaration of conformity.
How Zyberum helps
We support manufacturers from gap analysis to penetration testing and PSIRT setup. Learn more about our Cyber Resilience Act services or book a free meeting with a CRA expert.
FAQ
Frequently asked questions
Does the CRA apply to software-only products?
Yes. The CRA covers hardware and software products with digital elements, including standalone software such as apps and desktop applications, as long as they are placed on the EU market commercially. Pure SaaS is generally covered by NIS2 instead, and non-commercial open-source software is excluded.
What happens if my product is already on the market before December 2027?
Products placed on the market before 11 December 2027 only have to meet the CRA requirements if they are substantially modified afterwards. The reporting obligations for actively exploited vulnerabilities, however, apply from 11 September 2026 to all products in scope, including those already on the market.
How long must I provide security updates?
For the support period, which must reflect the time the product is expected to be in use and should be at least five years unless the product is expected to be used for a shorter time.