Guide

CRA: what the EU Cyber Resilience Act is, and who it binds

Reviewed September 2026 against Regulation (EU) 2024/2847, OJ L, 20.11.2024.

Short answer: the CRA is Regulation (EU) 2024/2847, the EU’s horizontal cybersecurity law for products with digital elements. It entered into force on 10 December 2024. Its reporting duty has applied since 11 September 2026, and the rest applies from 11 December 2027. It binds manufacturers first, then importers and distributors, and it is enforced through CE marking and market surveillance.

What the CRA is

CRA stands for Cyber Resilience Act. The instrument is a regulation, not a directive, so it binds directly in every Member State without national transposition. It sets essential cybersecurity requirements for any product with digital elements placed on the EU market, and it is the first EU law to attach those requirements to the product itself rather than to the organisation operating it.

The scope hinges on one criterion: a product with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.

“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”

“This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.”

Several product categories are carved out because other Union law already covers them: medical devices, in-vitro diagnostics, aviation-certified equipment, marine equipment and road vehicle type-approval. Spare parts manufactured to the same specifications as the components they replace are excluded too.

“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”

“This Regulation does not apply to spare parts that are made available on the market to replace identical components in products with digital elements and that are manufactured according to the same specifications as the components that they are intended to replace.”

EU CRA timeline and milestones

Three dates matter, and they are not one date. The regulation was published in the Official Journal on 20 November 2024 and entered into force on the twentieth day after publication, which is 10 December 2024. The application clause then splits the rest into three.

“This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union”

“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”

The reporting duty landing fifteen months before full application is the part most plans get wrong. The CRA timeline sets out each milestone with its citation, and a separate post on the 11 September 2026 reporting duty covers the clocks in detail.

Who the CRA affects

The regulation speaks to economic operators, and it gives each role a different set of duties. Duties do not transfer between roles, so read the row that matches what you actually do.

“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”

“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”

“a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties”

One trap sits underneath all three: an importer or a distributor that puts its own name or trademark on a product, or modifies one already placed on the market, is treated as the manufacturer and inherits the full set of duties.

“An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.”

Product classes: default, important, critical

The CRA sorts products into four tiers, and the tier decides who may sign off the conformity assessment. Most products sit in the default tier and never appear in an annex at all.

“IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS”

“CRITICAL PRODUCTS WITH DIGITAL ELEMENTS”

“the internal control procedure (based on module A) set out in Annex VIII”

“Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures”

Since 21 December 2025 those annex categories have a binding technical description of their own. Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025, adopted under Article 7(4) of the CRA and published in the Official Journal on 1 December 2025, sets out the technical description of the Annex III class I and class II categories in its Annex I and of the Annex IV categories in its Annex II. Read it before deciding that a product falls outside an annex: Commission Implementing Regulation (EU) 2025/2392, OJ L, 1.12.2025.

Free and open-source software that falls into an Annex III category has its own route: the manufacturer may use one of the Article 32(1) procedures, which include the internal control procedure, provided the technical documentation is made available to the public at the time of placing on the market.

“Manufacturers of products with digital elements qualifying as free and open-source software, which fall under the categories set out in Annex III, shall be able to demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the procedures referred to in paragraph 1 of this Article, provided that the technical documentation referred to in Article 31 is made available to the public at the time of the placing on the market of those products.”

CRA compliance: the core obligations

Five duties carry most of the weight for a manufacturer. They are not a checklist someone else can sign; each one has to be evidenced in the technical documentation.

Secure by design and secure by default

Annex I, Part I sets the product properties. The opening requirement is a general one, and the specific requirements that follow, including shipping without known exploitable vulnerabilities and with a secure default configuration, apply on the basis of the manufacturer’s own cybersecurity risk assessment.

“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.”

“secure by default configuration, unless otherwise agreed between manufacturer and business user”

Vulnerability handling and the support period

Annex I, Part II sets the process duties: identify and document components, remediate without delay, test regularly, publish information about fixed vulnerabilities, run a coordinated vulnerability disclosure policy and distribute updates securely. They run for the support period, which is normally at least five years.

“address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates”

“the support period shall be at least five years”

The software bill of materials

The first point of Annex I, Part II requires a software bill of materials in a commonly used and machine-readable format, covering at the very least the top-level dependencies. It is a documentation duty, not a publication duty.

“software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products”

What that means in practice, which formats qualify and who gets to see the file is the subject of a separate page: SBOM under the Cyber Resilience Act.

Reporting under Article 14

A manufacturer must notify an actively exploited vulnerability or a severe incident to the CSIRT designated as coordinator and to ENISA, on a 24-hour early warning, a 72-hour notification and a final report. This duty has applied since 11 September 2026 and it reaches products placed on the market before that date.

“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”

“By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.”

Conformity assessment, declaration and CE marking

The manufacturer runs the conformity assessment for the product and for the processes it has put in place, draws up an EU declaration of conformity and affixes the CE marking. For a software product with no physical form, the marking goes either on the declaration or on the website that accompanies the software.

“The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.”

“The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated.”

“For products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product.”

CRA regulations: penalties for getting it wrong

Penalties are laid down by Member States within brackets the regulation fixes. A breach of the essential requirements or of Articles 13 and 14 sits in the highest bracket.

“Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented.”

“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.”

The other brackets, and how they are actually applied, are set out in the post on CRA fines.

CRA on EUR-Lex: reading the primary text

The regulation is Regulation (EU) 2024/2847, CELEX number 32024R2847, published in OJ L of 20 November 2024. The authoritative text is on EUR-Lex: Regulation (EU) 2024/2847 on EUR-Lex. Every language version is equally authentic under EU law, so a German reader should quote the German text rather than a translation of the English one.

Every quote on this site is checked against the published text weekly, from the Publications Office machine endpoint rather than a summary. Our methodology page sets out how, and the glossary gives each defined term with its own pinpoint.

CRA Meldepflicht: the reporting duty in German

Readers searching for the CRA Meldepflicht are looking for the Article 14 reporting duty. This page exists in German as Die Cyberresilienz-Verordnung, quoting the German Official Journal text rather than a translation of the English. A page on the CRA in Germany covers the national picture, including which authority the German implementing law points at.

Check your product. Run the free Cybiq check: five or six questions, a definitive verdict on whether the CRA applies, which conformity route you face and which obligations attach to your role, with every claim anchored word-for-word in the Official Journal. Free tools for the declaration of conformity and the reporting routing are on the tools page. More scope questions are answered in the FAQ.