FAQ
Cyber Resilience Act: frequently asked questions
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Thirty-four answers for people building and selling products with digital elements in the EU. Every answer that states a legal position carries the words of the Official Journal itself: the quoted spans come from the same verified corpus the Cybiq decision engine cites, re-checked against the published text by automated tests. Where the Regulation genuinely does not settle a question, the answer says so. Definitions of marked terms live in the glossary.
Scope
Does the CRA apply to SaaS?
The Regulation covers products with digital elements: software or hardware products and their remote data processing solutions. A service that runs entirely on the provider’s own infrastructure is not supplied as such a product, so pure SaaS generally stays outside the CRA; the Cybiq engine reports it as probably out of scope with checks worth running. The Regulation does not settle this boundary with an explicit services provision: if customers install or run anything on their side, such as an app, agent, connector or browser extension, or if the service is sold together with hardware, that element can be in scope.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
“This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.”
Does the CRA apply to free and open-source software?
Not to everyone who touches it. The Regulation does not apply to people who contribute source code to free and open-source products that are not under their responsibility, and software whose source is openly shared under a licence granting rights to use, modify and redistribute it freely falls within the Regulation’s own definition of free and open-source software. The exclusion ends when the software is supplied in the course of a commercial activity, for example paid distribution or a commercial support tier wrapped around the product itself.
“does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility”
“software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable”
“open-source software supplied for distribution or use in the course of a commercial activity”
Does the CRA apply to tools used only inside my organisation?
No. The CRA regulates placing on the market and making available on the Union market, both of which involve supplying the product beyond your own organisation. Software that never leaves it triggers neither concept, so the engine returns out of scope for internal-only tools.
“the first making available of a product with digital elements on the Union market”
“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”
Does the CRA apply to hardware without any software?
Yes. The definition of a product with digital elements explicitly covers a software or hardware product, and it includes software or hardware components placed on the market separately. Hardware is in scope even when you ship it without any software of your own.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
Does the CRA apply to spare parts and components?
Spare parts are excluded where they are made available on the market to replace identical components and are manufactured to the same specifications as the parts they replace. The carve-out is narrow: components placed on the market separately otherwise fall inside the product definition, and if you change a placed product in a way that affects its compliance with the essential requirements, that can be a substantial modification with fresh obligations attached.
“This Regulation does not apply to spare parts that are made available on the market to replace identical components in products with digital elements and that are manufactured according to the same specifications as the components that they are intended to replace.”
“a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed”
What about products already on the market before 11 December 2027?
Products placed on the market before 11 December 2027 stay outside the main requirements unless they undergo a substantial modification from that date. One duty reaches back regardless: the Article 14 reporting obligations apply to all in-scope products, including those placed on the market before the full application date.
“Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.”
“By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.”
What does “placing on the market” mean?
It means the first making available of a product with digital elements on the Union market. It is a one-off trigger per product: everything that happens afterwards, such as further supplies, updates and vulnerability handling, rests on other concepts like making available and the support-period duties.
“the first making available of a product with digital elements on the Union market”
What does “making available” mean?
It means supplying a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. Supplying something for free therefore counts exactly like selling it, so long as the supply happens in the course of a commercial activity.
“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”
Does the CRA apply to non-EU sellers shipping into the EU?
Yes. The trigger is supply on the Union market in the course of a commercial activity, and nothing in either definition turns on where the seller is established. In practice a seller without an EU establishment reaches the EU market through an importer, which the Regulation defines as a person established in the Union who places on the market a product bearing the name or trademark of a person established outside the Union.
“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”
“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”
What about medical devices, cars, aviation and high-risk AI?
Where one of the listed Union acts governs the product, that act takes precedence and the CRA does not apply: the list covers medical devices, in-vitro diagnostics and road vehicles, with further exclusions for aviation-certified products and marine equipment. High-risk AI systems are treated differently: they are not excluded from the CRA, and a high-risk AI system that meets the CRA essential cybersecurity requirements is deemed to comply with the AI Act’s cybersecurity requirements, with the two conformity assessments coordinated.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
“shall be deemed to comply with the cybersecurity requirements set out in Article 15 of that Regulation”
“Regulation (EU) 2024/1689”
Classification
What makes a product “important” (Annex III)?
A product is important when it falls into a category listed in Annex III. The list spans password managers, standalone and embedded browsers, operating systems, network equipment, security tooling such as anti-malware and SIEM systems, smart home locks and cameras, internet-connected toys and health wearables.
“IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS”
“Password managers”
“Standalone and embedded browsers”
“Operating systems”
What is the difference between Class I and Class II?
Both classes sit inside the Annex III list of important products; they differ in how conformity is demonstrated. Class I products keep internal-control self-assessment only while harmonised standards, common specifications or certification schemes are applied in full, otherwise third-party procedures apply. Class II products, such as firewalls, intrusion detection and prevention systems, hypervisors and container runtimes, always demonstrate conformity through those third-party procedures.
“the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ as referred to in Article 27, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential cybersecurity requirements to either of the following procedures”
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
“Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures”
“Firewalls, intrusion detection and prevention systems”
What is a “critical” product (Annex IV)?
Annex IV lists the critical categories: hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements. These face the strictest route, with a notified body involved in the conformity assessment.
“CRITICAL PRODUCTS WITH DIGITAL ELEMENTS”
“Hardware Devices with Security Boxes”
“Smart meter gateways within smart metering systems”
“Smartcards or similar devices, including secure elements”
Who decides which class my product falls into?
The Regulation does not appoint a classifier: it publishes the Annex III and Annex IV lists, and the manufacturer performs the conformity assessment, which includes working out which listed category fits the product. For Class II and critical products that choice is then checked by a notified body during assessment rather than taken on trust.
“The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.”
“IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS”
“CRITICAL PRODUCTS WITH DIGITAL ELEMENTS”
What if my product fits two categories?
The Regulation does not settle how to rank overlapping categories: there is no explicit priority rule between annex items. Work conservatively. Identify every category the product matches and follow the route of the most demanding one, because a Class II or critical category leaves no room for self-assessment, while the reverse overlap would give you no relief from the stricter route.
“Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures”
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
Does self-assessment stay available for Class I products?
Not unconditionally. For Class I products, internal-control self-assessment stays available only where harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ are applied in full. If you apply them only partly, or they do not exist for your product, EU-type examination followed by production control (module B+C) or full quality assurance (module H) applies instead.
“the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ as referred to in Article 27, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential cybersecurity requirements to either of the following procedures”
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
Roles
Am I a manufacturer if I rebrand someone else’s product?
Yes. The definition covers a person who develops or manufactures products with digital elements or has them designed, developed or manufactured by others, and markets them under its name or trademark, whether for payment, monetisation or free of charge. Rebranded resellers are treated as manufacturers outright: an importer or distributor that places a product on the market under its own name or trademark, or carries out a substantial modification of an already placed product, is considered to be a manufacturer subject to Articles 13 and 14.
“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”
“An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.”
What are an importer’s duties?
Importers place on the market only products that comply with the essential cybersecurity requirements, and they indicate their name, registered trade name or registered trademark on the product. On vulnerabilities they have a pass-through duty: upon becoming aware of one, they inform the manufacturer without undue delay, and where the product presents a significant cybersecurity risk they immediately inform the market surveillance authorities of the Member States where they made it available.
“place on the market only products with digital elements that comply with the essential cybersecurity requirements”
“Importers shall indicate their name, registered trade name or registered trademark”
“Upon becoming aware of a vulnerability in the product with digital elements, importers shall inform the manufacturer without undue delay about that vulnerability”
“where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market”
What are a distributor’s duties?
Distributors act with due care in relation to the Regulation’s requirements, which includes verifying before making a product available that it bears CE marking and is accompanied by the required documentation. They mirror the importer pass-through duties: informing the manufacturer about vulnerabilities without undue delay, and immediately informing market surveillance authorities where the product presents a significant cybersecurity risk.
“act with due care in relation to the requirements set out in this Regulation”
“Upon becoming aware of a vulnerability in the product with digital elements, distributors shall inform the manufacturer without undue delay about that vulnerability”
“where the product with digital elements presents a significant cybersecurity risk, distributors shall immediately inform the market surveillance authorities of the Member States”
What if the manufacturer is outside the EU?
The CRA attaches at the Union border rather than at the company’s registered office. Its definition of importer covers precisely the case of a Union-established person placing on the market a product bearing the name or trademark of a person established outside the Union, and importers may only place compliant products there. A non-EU maker should therefore expect its EU importer to demand conformity evidence before taking stock, because the importer carries its own liability for what it lets through.
“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”
“place on the market only products with digital elements that comply with the essential cybersecurity requirements”
What is an open-source software steward?
An open-source software steward is a legal person, other than a manufacturer, that systematically supports the development of specific free and open-source products intended for commercial activities and ensures their viability. Stewards must put in place and document, in a verifiable manner, a cybersecurity policy fostering secure development and effective vulnerability handling, and parts of the Article 14 reporting regime can reach them to the extent they are involved in development.
“a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products”
“Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.”
Obligations
What is an SBOM and what depth is required?
An SBOM (software bill of materials) is a formal record containing details and supply-chain relationships of the components included in the software elements of a product. The required depth is a floor, not a ceiling: it must cover at the very least the top-level dependencies of the product, in a commonly used and machine-readable format such as CycloneDX or SPDX.
“a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements”
“software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products”
How long is the support period?
The support period is the period during which a manufacturer must ensure that vulnerabilities are handled effectively and in accordance with the essential cybersecurity requirements. It runs for at least five years. Where the product is expected to be in use for less than five years, the support period corresponds to that expected use time instead.
“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I”
“the support period shall be at least five years”
“Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.”
What does vulnerability handling require?
Manufacturers must ensure that vulnerabilities of the product are handled effectively and in accordance with the essential cybersecurity requirements: in practice a documented process to receive, triage, fix and publish fixes, with a contact channel for reporters. Products must ship secure by default unless the manufacturer and a business user agree otherwise.
“vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements”
“secure by default configuration, unless otherwise agreed between manufacturer and business user”
Who must report what, when, under Article 14?
Article 14 binds manufacturers only, which its own chapter heading states. A manufacturer notifies actively exploited vulnerabilities and severe incidents simultaneously to the CSIRT designated as coordinator and to ENISA via the single reporting platform. The clocks run from awareness: an early warning within 24 hours, a vulnerability notification within 72 hours, a final report for an actively exploited vulnerability no later than 14 days after a corrective or mitigating measure is available, and a final incident report within one month after submitting the incident notification.
“Reporting obligations of manufacturers”
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”
“without undue delay and in any event within 24 hours of the manufacturer becoming aware of it”
“within 72 hours”
“a final report, no later than 14 days after a corrective or mitigating measure is available”
“a final report, within one month after the submission of the incident notification under point (b)”
What are the CE marking rules?
CE marking is how the manufacturer indicates that the product and the processes put in place conform with the essential cybersecurity requirements. It must be affixed visibly, legibly and indelibly. For products that are software, the marking instead goes on the EU declaration of conformity or on the website accompanying the software product.
“a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing”
“visibly, legibly and indelibly indicate their conformity”
“For products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product.”
What goes into the technical documentation?
The technical documentation must be drawn up before the product is placed on the market and continuously updated, where appropriate, at least during the support period. Its content is set out in Annex VII. Watch the numbering: Annex V holds the EU declaration of conformity template, not the technical documentation.
“The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period.”
“CONTENT OF THE TECHNICAL DOCUMENTATION”
“EU DECLARATION OF CONFORMITY”
Dates and enforcement
Which three dates matter?
Chapter IV, the notification of conformity assessment bodies (Articles 35 to 51), applies from 11 June 2026. Article 14 reporting applies from 11 September 2026. Everything else applies from 11 December 2027.
“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”
“NOTIFICATION OF CONFORMITY ASSESSMENT BODIES”
How high are the penalties and who levies them?
Member States lay down the rules on penalties and must ensure they are implemented; the Regulation sets the ceilings. Non-compliance with the essential cybersecurity requirements and Articles 13 and 14 carries administrative fines of up to EUR 15 000 000 or, for an undertaking, up to 2.5 % of total worldwide annual turnover. Breaches of operator obligations carry administrative fines of up to EUR 10 000 000 or 2 %.
“Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented.”
“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover”
“administrative fines of up to EUR 10 000 000 or, if the offender is an undertaking, up to 2 % of its total worldwide annual turnover”
What happens if I miss a deadline?
The immediate legal exposure is the penalty regime just described: Member States enforce through nationally laid-down penalties, capped by Article 64’s ceilings. How enforcement proceeds in detail varies by Member State, so treat those ceilings as the outer bound rather than a prediction, and close gaps before the applicable date instead of after it.
“Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented.”
“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover”
Common edge cases
Do the duties apply if I give the product away free?
Yes, provided the supply happens in the course of a commercial activity. Making available covers supply whether in return for payment or free of charge, so free tiers, giveaways and free downloads from a business count like sales.
“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”
I contribute code to an open-source project: am I covered?
No. The Regulation does not apply to natural or legal persons who contribute source code to free and open-source products that are not under their responsibility. That protection belongs to contributors; running or monetising the project is different, and can put you in scope as a steward or as a manufacturer marketing the software under your name.
“does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility”
When do I need a notified body instead of self-assessment?
Three situations pull third-party assessment in. Annex III Class II products always demonstrate conformity through EU-type examination with production control or full quality assurance. Annex III Class I products lose internal-control self-assessment when harmonised standards, common specifications or certification schemes are not applied in full. Annex IV critical products face the strictest route throughout.
“The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.”
“Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures”
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
“CRITICAL PRODUCTS WITH DIGITAL ELEMENTS”
What counts as a significant cybersecurity risk?
A significant cybersecurity risk is one which, based on its technical characteristics, can be assumed to have a high likelihood of an incident leading to severe negative impact, including considerable material or non-material loss or disruption. This threshold is what obliges importers and distributors to inform market surveillance authorities immediately.
“a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption”
“where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market”
Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.