EU Regulation 2024/2847

Cyber Resilience Act (CRA)

The new European cybersecurity standard for all products with digital elements. We'll explain who it applies to, the deadlines and obligations — and, above all, get you compliant end to end.

2024/2847
EU Regulation
11 Sep
2026
Incident reporting starts
11 Dec
2027
Full applicability
€15M
Maximum fine
What is the CRA

Product security as a legal requirement

The Cyber Resilience Act is an EU regulation that, for the first time, introduces uniform and mandatory cybersecurity requirements for products with digital elements across their entire lifecycle — from design and development to support on the market.

The goal is to reduce systemic cyber risk across the EU. Security can no longer be an add-on; it must be a standard built in "by design" (security-by-design).

Who it applies to

  • Manufacturers
    incl. non-EU, placing a product on the EU market
  • Importers
    as compliance "gatekeepers" for the EU market
  • Distributors
    responsible for CE marking and documentation
  • Hardware and software
    anything with connectivity or data processing — IoT, applications, embedded systems
Manufacturer obligations

Six pillars of CRA compliance

Security-by-design

Cyber risk assessment and product design with security requirements built in from the very start.

Vulnerability handling

Processes to identify, record and remediate vulnerabilities throughout the support period — at least 5 years.

Conformity assessment & CE

Conformity assessment (self-assessment or via a notified body) and CE marking with the EU declaration of conformity.

Technical documentation

A technical file demonstrating conformity — security tests, threat model, SBOM and patch records.

Incident reporting

Reporting actively exploited vulnerabilities and serious incidents via the ENISA platform — early warning within 24 h.

Transparent support

A clear statement of how long you will provide security updates — disclosed already at the point of sale.

Applicability timeline

Key dates you can't afford to miss

10 Dec 2024

Entry into force

The regulation entered into force; the transition period begins.

11 Jun 2026

Notified bodies

Rules for conformity assessment bodies start to apply.

11 Sep 2026

Reporting obligation

Vulnerability and incident reporting becomes enforceable.

11 Dec 2027

Full applicability

All essential requirements, conformity assessment and CE marking become binding.

Incident reporting

When an incident hits, the clock is ticking

From 11 Sep 2026, strict deadlines apply for reporting actively exploited vulnerabilities and serious incidents via the single ENISA platform.

24 hEarly warning to CSIRT
72 hFull incident notification
14 daysFinal vulnerability report
  • We set up internal processes and templates so the deadlines never catch you off guard.
  • We prepare your team to communicate with the national CSIRT and the supervisory authority.
Fines

Non-compliance gets expensive

Penalties are tiered by the severity of the breach. The higher of the two values applies.

SeverityWhat it coversFine
Highest Breach of essential cybersecurity requirements and the reporting obligation (Art. 13 and 14) €15M / 2.5%
Medium Failures around CE marking, declaration of conformity, documentation or cooperation with authorities €10M / 2%
Lower False, incomplete or misleading information to notified bodies and authorities €5M / 1%

The percentage applies to global annual turnover. Micro and small enterprises have exemptions for some deadlines.

How we help

The path to CRA compliance in three phases

We guide you from the first analysis all the way to ongoing operations once the rules take effect.

Phase 2 · 2026–2027

Implementation & conformity

  • Building the technical documentation and SBOM
  • Preparation for conformity assessment / CE
  • EU declaration of conformity
  • Coordination with a notified body
Phase 3 · Operations

Operation & maintenance

  • Triage and reporting of vulnerabilities (24/72 h)
  • Patch management throughout the support period
  • Maintaining CE and documentation as products change
  • Preparation for supervisory-authority inspections
FAQ

CRA made clear

Does the CRA apply to my company too?
If you place any product with digital elements on the EU market — hardware or software capable of connecting or processing data — the CRA obligations apply to you, whether you're a manufacturer, importer or distributor. In a free consultation we'll help you assess which category you fall into.
What is an SBOM and why do I need one?
An SBOM (Software Bill of Materials) is a structured list of all software components and dependencies in your product. The CRA requires it as part of the technical documentation, because it lets you quickly assess the impact of a newly discovered vulnerability. We'll help you generate and maintain your SBOM.
What's the difference between the CRA and NIS2?
NIS2 regulates the cybersecurity of organisations in important sectors (processes, risk management, reporting). The CRA, by contrast, regulates the security of the products with digital elements themselves. Many companies have to prepare for both — and we'll help you with both.
When should I start working on compliance?
As soon as possible. Implementing security-by-design, reporting processes and complete technical documentation takes months. The reporting obligation applies from September 2026 and full applicability arrives in December 2027 — companies that start early avoid a costly last-minute scramble.

Get ready for the CRA ahead of time

Start with a free consultation. We'll assess whether and how the CRA applies to you and propose concrete next steps.