Skip to main content
EU Regulation

EU Cyber Resilience Act (CRA): Compliance Roadmap to 2027

The EU Cyber Resilience Act sets two hard deadlines: from 11 September 2026, reporting obligations apply for actively exploited vulnerabilities and serious security incidents. From 11 December 2027, all products with digital elements must meet the full requirements. Does your product have digital elements and external interfaces? Then it almost certainly falls under the CRA.

The Regulation

What the CRA Requires: and When

The Cyber Resilience Act is the first EU regulation with binding cybersecurity minimum requirements for all connected products on the EU market. It applies across products and industries.

Scope. Products with digital elements are affected: hardware and software with a data connection. The obligations apply to manufacturers, but also to importers and distributors who make such products available in the EU.

Core principles. Security by Design: build security in from the concept phase. Security by Default: secure default configuration at the point of delivery. Lifecycle responsibility: vulnerability management, update management and reporting obligations throughout the entire support period.

Penalties. Violations of the essential cybersecurity requirements can result in fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.

The Three Critical Dates

10 December 2024: The CRA entered into force.

11 September 2026: Reporting obligations take effect. Actively exploited vulnerabilities and serious incidents must be reported to ENISA: early warning within 24 hours, full notification within 72 hours, final report no later than 14 days after a remedy is available. → What manufacturers need to build before September 2026

11 December 2027: Full application. All requirements apply to products placed on the EU market, including conformity assessment, CE marking and technical documentation.

Cyber Resilience Act – Full application

00 Days
00 Hours
00 Minutes
00 Seconds

Click to switch view

Scope

Am I Affected? The First Self-Check

Rule of thumb: software with an external interface falls under the CRA. Exempt are products without digital elements, sector-specifically regulated areas (e.g. medical devices, automotive) and special cases such as open-source without commercial intent.

Standard Products

The majority of products. Self-assessment by the manufacturer. No third party needs to be involved.

Important Products (Class I and II)

Stricter requirements, partly requiring evidence through harmonised standards or assessment by a notified body (third-party assessment).

Critical Products

Highest tier. Mandatory certification by a notified body.
GAP Analysis

Where do you stand? Measuring maturity across 7 areas

The GAP Analysis checks whether your processes, documents and product characteristics cover the 64 CRA requirements — across seven areas: scope, governance, risk assessment (TARA), product requirements from Annex I, vulnerability management, reporting obligations, and documentation. Each checkpoint is rated on a scale from 0 (not present) to 3 (fully implemented, audit-ready).

The evaluation shows the compliance level per area and makes visible where a dedicated implementation project is needed and where fine-tuning suffices. If the TARA or vulnerability management areas fall below 66 %, a consultation is the next sensible step.

Recommendation: Carry out the analysis together with product management, development and quality assurance, and link supporting evidence directly. Repeat quarterly — this turns it into a progress instrument until December 2027.

Radar diagram: CRA maturity across seven areas
For US Manufacturers

Selling into the EU from the US? The CRA applies to you

The CRA does not regulate European companies. It regulates products on the European market. If your hardware or software with a data connection is sold in the EU, you carry the full manufacturer obligations — and your EU importers and distributors are legally required to verify your compliance before they place your product on the market.

Most US manufacturers do not start from zero. Security practices built on NIST SSDF, IEC 62443 or FDA premarket documentation already cover part of the ground. We map that existing evidence onto the CRA requirements and close the remaining gaps, instead of running a second, parallel compliance program.

itemis delivers this from both sides of the Atlantic: contracting with itemis Inc. in Chicago, meetings in your time zone, deliverables in English — backed by the compliance team in Germany, in the market where the CRA is implemented, with the CRAIG network for legal and standardization questions. Your contact in the US:

Jonathan Mohring

President, itemis Inc. · itemis AG

Jonathan Mohring is the President of itemis Inc. in the US. Prior to itemis, he spent over 20 years at Honda, Chrysler, and Daimler in Europe and the US driving innovation in the areas of engineering IT, software automation and data strategy. As President of itemis Inc., he is responsible for all operations and customers in North America. Jonathan holds a degree in Mechanical Engineering from the University of Toledo and an MBA in Technology and Innovation Management from the University of Stuttgart.

Schedule a consultation

Roadmap

What to Do by 2026 and 2027

Immediately: by September 2026

  • Establish a vulnerability disclosure process.
  • Set up an incident response process with a robust 24-hour reporting path.
  • Clarify contacts at ENISA and the national CSIRTs.
  • Assign responsibilities: for example a Product Security Officer.

Medium-term: by December 2027

  • Cyber risk assessment / TARA for all CRA-relevant products.
  • Integrate security requirements firmly into engineering processes.
  • Maintain a Software Bill of Materials (SBOM) for each product.
  • Vulnerability management across the entire lifecycle.
  • Lifecycle management: updates, patches and a clear end-of-support strategy.
  • Conformity assessment and CE marking with cybersecurity reference.

Two of these building blocks reach deep into adjacent topics. The TARA is methodologically part of cybersecurity. → Cyber Security And end-to-end traceability of requirements is mandatory once you need to evidence security requirements across tools. → Requirements Traceability

Responsibility

Who Is Liable? The Chain of Responsibility

The CRA distributes obligations along the entire supply chain. Every link can be held accountable for non-compliance.

Manufacturers

The primary responsibility lies here. They must carry out the cyber risk assessment (TARA), demonstrably design the product to be secure, and maintain technical documentation throughout the entire lifecycle.

Importers

They verify that the manufacturer has fulfilled all CRA obligations: CE marking, documentation, conformity assessment. Importers thereby assume direct liability.

Distributors

They must ensure that the product carries a valid CE marking and that all required instructions are included before it is sold to end customers.
CRAIG

CRAIG — the European CRA Community

CRAIG is a non-profit ASBL under Belgian law, founded on 18 March 2026 in Dortmund at the itemis PODIUM. Its mission: to democratise CRA implementation, especially for SMEs with limited resources.

CRAIG bridges the gap between law and technology. Complex regulatory texts are translated into actionable steps. This happens in two ways: through Local Chapters as a personal network on the ground (first locations: Böblingen and Stuttgart, more in the works) and through online tools such as the scope check, a knowledge base and templates.

Any affected organisation can join. Membership is free for individuals. Anyone who wants to can found their own chapter.

The founding team: Dirk Leopold (Chairman), Tim Scherer, Michael Happ, Janine Funke, Hauke Petersen, Max Schubert and Michael Jesse.

itemis is a strategic sponsor and actively supports the Europe-wide network for CRA implementation.

CRAIG website

The CRAIG founders at itemis PODIUM in Dortmund
Common Misconceptions

Three Assumptions That Will Be Expensive by the Deadline

Many manufacturers have the wrong date in mind, or underestimate who the notification obligation really affects. The three most common mistakes.

"The CRA doesn't apply to us until 2027."

Full applicability arrives on 11 December 2027. The notification obligation under Article 14, however, takes effect fifteen months earlier: on 11 September 2026.

"Only new products are affected."

Article 69(3) extends the notification obligation to all products with digital elements placed on the EU market before 11 December 2027. The year of manufacture is irrelevant.

"One notification to ENISA is enough."

The early warning must reach both ENISA and the national CSIRT in your member state simultaneously. A notification to ENISA alone does not satisfy Article 14.
itemis SECURE

How itemis SECURE and CRAIG Accelerate Implementation

The roles are clearly separated. CRAIG provides community, knowledge and network. itemis SECURE is the platform for technical implementation: model-based TARA, risk assessment and lifecycle management.

How they work together: the community clarifies the WHAT, SECURE delivers the HOW. In itemis SECURE, AI Assistants guide teams through the TARA process, instead of every team starting from scratch in a spreadsheet. The result is a living risk model that updates when new vulnerabilities emerge, not a PDF that is out of date three months later.

Transparency note: CRAIG is non-profit and vendor-neutral. itemis SECURE is our commercial product. We make that distinction openly.

itemis SECURE: Cyber Resilience Act

the cybersecurity engineering tool

TARA, threat modelling, attack trees, vulnerability management: with native support for ISO/SAE 21434 and the EU Cyber Resilience Act. AI-assisted automation reduces TARA effort by up to 80% with full human-in-the-loop control. In production use, among others, at OEMs, Tier-1 suppliers and medical device manufacturers.
Learn more about itemis SECURE
itemis SECURE Screenshot
Our Services

itemis Supports You Along the Entire Path

Each phase is a self-contained entry point. Lifecycle integration is available from the start, not only at the end.

01 Understand

CRA Readiness Assessment

  • GAP analysis against CRA and IEC 62443
  • Product classification: standard, Class I or II
  • Prioritised action plan aligned with the deadlines

2–5 days from kick-off to results

02 Engineer

Security Engineering

  • TARA with itemis SECURE
  • Secure development lifecycle
  • Process setup according to IEC 62443‑4‑1

Security requirements with traceability

03 Operate

Lifecycle Operations

  • SBOM generation and maintenance
  • CVE monitoring and VEX process
  • Vulnerability management throughout the support period

Patch documentation and evidence

04 Automate

Compliance Automation

  • Lifecycle integration into the toolchain
  • Automatically generated audit evidence
  • Traceability from risk to test

A single source of truth for all evidence

Our Experts
Dirk Leopold

Executive Vice President Digital Engineering · itemis AG

Dirk Leopold bridges complex engineering requirements and cybersecurity standards in the automotive and IoT domains. As a driving force behind itemis SECURE, he has deep expertise in Threat Analysis and Risk Assessment (TARA) and “Security by Design” methodologies. As a speaker, he focuses on how standards like ISO/SAE 21434 and the Cyber Resilience Act (CRA) impact the future of connected products. He is co-founder and president of CRAIG, an online community supporting the introduction of the CRA across Europe.
Dr. Stephan Eberle is CTO/CIO of itemis AG, driving the company’s transformation into a product-driven, AI-enabled organisation. With more than 25 years of experience at the intersection of software innovation and engineering, he focuses on auditable, deterministic AI for regulated industries such as automotive, healthcare, and defence. He led itemis to ISO 27001 and TISAX certification in 2025, and to ISO 9001 certification in 2026. Stephan holds a PhD in Engineering from the University of Stuttgart.
Get Started

Book a CRA Readiness Assessment

Schedule a call with Dirk Leopold and Jens Bühl.

FAQ

Frequently Asked Questions about the EU Cyber Resilience Act

Does every known vulnerability trigger the 24-hour notification obligation?
No. Article 14 requires notification only for an actively exploited vulnerability: one where the review indicates with sufficient certainty that actual exploitation is taking place. A merely known or theoretically possible vulnerability with no indication of exploitation does not start the clock.
When does the 24-hour deadline start?
It starts when the manufacturer can assume with sufficient certainty, after an initial review, that a vulnerability is actively being exploited or that a severe incident has occurred. The Commission’s CRA guidelines make clear that the initial review must not be delayed in order to push back the start of the deadline.
Is a notification to ENISA enough, or must I also inform the CSIRT?
Both must receive the notification simultaneously: ENISA and the national CSIRT designated as coordinator in your member state under NIS2. A notification to ENISA alone does not satisfy the obligation under Article 14.
Does the notification obligation in September 2026 also apply to products already on the market?
Yes. Article 69(3) CRA extends the notification obligation to products with digital elements placed on the EU market before 11 December 2027. It is the only provision of the CRA that covers existing products in this way.
Who is liable for vulnerabilities in purchased or open-source components?
The manufacturer who places the product on the market. The notification obligation attaches to the finished product, not to the origin of any individual code component. Vulnerabilities in third-party components therefore fall within your own vulnerability-handling responsibilities.
What constitutes a severe cybersecurity incident under the CRA?
An incident that affects the security of the product with digital elements. Severity and relevance are assessed by factors such as the extent of the impact, the number of users affected, and potential consequences for operations.
What fines are at risk for a violation of the notification obligation?
Under Article 64(2), up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Fines for a missed 24-hour early warning do not apply to micro and small enterprises. No one is exempt from the notification obligation itself, however.
What is a CVD policy (Coordinated Vulnerability Disclosure)?
A published process through which security researchers, customers and other parties can report vulnerabilities in your products. Under Annex I Part II of the CRA, manufacturers must maintain a CVD policy with a named single point of contact and actively encourage disclosure of potential vulnerabilities.
What is the difference between CRA and NIS2?
NIS2 addresses the cybersecurity of organisations and critical infrastructure operators. The CRA governs the security of products themselves. A CRA-compliant product helps NIS2-obligated operators meet their own requirements. Both laws apply at different points in the chain.
We are a US company selling into the EU. Does the CRA apply to us?
Yes. The CRA applies to every product with digital elements placed on the EU market, regardless of where the manufacturer is based. itemis supports US manufacturers from offices in Chicago and Germany — including mapping your existing NIST or IEC 62443 evidence onto the CRA requirements. → How we support US manufacturers
Knowledge

Insights on the Cyber Resilience Act