Cyber Resilience Act (CRA)
The Cyber Resilience Act (CRA) is the EU regulation with binding cybersecurity minimum requirements for products with digital elements. From 11 September 2026, reporting obligations apply for actively exploited vulnerabilities; from 11 December 2027, all requirements apply, including CE marking. The CRA is the first EU regulation to make cybersecurity a market access requirement across products and industries.
Who does the CRA apply to?
Affected are products with digital elements — that is, hardware and software with a data connection. The rule of thumb: software with an external interface falls under the CRA. The obligations primarily affect manufacturers, but also importers and distributors who make such products available in the EU. Exempt are products without digital elements, sector-specific regulated areas (e.g., medical, automotive) and special cases such as open-source software without commercial intent.
The three critical dates
| Date | What applies |
|---|---|
| 10 December 2024 | The CRA entered into force. |
| 11 September 2026 | The reporting obligations take effect: actively exploited vulnerabilities and serious incidents must be reported to ENISA and the national CSIRT — early warning within 24 hours, full notification within 72 hours, final report no later than 14 days after a remedy is available. |
| 11 December 2027 | Full application: all requirements apply to products placed on the EU market, including conformity assessment, CE marking and technical documentation. |
What obligations does the CRA bring?
The CRA requires technical and organisational measures across the entire product lifecycle:
- Security by Design and Security by Default: build security in from the concept phase and deliver products in a secure default configuration.
- Cyber risk assessment: the basis for every measure is a documented risk analysis of the product — methodically, this is what a TARA delivers.
- Vulnerability management: vulnerability handling throughout the entire support period, including a published CVD policy (Coordinated Vulnerability Disclosure) with a designated point of contact.
- SBOM: a machine-readable Software Bill of Materials of all software components must be created and maintained.
- Reporting obligations: actively exploited vulnerabilities and serious incidents must be reported to ENISA and the national CSIRT in parallel.
- Lifecycle maintenance: free security updates for the expected product lifetime, but at least five years; technical documentation must be retained for at least ten years.
The conformity assessment procedure depends on the risk class: standard products are self-assessed, important products (class I and II) are subject to stricter requirements — in some cases with third-party assessment by a notified body — and critical products require mandatory certification. Violations can result in fines of up to 15 million euros or 2.5% of worldwide annual turnover.
The CRA in practice: the deadline is 2026, not 2027
The most common misconception is the date: the reporting obligations under Article 14 take effect fifteen months before full applicability — and via Article 69(3) they also cover existing products already on the market. Anyone starting only in 2027 has missed the critical milestone. The viable order: first build reporting and disclosure processes, then integrate risk assessment, SBOM and security engineering into the development processes. A structured roadmap is provided by our 7-step guide to the CRA.


