CRA: cybersecurity for products with digital elements
The Cyber Resilience Act obliges manufacturers, importers and distributors of products with digital elements to provide cybersecurity across the entire lifecycle — from development to the end of support. Unlike NIS2 and DORA it does not attach to industries, but to your role in the supply chain.
Product law, not operator law.
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024 and applies directly across the EU. It treats cybersecurity like product safety: a product with digital elements may only be placed on the EU market if it meets the essential requirements of Annex I — demonstrated through a conformity assessment procedure and visible in the CE marking.
That is the decisive difference to NIS2 and DORA. Those two bind entities by sector and size. The CRA binds economic operators by their role: manufacturers, authorised representatives, importers and distributors. Anyone who merely operates or uses a product is out of scope — NIS2 applies to them instead. Whether you are in scope therefore does not depend on your industry, but on whether you place software or connected devices on the market.
The regulation distinguishes three risk levels. The default case is self-assessment by the manufacturer. Important products (Annex III, split into class I and II — password managers, VPNs, firewalls, microprocessors among others) and critical products (Annex IV — hardware security modules and smart cards among others) require stricter procedures, up to the involvement of a notified body. Exemptions include medical devices (MDR/IVDR), type-approved automotive technology, civil aviation and products exclusively for national security or defence.
Key deadlines
The CRA enters into force
Regulation (EU) 2024/2847, published in the Official Journal on 20 Nov 2024. Entry into force on the twentieth day thereafter; the obligations themselves apply in stages.
The chapter on conformity assessment bodies becomes applicable
From this point notified bodies can be designated — the infrastructure that will later have to assess important and critical products comes into existence in this window.
The reporting duties under Art. 14 become applicable
Manufacturers must report actively exploited vulnerabilities and severe security incidents: early warning within 24 hours, notification within 72 hours, final report within 14 days or one month — through the single reporting platform to the competent CSIRT and to ENISA. This deadline arrives 15 months before full application.
All remaining obligations become applicable
Essential requirements from Annex I, conformity assessment and CE marking, technical documentation, software bill of materials (SBOM), vulnerability handling and a support period of at least five years.
What the CRA asks of you.
Secure by default (Annex I Part I)
Products ship without known exploitable vulnerabilities, with a secure default configuration, access protection, encryption of data at rest and in transit, and the ability to securely delete user data.
Vulnerability handling across the support period (Annex I Part II)
Document vulnerabilities, remediate them without delay, ship security updates free of charge and separately from feature updates, run a contact point for reports and publish a coordinated disclosure policy. The support period is at least five years or the expected lifetime of the product.
Reporting duties (Art. 14) — from 11 Sep 2026
Report actively exploited vulnerabilities and severe security incidents: 24 hours early warning, 72 hours notification, final report within 14 days or one month. The recipients are the competent CSIRT and ENISA via a shared reporting platform.
Software bill of materials and technical documentation
An SBOM in a machine-readable format covering at least the top-level dependencies, plus technical documentation under Annex VII — both to be retained for ten years or for the duration of the support period.
Conformity assessment and CE marking
For the default case internal control by the manufacturer is sufficient. Important products from Annex III and critical products from Annex IV require stricter procedures, involving a notified body for class II and Annex IV. The result is an EU declaration of conformity and the CE marking.
Obligations of importers and distributors
Anyone importing a product from a third country into the EU or reselling it must verify that conformity assessment, CE marking and documentation are in place — and must not make a product available if they have reason to believe it is not compliant. Anyone selling a product under their own name or substantially modifying it counts as a manufacturer themselves.
Product register, reporting clock and evidence in one place.
ReportAct keeps a product register in which every product with digital elements carries its CRA classification — default case, important under Annex III or critical under Annex IV. The classification determines which conformity assessment procedure applies and which evidence you have to keep.
For the Art. 14 reporting duties the same reporting clock runs as for NIS2 and DORA: as soon as an incident is recorded, the deadlines for the 24-hour early warning and the 72-hour notification start visibly — including the CSIRT and ENISA as recipients. If you already run NIS2 or DORA, you do not get a second process here, you get the same one.
The CRA control catalogue hangs on the same sealed evidence chain as the other six frameworks. A piece of evidence you keep for ISO 27001 or NIS2 anyway counts here as well. And through the supplier register a product can be linked to its component suppliers — the basis for everything the CRA demands along the supply chain.
Product/positioning statement, not legal advice. The CRA module covers the product register, classification, reporting clock and control evidence today; machine-readable SBOM processing and the CE conformity run are in progress.
Read it first-hand
ReportAct is not a consultancy. This page does not replace legal advice and makes no claim to completeness. Only the text of the regulation in its applicable version is authoritative. Our Terms apply.
The first CRA deadline is 11 September 2026.
Set up your product register, classify against Annex III and IV, and have the reporting clock in place before the first incident starts it.