CRApreparedContact us

Cyber Resilience Act

Cyber Resilience Act (CRA): what it is and what it requires

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It sets mandatory cybersecurity requirements for hardware and software products with digital elements made available on the EU market. Manufacturers must handle vulnerabilities for the support period and report actively exploited vulnerabilities and severe incidents.

Written by: CRAprepared teamExpert: Dejan TropLast reviewed: 2 min read
In short

The Cyber Resilience Act makes cybersecurity a condition for placing products with digital elements on the EU market. Manufacturers must design products securely, handle vulnerabilities, document compliance and, for most products, affix the CE marking.

The Cyber Resilience Act is Regulation (EU) 2024/2847. It entered into force on 10 December 2024. Reporting obligations have applied since 11 September 2026. Most other obligations apply from 11 December 2027.

What the CRA covers

The CRA applies to products with digital elements made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network (Article 2(1)). A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately (Article 3(1)).

That covers connected consumer devices, industrial equipment with software, firmware, standalone software and mobile applications. Some products are excluded because other EU rules cover them, such as medical devices, motor vehicles and certified aviation products (Article 2(2) to (4)).

What the CRA requires from manufacturers

AreaWhat the regulation saysWhere
Secure designProducts meet the essential cybersecurity requirements based on a risk assessmentArticle 13, Annex I Part I
Vulnerability handlingIdentify, document and remediate vulnerabilities, with an SBOM and a disclosure policyAnnex I Part II
Support periodHandle vulnerabilities for the support period, at least five years unless the product is expected to be used for lessArticle 13(8)
DocumentationTechnical documentation and user informationArticle 31, Annexes II and VII
ConformityConformity assessment, EU declaration of conformity and CE markingArticles 28 to 32
ReportingActively exploited vulnerabilities and severe incidents: 24 h, 72 h and final reportArticle 14

What this means for manufacturers

The regulation is about the product, not the organisation. A company can hold an ISO 27001 certificate and still have no documented risk assessment for a specific firmware release. The CRA asks what was done for this product, and for the evidence.

Penalties are set by Member States within a ceiling in Article 64: up to EUR 15 million or 2.5 percent of worldwide annual turnover, whichever is higher, for non-compliance with Annex I and Articles 13 and 14.

Evidence you should maintain
  • A documented, dated cybersecurity risk assessment per product
  • An SBOM per release and a vulnerability handling record
  • The technical file described in Annex VII
  • The support period decision and its rationale
  • Records showing that the reporting workflow works
Common mistake

Treating the CRA as a documentation exercise for 2027. Reporting has applied since 11 September 2026, and design decisions made today decide how hard conformity will be.

Next step

Read the scope guide, the CRA timeline and the CRA SBOM requirements.

Relevant service

We help manufacturers turn this requirement into a process and evidence.

See the service (Slovenian)

Related guidance

Written by: CRAprepared teamExpert: Dejan Trop, Cybersecurity strategistLast reviewed: Editorial policy

This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.

Will your product be CRA prepared?

CRA reporting obligations have applied since 11 September 2026. Most CRA requirements apply from 11 December 2027. We work with manufacturers in Slovenia and across the EU. Write to us in English or Slovenian.