The Cyber Resilience Act makes cybersecurity a condition for placing products with digital elements on the EU market. Manufacturers must design products securely, handle vulnerabilities, document compliance and, for most products, affix the CE marking.
The Cyber Resilience Act is Regulation (EU) 2024/2847. It entered into force on 10 December 2024. Reporting obligations have applied since 11 September 2026. Most other obligations apply from 11 December 2027.
What the CRA covers
The CRA applies to products with digital elements made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network (Article 2(1)). A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately (Article 3(1)).
That covers connected consumer devices, industrial equipment with software, firmware, standalone software and mobile applications. Some products are excluded because other EU rules cover them, such as medical devices, motor vehicles and certified aviation products (Article 2(2) to (4)).
What the CRA requires from manufacturers
| Area | What the regulation says | Where |
|---|---|---|
| Secure design | Products meet the essential cybersecurity requirements based on a risk assessment | Article 13, Annex I Part I |
| Vulnerability handling | Identify, document and remediate vulnerabilities, with an SBOM and a disclosure policy | Annex I Part II |
| Support period | Handle vulnerabilities for the support period, at least five years unless the product is expected to be used for less | Article 13(8) |
| Documentation | Technical documentation and user information | Article 31, Annexes II and VII |
| Conformity | Conformity assessment, EU declaration of conformity and CE marking | Articles 28 to 32 |
| Reporting | Actively exploited vulnerabilities and severe incidents: 24 h, 72 h and final report | Article 14 |
What this means for manufacturers
The regulation is about the product, not the organisation. A company can hold an ISO 27001 certificate and still have no documented risk assessment for a specific firmware release. The CRA asks what was done for this product, and for the evidence.
Penalties are set by Member States within a ceiling in Article 64: up to EUR 15 million or 2.5 percent of worldwide annual turnover, whichever is higher, for non-compliance with Annex I and Articles 13 and 14.
- A documented, dated cybersecurity risk assessment per product
- An SBOM per release and a vulnerability handling record
- The technical file described in Annex VII
- The support period decision and its rationale
- Records showing that the reporting workflow works
Treating the CRA as a documentation exercise for 2027. Reporting has applied since 11 September 2026, and design decisions made today decide how hard conformity will be.
Next step
Read the scope guide, the CRA timeline and the CRA SBOM requirements.
We help manufacturers turn this requirement into a process and evidence.
Related guidance
- CRA timeline: what applies in 2026 and 2027
- Does the Cyber Resilience Act apply to your product?
- CRA reporting obligations: 24 hours, 72 hours and final report
- CRA SBOM requirements: what is actually required?
This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.