All frameworks
EU regulationEU market

CRA

Cyber Resilience Act (EU) 2024/2847

The Cyber Resilience Act sets essential cybersecurity requirements for hardware and software products placed on the EU market, and vulnerability-handling duties for their manufacturers over the support period. Reporting obligations apply from 11 September 2026 and the full regulation from 11 December 2027.

Who it reaches

  • Manufacturers of software and connected hardware sold in the EU, wherever they are established.
  • Importers and distributors of such products.
  • Open-source stewards, under a lighter regime, where software is developed in a commercial context.

What the audit checks

  1. 01Default products: self-assessment against Annex I, technical documentation and an EU declaration of conformity with CE marking.
  2. 02Important class I products: harmonised standards or third-party assessment; class II and critical products: third-party assessment by a notified body.
  3. 03Readiness audits check the secure development lifecycle, SBOM, vulnerability handling and the support period commitments.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Product classification1 to 3
Gap assessment against Annex I2 to 4
Secure development, SBOM, vulnerability handling12 to 36
Conformity assessment and documentation4 to 12

Evidence to have ready

  • Product classification with reasoning
  • Cybersecurity risk assessment for the product
  • Secure development lifecycle records
  • Software bill of materials
  • Coordinated vulnerability disclosure policy and contact
  • Security update process and support period statement
  • Technical documentation per Annex VII
  • EU declaration of conformity
  • Incident and exploited-vulnerability reporting process

Dates

  • CRA reporting obligations apply
  • CRA applies in full
All regulatory deadlines

Questions people ask

Is SaaS in scope of the CRA?
Mostly not as a product, unless it is remote data processing that a product depends on. Software you ship to customers, including client applications and on-premise components, is in scope.
What has to be reported and when?
From 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT within 24 hours of awareness, with follow-ups at 72 hours and 14 days.

Go deeper