EU regulationEU market
CRA
Cyber Resilience Act (EU) 2024/2847
The Cyber Resilience Act sets essential cybersecurity requirements for hardware and software products placed on the EU market, and vulnerability-handling duties for their manufacturers over the support period. Reporting obligations apply from 11 September 2026 and the full regulation from 11 December 2027.
Who it reaches
- Manufacturers of software and connected hardware sold in the EU, wherever they are established.
- Importers and distributors of such products.
- Open-source stewards, under a lighter regime, where software is developed in a commercial context.
What the audit checks
- 01Default products: self-assessment against Annex I, technical documentation and an EU declaration of conformity with CE marking.
- 02Important class I products: harmonised standards or third-party assessment; class II and critical products: third-party assessment by a notified body.
- 03Readiness audits check the secure development lifecycle, SBOM, vulnerability handling and the support period commitments.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Product classification | 1 to 3 |
| Gap assessment against Annex I | 2 to 4 |
| Secure development, SBOM, vulnerability handling | 12 to 36 |
| Conformity assessment and documentation | 4 to 12 |
Evidence to have ready
- Product classification with reasoning
- Cybersecurity risk assessment for the product
- Secure development lifecycle records
- Software bill of materials
- Coordinated vulnerability disclosure policy and contact
- Security update process and support period statement
- Technical documentation per Annex VII
- EU declaration of conformity
- Incident and exploited-vulnerability reporting process
Dates
- CRA reporting obligations apply
- CRA applies in full
Questions people ask
- Is SaaS in scope of the CRA?
- Mostly not as a product, unless it is remote data processing that a product depends on. Software you ship to customers, including client applications and on-premise components, is in scope.
- What has to be reported and when?
- From 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT within 24 hours of awareness, with follow-ups at 72 hours and 14 days.