What Does CRA Compliance Mean?
CRA compliance refers to meeting all requirements set forth by the EU Cyber Resilience Act (Regulation 2024/2847) for products with digital elements. This means your product satisfies the essential cybersecurity requirements and you have completed the necessary conformity assessment procedures.
Compliance = Market Access
Without CRA compliance, products cannot be legally placed on the EU market after December 11, 2027. This applies regardless of where the product is manufactured—if you sell in the EU, you must comply.
The Three Pillars of CRA Compliance
Security Requirements
Your product must meet the essential cybersecurity requirements in Annex I, including secure design, data protection, and access control.
Vulnerability Management
You must have processes to identify, document, and fix security vulnerabilities throughout the product's entire lifecycle.
Documentation
Technical documentation, SBOM, and user information must be maintained and available for authorities.
Who Must Achieve CRA Compliance?
The CRA applies to all economic operators in the supply chain, with different obligations:
Manufacturers
Primary responsibility. Must:
- Design and build products meeting Annex I requirements
- Perform conformity assessment (self or third-party)
- Create and maintain technical documentation
- Affix CE marking
- Handle vulnerability disclosure and patching
Importers
Due diligence obligations. Must:
- Verify manufacturer has completed conformity assessment
- Ensure CE marking is present
- Check documentation is available
- Not import non-compliant products
Distributors
Verification responsibilities. Must:
- Verify CE marking before making available
- Not supply products known to be non-compliant
- Cooperate with market surveillance authorities
Steps to Achieve CRA Compliance
Follow this practical roadmap to prepare your organization for CRA compliance:
Determine Product Classification
Assess if your product is Default, Important (Class I or II), or Critical. This determines your conformity assessment path.
Take Classification Assessment →Perform Gap Analysis
Compare your current security practices against CRA Annex I requirements. Identify what needs to change.
Explore All Requirements →Implement Security Controls
Update your product to meet secure-by-default, access control, data protection, and other requirements.
Establish Vulnerability Management
Set up coordinated disclosure, tracking, and patch distribution processes.
VDP Builder Tool →Prepare Documentation
Compile technical documentation file as per Annex VII requirements.
Complete Conformity Assessment
Self-assessment (for Standard/Class I with standards) or engage a Notified Body (for Class II/Critical).
Affix CE Marking
Once compliant, apply the CE mark to the product and packaging.
CRA Compliance Deadlines
Key dates for planning your compliance journey:
CRA Entered into Force
Regulation became EU law. Transition period begins.
Reporting Obligations Start
Manufacturers must report vulnerabilities and incidents to ENISA.
Full Compliance Required
All products must be CRA compliant to be sold in the EU.
⏰ Start Now
With less than 2 years until full enforcement, organizations should begin compliance efforts immediately. Product redesigns, process changes, and documentation can take 12-18 months.
Frequently Asked Questions
Is CRA compliance mandatory?
Yes. After December 11, 2027, products not meeting CRA requirements cannot be legally sold on the EU market. This applies to products manufactured anywhere in the world if they are sold in the EU.
Does CRA apply to SaaS products?
The CRA applies primarily to products, not pure services. However, if your SaaS includes downloadable components or client-side software, those elements may be covered.
What about open source software?
Open source software developed in a non-commercial context is generally exempt. However, if you monetize the software or provide it as part of a commercial product, standard CRA obligations apply.
Can I self-certify for CRA compliance?
For the Standard category and Class I products (when following harmonised standards), you can use Module A self-assessment. Class II and Critical products require third-party Notified Body involvement.
Start Your CRA Compliance Journey
Use our free assessment tool to understand your product's classification and get a personalized roadmap.