← Back to CRA Guide

CRA Compliance: What It Means and How to Achieve It

A practical guide for manufacturers, importers, and distributors selling digital products in the EU.

Last updated: September 5, 2026

What Does CRA Compliance Mean?

CRA compliance refers to meeting all requirements set forth by the EU Cyber Resilience Act (Regulation 2024/2847) for products with digital elements. This means your product satisfies the essential cybersecurity requirements and you have completed the necessary conformity assessment procedures.

Compliance = Market Access

Without CRA compliance, products cannot be legally placed on the EU market after December 11, 2027. This applies regardless of where the product is manufactured—if you sell in the EU, you must comply.

The Three Pillars of CRA Compliance

Security Requirements

Your product must meet the essential cybersecurity requirements in Annex I, including secure design, data protection, and access control.

Vulnerability Management

You must have processes to identify, document, and fix security vulnerabilities throughout the product's entire lifecycle.

Documentation

Technical documentation, SBOM, and user information must be maintained and available for authorities.

Who Must Achieve CRA Compliance?

The CRA applies to all economic operators in the supply chain, with different obligations:

Manufacturers

Primary responsibility. Must:

  • Design and build products meeting Annex I requirements
  • Perform conformity assessment (self or third-party)
  • Create and maintain technical documentation
  • Affix CE marking
  • Handle vulnerability disclosure and patching

Importers

Due diligence obligations. Must:

  • Verify manufacturer has completed conformity assessment
  • Ensure CE marking is present
  • Check documentation is available
  • Not import non-compliant products

Distributors

Verification responsibilities. Must:

  • Verify CE marking before making available
  • Not supply products known to be non-compliant
  • Cooperate with market surveillance authorities

Steps to Achieve CRA Compliance

Follow this practical roadmap to prepare your organization for CRA compliance:

1

Determine Product Classification

Assess if your product is Default, Important (Class I or II), or Critical. This determines your conformity assessment path.

Take Classification Assessment →
2

Perform Gap Analysis

Compare your current security practices against CRA Annex I requirements. Identify what needs to change.

Explore All Requirements →
3

Implement Security Controls

Update your product to meet secure-by-default, access control, data protection, and other requirements.

4

Establish Vulnerability Management

Set up coordinated disclosure, tracking, and patch distribution processes.

VDP Builder Tool →
5

Create SBOM

Generate and maintain a Software Bill of Materials for your product.

SBOM Guide →
6

Prepare Documentation

Compile technical documentation file as per Annex VII requirements.

7

Complete Conformity Assessment

Self-assessment (for Standard/Class I with standards) or engage a Notified Body (for Class II/Critical).

8

Affix CE Marking

Once compliant, apply the CE mark to the product and packaging.

CRA Compliance Deadlines

Key dates for planning your compliance journey:

December 2024

CRA Entered into Force

Regulation became EU law. Transition period begins.

September 2026

Reporting Obligations Start

Manufacturers must report vulnerabilities and incidents to ENISA.

11 December 2027

Full Compliance Required

All products must be CRA compliant to be sold in the EU.

⏰ Start Now

With less than 2 years until full enforcement, organizations should begin compliance efforts immediately. Product redesigns, process changes, and documentation can take 12-18 months.

Frequently Asked Questions

Is CRA compliance mandatory?

Yes. After December 11, 2027, products not meeting CRA requirements cannot be legally sold on the EU market. This applies to products manufactured anywhere in the world if they are sold in the EU.

Does CRA apply to SaaS products?

The CRA applies primarily to products, not pure services. However, if your SaaS includes downloadable components or client-side software, those elements may be covered.

What about open source software?

Open source software developed in a non-commercial context is generally exempt. However, if you monetize the software or provide it as part of a commercial product, standard CRA obligations apply.

Can I self-certify for CRA compliance?

For the Standard category and Class I products (when following harmonised standards), you can use Module A self-assessment. Class II and Critical products require third-party Notified Body involvement.

Start Your CRA Compliance Journey

Use our free assessment tool to understand your product's classification and get a personalized roadmap.