FAQ Last Updated: May 2026

CRA Frequently Asked Questions

Comprehensive answers to common questions about the EU Cyber Resilience Act. Find authoritative information about CRA compliance, requirements, and timelines.

Quick Answer: Does CRA Apply to My SaaS?

It depends on your architecture. Pure browser-based SaaS is generally not covered by CRA — Recital (12) explicitly excludes cloud services not tied to a physical product. NIS2 applies instead. CRA does apply to downloadable components (mobile apps, desktop clients, SDKs) and cloud backends supporting a product with digital elements.

Check Your Requirements (6 min) →

CRA Basics

What is the EU Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act (CRA), officially EU Regulation 2024/2847, is a comprehensive EU regulation that establishes mandatory cybersecurity requirements for products with digital elements sold in the European Union.

Key points:
• Applies to hardware and software products that connect to networks or process data
• Covers manufacturers, importers, and distributors
• Requires security throughout a product's lifecycle
• Includes vulnerability management, security updates, and transparent communication
• Full enforcement begins December 11, 2027

Does CRA Apply?

Does the CRA apply to SaaS products?

It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements" — so pure browser-based SaaS is generally NOT covered by CRA. NIS2 applies to such services instead (for organizations of sufficient size).

CRA does apply to:
• Downloadable components — mobile apps, desktop clients, SDKs, agents
• Cloud backends that support a product with digital elements (e.g., the cloud service behind an IoT device)

For in-scope components, typically 8-12 of 22 requirements apply. The free CRA assessment at cra-toolkit.com can determine your specific situation.

Source: EU Regulation 2024/2847, Recital (12)

Does CRA apply to US companies?

Yes, if your US-based company sells products with digital elements to EU customers, the CRA applies to you.

Key points:
• CRA has extraterritorial reach—applies based on where products are sold
• Even sales through distributors or resellers trigger compliance requirements
• Similar to how GDPR applies to non-EU companies processing EU data
• All manufacturers placing products on the EU market must comply

How do I check if CRA applies to my product?

Ask yourself these three questions:

1. Do you sell or make your product available in the EU market?
2. Is your product software or hardware that processes data or connects to networks?
3. Are you the manufacturer (creator/seller) of the product?

If YES to all three → CRA likely applies.

For a detailed assessment of which specific requirements apply to your product, use the free 6-minute assessment at cra-toolkit.com/assessment.

Requirements

What are the main CRA requirements for software?

The main CRA requirements for software products are:

1. Secure by Design (Annex I, Part I, point 1) - Integrate security throughout development
2. Secure by Default (Annex I, Part I, point 2b) - Ship with secure default configurations
3. Software Bill of Materials/SBOM (Annex I, Part II, point 1) - Maintain a list of all software components
4. Vulnerability Handling (Annex I, Part II + Article 13) - Have a process to receive and address security vulnerabilities
5. Security Updates (Annex I, Part I, point 2c + Article 13.8) - Provide security updates for at least 5 years

There are 22 requirements in total: 14 product security requirements (Annex I, Part I) and 8 vulnerability handling requirements (Annex I, Part II). Use our free assessment tool to identify which apply to your product.

What is an SBOM and why does CRA require it?

An SBOM (Software Bill of Materials) is a comprehensive list of all software components, libraries, and dependencies in a product—like an ingredients list for software.

Annex I, Part II, point (1) of the CRA requires manufacturers to identify and document vulnerabilities in components, and Article 13 requires making an SBOM available. The SBOM must cover at minimum top-level dependencies and be in a machine-readable format.

Why required:
• Enables rapid identification of affected products when vulnerabilities are discovered (e.g., Log4j)
• Provides transparency about third-party components and their security status
• Supports vulnerability management and incident response

Free SBOM tools: CycloneDX, Syft, Trivy

Timeline & Deadlines

When does CRA enforcement begin?

CRA enforcement happens in phases:

• November 20, 2024 - CRA published in Official Journal
• December 10, 2024 - CRA enters into force
• June 11, 2026 - Conformity assessment body notification requirements apply (Chapter IV)
• September 11, 2026 - Vulnerability and incident reporting obligations begin (Article 14)
• December 11, 2027 - Full enforcement of all requirements

Organizations should begin compliance preparations now to meet these deadlines.

Costs & Funding

How much does CRA compliance cost?

CRA compliance costs vary significantly:

Consultant route:
• Initial assessment: €8,000-€15,000
• Full implementation: €20,000-€50,000+

DIY route with free tools:
• CycloneDX for SBOM generation: €0
• OWASP Dependency-Track for vulnerability monitoring: €0
• Trivy for container scanning: €0
• Semgrep for static analysis: €0

EU Funding: SMEs can apply for up to €30,000 in grants through the SECURE/Secure4sme program (50% co-financing). Applications at secure4sme.eu.

The free CRA Compliance Toolkit at cra-toolkit.com helps identify which requirements apply, potentially saving thousands in consultant fees.

Exemptions

What products are exempt from CRA?

The following categories are outside CRA scope or explicitly exempt (Article 2):

1. Products not made available on the EU market — software or hardware used exclusively within the manufacturer's own organisation and never supplied to any external party. This is a scope boundary: CRA only applies to products 'made available on the market' per Article 2(1). There is no exemption article for internal use — it is simply outside scope.
2. Products covered by sector-specific EU regulations: medical devices (2017/745 — Article 2(2)(a)) and in vitro diagnostic devices (2017/746 — Article 2(2)(b)), motor vehicles (2019/2144 — Article 2(2)(c)), civil aviation equipment certified under Regulation 2018/1139 (Article 2(3)), marine equipment under Directive 2014/90 (Article 2(4))
3. Spare parts — components placed on the EU market to replace identical components and manufactured to the same specifications as the original (Article 2(6))
4. Military, defence, and national security products — products developed or modified exclusively for national security or defence purposes, or products specifically designed to process classified information (Article 2(7))
5. Non-commercial open-source software — software developed and supplied outside any commercial activity (Recital 18). Commercial entities distributing open-source software remain liable under CRA for that distribution.

Important — no exemption for bespoke software: There is NO CRA exemption for custom or bespoke software developed for a single client. If you develop software under contract and deliver it to a customer, you are placing a product on the EU market and CRA applies. The out-of-scope boundary under Article 2(1) applies only where the software is never supplied to any external party and is used solely within your own organisation.

CRA vs Other Regulations

What is the difference between CRA and NIS2?

CRA and NIS2 are complementary EU regulations with different focuses:

CRA (Cyber Resilience Act):
• Focus: PRODUCT security
• Applies to: Hardware and software products
• Requirements: SBOM, vulnerability handling, security updates

NIS2 (Network and Information Security Directive 2):
• Focus: ORGANIZATIONAL security
• Applies to: Essential and important entities
• Requirements: Risk management, incident reporting, governance

Companies may need both: NIS2 for organizational practices, CRA for manufactured products.

Enforcement & Penalties

What are the penalties for CRA non-compliance?

CRA non-compliance can result in significant penalties (Article 64):

• Tier 1 — Up to €15 million or 2.5% of global annual turnover (whichever is higher): non-compliance with essential cybersecurity requirements (Annex I), and failure to meet manufacturer obligations under Article 13 (risk assessment, technical documentation, vulnerability handling, support period) or Article 14 (mandatory 24-hour reporting of actively exploited vulnerabilities and severe incidents to ENISA and national CSIRT)
• Tier 2 — Up to €10 million or 2% of global annual turnover: failure to meet conformity assessment and market placement obligations — CE marking (Articles 30–31), EU Declaration of Conformity (Article 28), conformity assessment procedures (Article 32), and obligations of authorised representatives, importers, and distributors (Articles 18–23)
• Tier 3 — Up to €5 million or 1% of global annual turnover for providing incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities in response to a request (Article 64(4))
• Products may be recalled or withdrawn from the EU market
• Market surveillance authorities can prohibit or restrict market placement

Compliance is essential for continued access to the EU single market.

Implementation Guide

How do I create a vulnerability disclosure policy for CRA?

A coordinated vulnerability disclosure policy is required by Annex I, Part II, point (5). Here's how to create one:

1. Set up a security contact address (e.g., security@yourdomain.com) — required by Annex I, Part II, point (6)
2. Create a security.txt file at /.well-known/security.txt
3. Publish a coordinated vulnerability disclosure policy page on your website
4. Establish mandatory Article 14 reporting procedures:
• 24 hours: early warning to ENISA and national CSIRT when an actively exploited vulnerability or severe incident is discovered
• 72 hours: full vulnerability/incident notification with general information about the exploit and corrective measures taken
• 14 days: final report after a corrective or mitigating measure is available
5. Establish a process for tracking and patching reported vulnerabilities

The CRA Toolkit includes a free security.txt generator and policy templates at cra-toolkit.com/tools.

Ready to assess your product?

Answer 30 questions and get your personal CRA compliance score with a prioritised action plan.

Official Resources