What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is an EU regulation (officially: Regulation (EU) 2024/2847) that establishes cybersecurity requirements for all products with digital elements sold in the European Union.
Unlike previous regulations that focused on specific sectors, the CRA applies horizontally across all digital products—from consumer IoT devices to enterprise software, industrial control systems, and embedded firmware.
Key Takeaway
If your product connects to a network, processes data, or contains software, the Cyber Resilience Act likely applies to you. Compliance is mandatory for EU market access starting December 2027.
What Makes CRA Different?
- Product lifecycle coverage: Security must be maintained throughout the product's entire support period, not just at launch
- Vulnerability management: Mandatory disclosure and patching requirements with specific timelines
- Transparency: Users must be informed about security support timeframes and how to report vulnerabilities
- CE marking: Products must bear CE marking to demonstrate CRA compliance
Who Does the Cyber Resilience Act Apply To?
The CRA defines economic operators with different responsibilities based on their role in the supply chain:
Manufacturers
Any entity that designs, develops, or produces products with digital elements—including software publishers and vendors of software with downloadable components.
Primary responsibility for CRA compliance
Importers
Companies that bring products from outside the EU into the European market. Must verify manufacturer compliance.
Due diligence obligations
Distributors
Retailers and wholesalers that make products available on the EU market. Must not sell non-compliant products.
Verification responsibilities
Products Covered by CRA
The regulation covers a broad range of products with digital elements:
- Software applications (desktop, mobile)
- Operating systems and firmware
- IoT devices (smart home, wearables, industrial sensors)
- Network equipment (routers, firewalls, switches)
- Industrial control systems
- Connected toys and consumer electronics
- SaaS with downloadable components (apps, agents, SDKs)
Limited Exemptions
Some products are exempt, including those already covered by sector-specific regulations (e.g., medical devices under MDR, automotive under UNECE), open-source software developed non-commercially, and certain national security products.
CRA Timeline & Enforcement Dates
The Cyber Resilience Act was adopted in 2024 with a phased implementation timeline:
CRA Adopted
Regulation (EU) 2024/2847 published in the Official Journal
Entry into Force
CRA officially enters into force, 20 days after publication
Notified Body Rules Apply
Rules for conformity assessment bodies become applicable (18 months after entry)
Reporting Obligations Start
Vulnerability and incident reporting to ENISA/CSIRTs becomes mandatory (21 months)
Full Enforcement
All CRA requirements become mandatory. Products must be compliant to be sold in the EU.
CRA Requirements Explained (Plain English)
The CRA's security requirements are defined in Annex I, split into two parts:
Part I: Product Security
Requirements for the product itself:
- Secure by default configuration
- Protection against unauthorized access
- Data confidentiality and integrity
- Minimal attack surface
- Incident impact mitigation
- Security logging and monitoring
Part II: Vulnerability Handling
Requirements for ongoing security management:
- Vulnerability identification and documentation
- Coordinated vulnerability disclosure (CVD)
- Timely security patches and updates
- Software Bill of Materials (SBOM)
- User notification of vulnerabilities
Want to explore all 22 CRA requirements in detail?
Open Requirements Explorer →CRA for Software Products
Software products—including desktop applications, mobile apps, web applications, and SaaS platforms—are explicitly covered by the Cyber Resilience Act. Key considerations:
Classification Categories
Software products are classified based on their risk profile, which determines the conformity assessment procedure:
Not sure how your product is classified?
Take the Classification Assessment →CRA for IoT & Hardware Products
IoT devices and hardware with digital elements face particular scrutiny under the CRA, as they often have longer deployment lifespans and are more difficult to update.
Specific Requirements for IoT
- Over-the-air updates: Secure update mechanisms must be built in from design
- Default security: No universal default passwords; unique credentials per device
- Physical security: Tamper resistance where appropriate
- Minimum viability: Device must remain functional even without network connectivity
- Support period: Extended support often required (5+ years for consumer devices)
Hardware-Specific Challenges
Unlike software, hardware cannot be easily recalled and patched. Plan for extended security support and ensure your update distribution infrastructure can reach deployed devices throughout their lifecycle.
SBOM & Documentation Requirements
The CRA mandates a Software Bill of Materials (SBOM) for all products with digital elements, along with comprehensive technical documentation.
What CRA Requires for SBOM
- Machine-readable format (CycloneDX or SPDX recommended)
- At minimum: top-level dependencies
- Component names, versions, and suppliers
- Update upon each release
Required Documentation (Annex VII)
- Product description and intended use
- Design and development documentation
- Cybersecurity risk assessment
- Test reports and conformity evidence
- Instructions for secure installation and use
- Vulnerability handling procedures
Need help creating your first SBOM?
SBOM Generator Guide →Penalties & Non-Compliance Risks
The Cyber Resilience Act includes significant enforcement mechanisms:
Financial Penalties
- Up to €15 million or 2.5% of global turnover (whichever is higher) for essential requirement violations
- Up to €10 million or 2% of turnover for other violations
- Up to €5 million or 1% of turnover for providing incorrect information
Market Consequences
- Product ban: Authorities can prohibit sale of non-compliant products
- Recalls: Mandatory product recalls can be ordered
- Public disclosure: Non-compliance may be publicly announced
- CE marking removal: Products cannot bear CE marking
How to Prepare for CRA (Engineering Checklist)
Start your CRA compliance journey with these practical steps:
Assess Your Product Classification
Determine if your product is Standard, Class I, Class II, or Critical. This affects your conformity assessment path.
Take Assessment →Conduct a Gap Analysis
Review CRA Annex I requirements against your current security practices. Identify what needs to change.
Explore Requirements →Implement Core Security Controls
Prioritize secure-by-default configuration, access control, and data protection.
Set Up Vulnerability Management
Establish processes for vulnerability disclosure, tracking, and patching.
VDP Builder →Prepare Documentation
Compile technical documentation file as required by Annex VII.
Plan Conformity Assessment
For Class II/Critical products, identify Notified Bodies and budget for third-party assessment.
Deep Dive Topics
Explore specific CRA topics in more detail:
CRA Compliance Guide
What compliance means for manufacturers, importers, and distributors.
→All 22 CRA Requirements
Complete Annex I requirements explained in plain English.
→SBOM Requirements
Software Bill of Materials requirements and tools.
→Vulnerability Management
Disclosure policies, patching, and reporting.
→CRA for Software
Desktop, mobile, web apps, and SaaS products.
→CRA for IoT
Connected devices, smart home, industrial IoT.
→Compliance Checklist
Actionable roadmap for engineering teams.
→Free Compliance Tools
Our toolkit includes free tools to help you prepare for CRA compliance:
Assessment Wizard
6-minute assessment to determine your product classification and compliance gaps.
Start Assessment
Requirements Explorer
Track your progress against all 22 CRA requirements with filtering and search.
Explore Requirements
Compliance Dashboard
Visual overview of your readiness score and compliance progress.
View Dashboard
VDP & security.txt Generator
Generate CRA-compliant vulnerability disclosure policies instantly.
Generate VDPReady to Start Your CRA Compliance Journey?
Take our free 6-minute assessment to understand your product's classification and get a personalized compliance roadmap.
Start Free CRA Assessment