EU Regulation 2024/2847

Cyber Resilience Act (CRA)

The complete guide to the EU's new cybersecurity regulation for software, IoT, and hardware products. Learn what's required, who's affected, and how to prepare your engineering team.

Last updated: September 5, 2026

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is an EU regulation (officially: Regulation (EU) 2024/2847) that establishes cybersecurity requirements for all products with digital elements sold in the European Union.

Unlike previous regulations that focused on specific sectors, the CRA applies horizontally across all digital products—from consumer IoT devices to enterprise software, industrial control systems, and embedded firmware.

Key Takeaway

If your product connects to a network, processes data, or contains software, the Cyber Resilience Act likely applies to you. Compliance is mandatory for EU market access starting December 2027.

What Makes CRA Different?

  • Product lifecycle coverage: Security must be maintained throughout the product's entire support period, not just at launch
  • Vulnerability management: Mandatory disclosure and patching requirements with specific timelines
  • Transparency: Users must be informed about security support timeframes and how to report vulnerabilities
  • CE marking: Products must bear CE marking to demonstrate CRA compliance

Who Does the Cyber Resilience Act Apply To?

The CRA defines economic operators with different responsibilities based on their role in the supply chain:

Manufacturers

Any entity that designs, develops, or produces products with digital elements—including software publishers and vendors of software with downloadable components.

Primary responsibility for CRA compliance

Importers

Companies that bring products from outside the EU into the European market. Must verify manufacturer compliance.

Due diligence obligations

Distributors

Retailers and wholesalers that make products available on the EU market. Must not sell non-compliant products.

Verification responsibilities

Products Covered by CRA

The regulation covers a broad range of products with digital elements:

  • Software applications (desktop, mobile)
  • Operating systems and firmware
  • IoT devices (smart home, wearables, industrial sensors)
  • Network equipment (routers, firewalls, switches)
  • Industrial control systems
  • Connected toys and consumer electronics
  • SaaS with downloadable components (apps, agents, SDKs)

Limited Exemptions

Some products are exempt, including those already covered by sector-specific regulations (e.g., medical devices under MDR, automotive under UNECE), open-source software developed non-commercially, and certain national security products.

CRA Timeline & Enforcement Dates

The Cyber Resilience Act was adopted in 2024 with a phased implementation timeline:

20 Nov 2024

CRA Adopted

Regulation (EU) 2024/2847 published in the Official Journal

10 Dec 2024

Entry into Force

CRA officially enters into force, 20 days after publication

11 Jun 2026

Notified Body Rules Apply

Rules for conformity assessment bodies become applicable (18 months after entry)

11 Sep 2026

Reporting Obligations Start

Vulnerability and incident reporting to ENISA/CSIRTs becomes mandatory (21 months)

11 Dec 2027

Full Enforcement

All CRA requirements become mandatory. Products must be compliant to be sold in the EU.

CRA Requirements Explained (Plain English)

The CRA's security requirements are defined in Annex I, split into two parts:

Part I: Product Security

Requirements for the product itself:

  • Secure by default configuration
  • Protection against unauthorized access
  • Data confidentiality and integrity
  • Minimal attack surface
  • Incident impact mitigation
  • Security logging and monitoring

Part II: Vulnerability Handling

Requirements for ongoing security management:

  • Vulnerability identification and documentation
  • Coordinated vulnerability disclosure (CVD)
  • Timely security patches and updates
  • Software Bill of Materials (SBOM)
  • User notification of vulnerabilities

Want to explore all 22 CRA requirements in detail?

Open Requirements Explorer →

CRA for Software Products

Software products—including desktop applications, mobile apps, web applications, and SaaS platforms—are explicitly covered by the Cyber Resilience Act. Key considerations:

Classification Categories

Software products are classified based on their risk profile, which determines the conformity assessment procedure:

Standard
Most software products. Self-assessment (Module A) is allowed without third-party involvement.
Important (Class I)
Identity management, VPNs, password managers, etc. Third-party assessment required until harmonised CRA standards are published (Article 32) required.
Important (Class II)
Hypervisors, container runtimes, firewalls, intrusion detection. Mandatory third-party assessment.
Critical
Smartcard/secure element systems, HSMs. European cybersecurity certification required where a scheme has been adopted (Article 8(1)); otherwise Notified Body assessment (Article 32(4)).

Not sure how your product is classified?

Take the Classification Assessment →

CRA for IoT & Hardware Products

IoT devices and hardware with digital elements face particular scrutiny under the CRA, as they often have longer deployment lifespans and are more difficult to update.

Specific Requirements for IoT

  • Over-the-air updates: Secure update mechanisms must be built in from design
  • Default security: No universal default passwords; unique credentials per device
  • Physical security: Tamper resistance where appropriate
  • Minimum viability: Device must remain functional even without network connectivity
  • Support period: Extended support often required (5+ years for consumer devices)

Hardware-Specific Challenges

Unlike software, hardware cannot be easily recalled and patched. Plan for extended security support and ensure your update distribution infrastructure can reach deployed devices throughout their lifecycle.

SBOM & Documentation Requirements

The CRA mandates a Software Bill of Materials (SBOM) for all products with digital elements, along with comprehensive technical documentation.

What CRA Requires for SBOM

  • Machine-readable format (CycloneDX or SPDX recommended)
  • At minimum: top-level dependencies
  • Component names, versions, and suppliers
  • Update upon each release

Required Documentation (Annex VII)

  • Product description and intended use
  • Design and development documentation
  • Cybersecurity risk assessment
  • Test reports and conformity evidence
  • Instructions for secure installation and use
  • Vulnerability handling procedures

Need help creating your first SBOM?

SBOM Generator Guide →

Penalties & Non-Compliance Risks

The Cyber Resilience Act includes significant enforcement mechanisms:

Financial Penalties

  • Up to €15 million or 2.5% of global turnover (whichever is higher) for essential requirement violations
  • Up to €10 million or 2% of turnover for other violations
  • Up to €5 million or 1% of turnover for providing incorrect information

Market Consequences

  • Product ban: Authorities can prohibit sale of non-compliant products
  • Recalls: Mandatory product recalls can be ordered
  • Public disclosure: Non-compliance may be publicly announced
  • CE marking removal: Products cannot bear CE marking

How to Prepare for CRA (Engineering Checklist)

Start your CRA compliance journey with these practical steps:

1

Assess Your Product Classification

Determine if your product is Standard, Class I, Class II, or Critical. This affects your conformity assessment path.

Take Assessment →
2

Conduct a Gap Analysis

Review CRA Annex I requirements against your current security practices. Identify what needs to change.

Explore Requirements →
3

Implement Core Security Controls

Prioritize secure-by-default configuration, access control, and data protection.

4

Set Up Vulnerability Management

Establish processes for vulnerability disclosure, tracking, and patching.

VDP Builder →
5

Generate SBOM

Create and maintain a machine-readable Software Bill of Materials.

SBOM Guide →
6

Prepare Documentation

Compile technical documentation file as required by Annex VII.

7

Plan Conformity Assessment

For Class II/Critical products, identify Notified Bodies and budget for third-party assessment.

Deep Dive Topics

Explore specific CRA topics in more detail:

Free Compliance Tools

Our toolkit includes free tools to help you prepare for CRA compliance:

CRA Compliance Assessment Wizard

Assessment Wizard

6-minute assessment to determine your product classification and compliance gaps.

Start Assessment
CRA Requirements Explorer

Requirements Explorer

Track your progress against all 22 CRA requirements with filtering and search.

Explore Requirements
CRA Compliance Dashboard

Compliance Dashboard

Visual overview of your readiness score and compliance progress.

View Dashboard
Vulnerability Disclosure Policy Generator

VDP & security.txt Generator

Generate CRA-compliant vulnerability disclosure policies instantly.

Generate VDP

Ready to Start Your CRA Compliance Journey?

Take our free 6-minute assessment to understand your product's classification and get a personalized compliance roadmap.

Start Free CRA Assessment

CRA Compliance Guides by Industry, Role & Country

Tailored CRA guidance for every product type, team, and EU market.

By industry / product type

Fintech Platforms Mobile Apps AI Startups Medical Devices Automotive Software Smart Home Devices CRM Software B2B SaaS Open Source Software Video Games Industrial Control Systems (ICS) Edtech Platforms Consumer Electronics E-commerce Platforms Point of Sale (POS) Systems HR Tech ERP Software Healthtech Apps Wearable Technology Networking Equipment (Routers/Switches) Cloud Storage Providers Accounting Software Maritime Software Aviation Systems Agritech Platforms Logistics and Supply Chain Software Biometric Scanners Payment Gateways VPN Providers Password Managers Smart Toys Web Browsers Operating Systems Desktop Applications Messaging Apps Cryptocurrency Wallets Smart TVs Drones 3D Printers Robotics Telecommunications Software Marketing Automation Tools Real Estate Software (Proptech) Legaltech Software Virtual Reality (VR) Headsets Augmented Reality (AR) Apps Microservices Architectures APIs Firmware Developers Web Hosting Control Panels