The CRA covers hardware and software whose intended use includes a direct or indirect data connection to a device or network – including components placed on the market separately. The obligations fall primarily on manufacturers as soon as a product is made available on the EU market; importers and distributors are subject to graduated verification and cooperation duties. Product areas with their own sectoral rules are excluded – such as medical devices, motor vehicles, aviation and maritime transport – as is free and open-source software outside a commercial activity.
The EU Cyber Resilience Act
What Regulation (EU) 2024/2847 requires from manufacturers, importers and distributors of products with digital elements – from security by design and SBOM to the reporting deadlines starting 11 September 2026.
24 hEarly warning to CSIRT & ENISA from awareness
€15 MMaximum fine — or 2.5% of global annual turnover
5 yrsMinimum support period, as a rule (Art. 13)
22ENISA principles for secure by design & default
With the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), the EU introduces horizontal cybersecurity requirements for products with digital elements for the first time – from consumer devices and operating systems to industrial components. The regulation entered into force on 10 December 2024 and applies in stages: the reporting obligations for actively exploited vulnerabilities and severe incidents take effect on 11 September 2026, while the remaining obligations, including CE marking, apply from 11 December 2027. Unlike NIS2, which addresses organisations, the CRA targets the product itself: anyone making hardware or software available on the EU market must demonstrate security across the entire product lifecycle. For manufacturers, this means new processes in development, vulnerability management and documentation – with lead times that are now becoming very real.
The CRA deadlines at a glance
Four dates drive implementation — tap a milestone for details.
10 Dec 2024
Entered into force
The CRA (Regulation (EU) 2024/2847) is in force. Obligations apply in stages — the lead time for manufacturers, importers and distributors has been running since this date.
11 Jun 2026
Chapter IV: notified bodies
The rules on notifying conformity assessment bodies apply. The infrastructure for the EU-type examination with subsequent production control (modules B and C) and full quality assurance (module H) is being established.
11 Sep 2026
Reporting duties (Art. 14)
Actively exploited vulnerabilities and severe incidents must be reported: early warning within 24 hours, detailed notification within 72 hours — to the CSIRT and ENISA via the Single Reporting Platform.
11 Dec 2027
Main obligations + CE
All remaining obligations apply: products with digital elements require the CE marking, which then also attests CRA conformity — evidenced by the EU declaration of conformity and technical documentation.
The Essentials at a Glance
Seven topic blocks — tap to expand.
Which product class affects you?
The CRA grades products by risk — each with its own route to demonstrating conformity.
- The manufacturer assesses conformity itself (internal control, module A) — no notified body required.
- All Annex I requirements still apply in full.
- The product's core functionality determines the classification.
- Self-assessment is only permitted if relevant harmonised standards or schemes are applied in full — otherwise third-party assessment.
- Technical descriptions are clarified by Implementing Regulation (EU) 2025/2392.
Password managersBrowsersVPN productsOperating systemsRoutersSIEM systems
- A notified body must be involved: EU-type examination with subsequent production control (modules B and C) or full quality assurance (module H).
Hypervisors & container runtimesFirewallsIntrusion detection/prevention systemsTamper-resistant microprocessors & microcontrollers
- For critical products, a mandatory European cybersecurity certification can be required (scheme under Art. 32).
Smart meter gatewaysSmartcards & secure elements
In-depth whitepaper
CRA Reality Check — Zero-Days, Supply Chain & AI
How manufacturers actually implement the Cyber Resilience Act: the new ENISA playbooks, the 24-hour reporting clock, SBOM/supply chain and AI — as an actionable roadmap for product-security and CISO teams.
ENISA playbooks as release gates
The 22 Secure-by-Design principles, mapped to CRA Annex I.
Zero-days & the 24-hour clock
Article 14 (24/72/14), the Single Reporting Platform and machine-speed exploitation.
Supply chain & SBOM
SBOM per Annex I, component due diligence (Art. 13) and open-source stewards (Art. 24).
AI under the CRA
The CRA–AI Act interface (Art. 12) and AI as a threat accelerant.
Download the whitepaper (free)
English-language whitepaper · direct download after a short request.
New · from 11 Sep 2026
Reporting goes live: 24 hours, one platform — the ENISA SRP
From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents via ENISA's central Single Reporting Platform (SRP) — report once instead of up to 27 times. ENISA published the official factsheet, FAQ and user guides on 31 July 2026; the European Commission's guidance of 27 July 2026 adds detail on the reporting obligations.
24 hearly warning after awareness
72 hfull notification
14 d / 1 mofinal report
0 APIsat launch: web form
- Product-based — also covers products that have long been on the market
- An attempt is enough: “actively exploited” does not require a successful attack
- Access via EU Login; the CSIRT validates in parallel with your first report
- Delayed dissemination only as a CSIRT decision (Delegated Regulation (EU) 2026/881)
Sources: ENISA “CRA Single Reporting Platform Factsheet” v1.0 (31 Jul 2026); ENISA SRP FAQ; European Commission guidance C(2026) 5252 (27 Jul 2026).
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
CRA Single Reporting Platform Factsheet (v1.0)
Official factsheet of 31 July 2026 on the SRP: who must report, the three reporting stages and deadlines, how to use the platform, and how notifications are disseminated to CSIRTs, ENISA and market surveillance.
Delegated Regulation (EU) 2026/881
Specifies the conditions under which the dissemination of notifications may exceptionally be delayed on cybersecurity grounds (Art. 16(2) CRA).
Verordnung (EU) 2024/2847 (Cyber Resilience Act)
Legally binding full text; basis for the information on Annex I, Annexes III/IV, the reporting obligations (Art. 14, 16), the conformity assessment (Art. 32), the penalties (Art. 64) and the application dates (Art. 71).
Durchführungsverordnung (EU) 2025/2392
Technical descriptions of the categories of important and critical products with digital elements; adopted on 28 November 2025.
Cyber Resilience Act (Themenseite)
German perspective on product classes, SBOM, the reporting channel via the central ENISA platform and the exemptions from the scope.
Cyber Resilience Act – Shaping Europe's digital future
Official policy page with the timeline of application dates and the implementation guidance published in July 2026.
BSI TR-03183: Cyber Resilience Requirements for Manufacturers and Products
Multi-part Technical Guideline supporting CRA implementation, including specific SBOM requirements (Part 2) and requirements for vulnerability reports (Part 3).
Cyber Resilience Act: Commission clarifies “important” and “critical” product categories
Legal analysis of the classification of product categories under Implementing Regulation (EU) 2025/2392 and the role of core functionality.
ENISA Secure by Design and Default Playbook
Practical implementation aid (v1.0, 30 July 2026): 22 secure-by-design/default principles with checklists and release gates; Annex C maps them indicatively onto the requirements of CRA Annex I.
Ready for the CRA deadlines in 2026 and 2027?
In a no-obligation initial consultation, we clarify which product classes and obligations affect your portfolio and where you stand today. Get in touch with us.