Book an Appointment

The EU Cyber Resilience Act

What Regulation (EU) 2024/2847 requires from manufacturers, importers and distributors of products with digital elements – from security by design and SBOM to the reporting deadlines starting 11 September 2026.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

24 hEarly warning to CSIRT & ENISA from awareness
€15 MMaximum fine — or 2.5% of global annual turnover
5 yrsMinimum support period, as a rule (Art. 13)
22ENISA principles for secure by design & default

With the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), the EU introduces horizontal cybersecurity requirements for products with digital elements for the first time – from consumer devices and operating systems to industrial components. The regulation entered into force on 10 December 2024 and applies in stages: the reporting obligations for actively exploited vulnerabilities and severe incidents take effect on 11 September 2026, while the remaining obligations, including CE marking, apply from 11 December 2027. Unlike NIS2, which addresses organisations, the CRA targets the product itself: anyone making hardware or software available on the EU market must demonstrate security across the entire product lifecycle. For manufacturers, this means new processes in development, vulnerability management and documentation – with lead times that are now becoming very real.

The CRA deadlines at a glance

Four dates drive implementation — tap a milestone for details.

The Essentials at a Glance

Seven topic blocks — tap to expand.

Which product class affects you?

The CRA grades products by risk — each with its own route to demonstrating conformity.

Self-assessment (module A)
  • The manufacturer assesses conformity itself (internal control, module A) — no notified body required.
  • All Annex I requirements still apply in full.
  • The product's core functionality determines the classification.
In-depth whitepaper

CRA Reality Check — Zero-Days, Supply Chain & AI

How manufacturers actually implement the Cyber Resilience Act: the new ENISA playbooks, the 24-hour reporting clock, SBOM/supply chain and AI — as an actionable roadmap for product-security and CISO teams.

ENISA playbooks as release gates

The 22 Secure-by-Design principles, mapped to CRA Annex I.

Zero-days & the 24-hour clock

Article 14 (24/72/14), the Single Reporting Platform and machine-speed exploitation.

Supply chain & SBOM

SBOM per Annex I, component due diligence (Art. 13) and open-source stewards (Art. 24).

AI under the CRA

The CRA–AI Act interface (Art. 12) and AI as a threat accelerant.

Download the whitepaper (free)

English-language whitepaper · direct download after a short request.

New · from 11 Sep 2026

Reporting goes live: 24 hours, one platform — the ENISA SRP

From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents via ENISA's central Single Reporting Platform (SRP) — report once instead of up to 27 times. ENISA published the official factsheet, FAQ and user guides on 31 July 2026; the European Commission's guidance of 27 July 2026 adds detail on the reporting obligations.

24 hearly warning after awareness
72 hfull notification
14 d / 1 mofinal report
0 APIsat launch: web form
  • Product-based — also covers products that have long been on the market
  • An attempt is enough: “actively exploited” does not require a successful attack
  • Access via EU Login; the CSIRT validates in parallel with your first report
  • Delayed dissemination only as a CSIRT decision (Delegated Regulation (EU) 2026/881)

Sources: ENISA “CRA Single Reporting Platform Factsheet” v1.0 (31 Jul 2026); ENISA SRP FAQ; European Commission guidance C(2026) 5252 (27 Jul 2026).

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ENISA · 2026

CRA Single Reporting Platform Factsheet (v1.0)

Official factsheet of 31 July 2026 on the SRP: who must report, the three reporting stages and deadlines, how to use the platform, and how notifications are disseminated to CSIRTs, ENISA and market surveillance.

European Commission / Official Journal of the EU · 2026

Delegated Regulation (EU) 2026/881

Specifies the conditions under which the dissemination of notifications may exceptionally be delayed on cybersecurity grounds (Art. 16(2) CRA).

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Legally binding full text; basis for the information on Annex I, Annexes III/IV, the reporting obligations (Art. 14, 16), the conformity assessment (Art. 32), the penalties (Art. 64) and the application dates (Art. 71).

Europäische Kommission / Amtsblatt der EU · 2025

Durchführungsverordnung (EU) 2025/2392

Technical descriptions of the categories of important and critical products with digital elements; adopted on 28 November 2025.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Cyber Resilience Act (Themenseite)

German perspective on product classes, SBOM, the reporting channel via the central ENISA platform and the exemptions from the scope.

Europäische Kommission · 2026

Cyber Resilience Act – Shaping Europe's digital future

Official policy page with the timeline of application dates and the implementation guidance published in July 2026.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2025

BSI TR-03183: Cyber Resilience Requirements for Manufacturers and Products

Multi-part Technical Guideline supporting CRA implementation, including specific SBOM requirements (Part 2) and requirements for vulnerability reports (Part 3).

Herbert Smith Freehills Kramer · 2026

Cyber Resilience Act: Commission clarifies “important” and “critical” product categories

Legal analysis of the classification of product categories under Implementing Regulation (EU) 2025/2392 and the role of core functionality.

ENISA · 2026

ENISA Secure by Design and Default Playbook

Practical implementation aid (v1.0, 30 July 2026): 22 secure-by-design/default principles with checklists and release gates; Annex C maps them indicatively onto the requirements of CRA Annex I.

Ready for the CRA deadlines in 2026 and 2027?

In a no-obligation initial consultation, we clarify which product classes and obligations affect your portfolio and where you stand today. Get in touch with us.