Book an Appointment

The EU Cyber Resilience Act

What Regulation (EU) 2024/2847 requires from manufacturers, importers and distributors of products with digital elements – from security by design and SBOM to the reporting deadlines starting 11 September 2026.

With the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), the EU introduces horizontal cybersecurity requirements for products with digital elements for the first time – from consumer devices and operating systems to industrial components. The regulation entered into force on 10 December 2024 and applies in stages: the reporting obligations for actively exploited vulnerabilities and severe incidents take effect on 11 September 2026, while the remaining obligations, including CE marking, apply from 11 December 2027. Unlike NIS2, which addresses organisations, the CRA targets the product itself: anyone making hardware or software available on the EU market must demonstrate security across the entire product lifecycle. For manufacturers, this means new processes in development, vulnerability management and documentation – with lead times that are now becoming very real.

The Essentials at a Glance

01

Scope: products with digital elements

The CRA covers hardware and software whose intended use includes a direct or indirect data connection to a device or network – including components placed on the market separately. The obligations fall primarily on manufacturers as soon as a product is made available on the EU market; importers and distributors are subject to graduated verification and cooperation duties. Product areas with their own sectoral rules are excluded – such as medical devices, motor vehicles, aviation and maritime transport – as is free and open-source software outside a commercial activity.

02

Product classes: default, important (class I/II), critical

The regulation grades products by risk: the vast majority are default products and undergo a manufacturer self-assessment. Important products under Annex III are divided into class I (19 categories, including password managers, browsers, VPN products, operating systems, routers and SIEM systems) and class II (4 categories: hypervisors and container runtimes, firewalls and intrusion detection/prevention systems, as well as tamper-resistant microprocessors and microcontrollers). For critical products under Annex IV – including smart meter gateways as well as smartcards and secure elements – a mandatory European cybersecurity certification can be prescribed. Implementing Regulation (EU) 2025/2392 of 28 November 2025 specifies the technical descriptions of the categories; the product's core functionality is decisive for the classification.

03

Annex I: security by design, update obligation, SBOM

Annex I defines the essential cybersecurity requirements in two parts. Part I concerns product properties: products must be developed on the basis of a risk assessment, made available without known exploitable vulnerabilities and delivered with a secure default configuration; vulnerabilities must be addressed through security updates – installable automatically by default, with an opt-out option. Part II requires vulnerability handling processes: a software bill of materials (SBOM) in a commonly used, machine-readable format covering at least the top-level dependencies, a coordinated disclosure policy, a contact point for vulnerability reports, as well as regular testing and the prompt, free-of-charge distribution of security updates. The CRA does not require the SBOM to be published; as a practical starting point, Technical Guideline BSI TR-03183 specifies SBOM contents and formats, among other things.

04

Reporting obligations from 11 September 2026 (Art. 14)

From 11 September 2026, manufacturers must report actively exploited vulnerabilities as well as severe incidents having an impact on the security of the product – simultaneously to the CSIRT designated as coordinator and to ENISA via the single reporting platform under Art. 16. A three-stage procedure applies: an early warning within 24 hours of becoming aware, a detailed notification within 72 hours, and a final report – for vulnerabilities no later than 14 days after a corrective or mitigating measure becomes available, for incidents one month after the incident notification. These deadlines presuppose prepared detection, assessment and reporting processes – in particular the ability to reliably establish active exploitation.

05

Conformity assessment and CE marking

Depending on the class, conformity is demonstrated through internal control (module A), EU-type examination followed by conformity to type based on internal production control (modules B and C), full quality assurance (module H) or a European cybersecurity certification scheme (Art. 32). Important class I products may only be declared conformant via self-assessment if the relevant harmonised standards or schemes are applied in full; for class II, the involvement of a notified body is mandatory. From 11 December 2027, products with digital elements may only be placed on the EU market with CE marking (Art. 29–30), which then also confirms CRA conformity – to be demonstrated through the EU declaration of conformity and technical documentation. Infringements of the requirements of Annex I or the obligations under Art. 13 and 14 carry fines of up to EUR 15 million or 2.5% of worldwide annual turnover; other breaches of obligations carry fines of up to EUR 10 million or 2% (Art. 64).

06

Support period and lifecycle obligations

Manufacturers must determine a support period during which vulnerabilities are handled effectively; as a rule, it is at least five years (Art. 13). Once made available, security updates must remain available for at least ten years after their publication or for the remainder of the support period – whichever is longer – and must be provided free of charge during the support period. The CRA thus shifts the focus from a one-off conformity check to permanently operated processes: secure development, vulnerability and patch management, and ongoing documentation. In addition, the provisions on the notification of conformity assessment bodies (Chapter IV) have applied since 11 June 2026, and in July 2026 the European Commission published practice-oriented guidance on implementation.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Legally binding full text; basis for the information on Annex I, Annexes III/IV, the reporting obligations (Art. 14, 16), the conformity assessment (Art. 32), the penalties (Art. 64) and the application dates (Art. 71).

Europäische Kommission / Amtsblatt der EU · 2025

Durchführungsverordnung (EU) 2025/2392

Technical descriptions of the categories of important and critical products with digital elements; adopted on 28 November 2025.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Cyber Resilience Act (Themenseite)

German perspective on product classes, SBOM, the reporting channel via the central ENISA platform and the exemptions from the scope.

Europäische Kommission · 2026

Cyber Resilience Act – Shaping Europe's digital future

Official policy page with the timeline of application dates and the implementation guidance published in July 2026.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2025

BSI TR-03183: Cyber Resilience Requirements for Manufacturers and Products

Multi-part Technical Guideline supporting CRA implementation, including specific SBOM requirements (Part 2) and requirements for vulnerability reports (Part 3).

Herbert Smith Freehills Kramer · 2026

Cyber Resilience Act: Commission clarifies “important” and “critical” product categories

Legal analysis of the classification of product categories under Implementing Regulation (EU) 2025/2392 and the role of core functionality.

Ready for the CRA deadlines in 2026 and 2027?

In a no-obligation initial consultation, we clarify which product classes and obligations affect your portfolio and where you stand today. Get in touch with us.