01Scope: products with digital elements
The CRA covers hardware and software whose intended use includes a direct or indirect data connection to a device or network – including components placed on the market separately. The obligations fall primarily on manufacturers as soon as a product is made available on the EU market; importers and distributors are subject to graduated verification and cooperation duties. Product areas with their own sectoral rules are excluded – such as medical devices, motor vehicles, aviation and maritime transport – as is free and open-source software outside a commercial activity.
02Product classes: default, important (class I/II), critical
The regulation grades products by risk: the vast majority are default products and undergo a manufacturer self-assessment. Important products under Annex III are divided into class I (19 categories, including password managers, browsers, VPN products, operating systems, routers and SIEM systems) and class II (4 categories: hypervisors and container runtimes, firewalls and intrusion detection/prevention systems, as well as tamper-resistant microprocessors and microcontrollers). For critical products under Annex IV – including smart meter gateways as well as smartcards and secure elements – a mandatory European cybersecurity certification can be prescribed. Implementing Regulation (EU) 2025/2392 of 28 November 2025 specifies the technical descriptions of the categories; the product's core functionality is decisive for the classification.
03Annex I: security by design, update obligation, SBOM
Annex I defines the essential cybersecurity requirements in two parts. Part I concerns product properties: products must be developed on the basis of a risk assessment, made available without known exploitable vulnerabilities and delivered with a secure default configuration; vulnerabilities must be addressed through security updates – installable automatically by default, with an opt-out option. Part II requires vulnerability handling processes: a software bill of materials (SBOM) in a commonly used, machine-readable format covering at least the top-level dependencies, a coordinated disclosure policy, a contact point for vulnerability reports, as well as regular testing and the prompt, free-of-charge distribution of security updates. The CRA does not require the SBOM to be published; as a practical starting point, Technical Guideline BSI TR-03183 specifies SBOM contents and formats, among other things.
04Reporting obligations from 11 September 2026 (Art. 14)
From 11 September 2026, manufacturers must report actively exploited vulnerabilities as well as severe incidents having an impact on the security of the product – simultaneously to the CSIRT designated as coordinator and to ENISA via the single reporting platform under Art. 16. A three-stage procedure applies: an early warning within 24 hours of becoming aware, a detailed notification within 72 hours, and a final report – for vulnerabilities no later than 14 days after a corrective or mitigating measure becomes available, for incidents one month after the incident notification. These deadlines presuppose prepared detection, assessment and reporting processes – in particular the ability to reliably establish active exploitation.
05Conformity assessment and CE marking
Depending on the class, conformity is demonstrated through internal control (module A), EU-type examination followed by conformity to type based on internal production control (modules B and C), full quality assurance (module H) or a European cybersecurity certification scheme (Art. 32). Important class I products may only be declared conformant via self-assessment if the relevant harmonised standards or schemes are applied in full; for class II, the involvement of a notified body is mandatory. From 11 December 2027, products with digital elements may only be placed on the EU market with CE marking (Art. 29–30), which then also confirms CRA conformity – to be demonstrated through the EU declaration of conformity and technical documentation. Infringements of the requirements of Annex I or the obligations under Art. 13 and 14 carry fines of up to EUR 15 million or 2.5% of worldwide annual turnover; other breaches of obligations carry fines of up to EUR 10 million or 2% (Art. 64).
06Support period and lifecycle obligations
Manufacturers must determine a support period during which vulnerabilities are handled effectively; as a rule, it is at least five years (Art. 13). Once made available, security updates must remain available for at least ten years after their publication or for the remainder of the support period – whichever is longer – and must be provided free of charge during the support period. The CRA thus shifts the focus from a one-off conformity check to permanently operated processes: secure development, vulnerability and patch management, and ongoing documentation. In addition, the provisions on the notification of conformity assessment bodies (Chapter IV) have applied since 11 June 2026, and in July 2026 the European Commission published practice-oriented guidance on implementation.