The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, establishes horizontal cybersecurity requirements for products with digital elements. It covers many hardware and software products placed on the EU market and addresses planning, development, delivery, operation and the support period.
Who is affected?
The CRA primarily addresses manufacturers, importers and distributors of products with digital elements, including software, hardware and required remote data processing. Sector-regulated products, certain non-commercial open-source development and other groups have specific rules or exclusions. Classification depends on product and business model.
Core manufacturer duties
- Risk-based security:
Create and maintain a cybersecurity risk assessment. - Secure by design/default:
Appropriate security, safe defaults, data protection and minimized attack surface. - Vulnerability handling:
Identify, document and fix vulnerabilities and provide security updates. - Components:
Track dependencies; the CRA explicitly calls for a machine-readable SBOM in technical documentation. - Conformity:
Technical documentation, applicable assessment, declaration and CE marking.
What must be reported from September 2026?
Manufacturers report actively exploited vulnerabilities and severe security incidents through the CRA Single Reporting Platform. An early warning is due within 24 hours and a complete notification within 72 hours of awareness. For exploited vulnerabilities, a final report follows no later than 14 days after a corrective or mitigating measure is available; for severe incidents, within one month after the 72-hour notification.
How should organizations prepare?
- Classify portfolio, roles and applicability with legal and product expertise.
- Document ownership across secure development, release, update and support.
- Establish per-release SBOMs, monitoring and prioritization.
- Operate a vulnerability contact and disclosure process.
- Exercise 24/72-hour reporting with product, legal, management and CSIRT.
- Collect evidence early; last-minute documentation cannot replace a working lifecycle.
This article is technical orientation, not legal advice. The regulation, later legal acts and official guidance remain authoritative.
Thank you for your feedback! We will review it and optimize this content.