CRA
Cyber Resilience Act, Regulation (EU) 2024/2847
Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.
The law in brief
The Cyber Resilience Act sets cybersecurity requirements for hardware and software products sold in the EU, across their whole life. Manufacturers must design products securely, handle vulnerabilities, supply security updates for a defined support period, and report actively exploited vulnerabilities and severe incidents.
It is the first EU law to make "secure by design" a condition of market access for almost every connected product and most commercial software, and it brings CE marking to cybersecurity.
Who it applies to
- Products with digital elements: hardware and software, including remote data processing solutions integral to them, whose intended or foreseeable use includes a connection to a device or network, placed on the EU market.
- Manufacturers carry most duties; importers and distributors must check products comply.
- Important and critical products, such as identity management software, password managers, VPNs, operating systems, firewalls and smart cards, face stricter conformity assessment.
- Excluded: products covered by their own sector rules (medical devices, cars, aviation, marine equipment), products solely for national security or defense, and free and open-source software not supplied in the course of a commercial activity. Open-source stewards have a lighter regime.
What it requires
Essential cybersecurity requirements
Design, develop and produce products to the essential requirements in Annex I, including secure by default configuration, no known exploitable vulnerabilities at release, protection of data, and security updates.
Vulnerability handling for the support period
Identify, document and remediate vulnerabilities throughout the support period, which should reflect expected use and is generally at least five years, and keep a software bill of materials.
Report exploited vulnerabilities and severe incidents
Notify the designated CSIRT and ENISA through the single reporting platform: an early warning within 24 hours, a notification within 72 hours, and a final report, for actively exploited vulnerabilities and severe incidents affecting product security.
Conformity assessment and CE marking
Complete the conformity assessment procedure for the product's class, draw up the technical documentation and EU declaration of conformity, and affix the CE marking.
Information for users
Supply clear instructions and information, including the end date of the support period and a single point of contact for vulnerability reports.
People's rights
Users must receive clear information on the product's support period, security updates and how to report vulnerabilities, and can complain to market surveillance authorities.
Enforcement and penalties
Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaching the essential cybersecurity requirements or manufacturers' main obligations; up to €10 million or 2% for other obligations; up to €5 million or 1% for supplying incorrect or misleading information (Art. 64). Authorities can also order products withdrawn or recalled.
What's changing
Reporting duties apply from 11 September 2026. Manufacturers must now report actively exploited vulnerabilities and severe incidents through the single reporting platform, even for products placed on the market before that date. The remaining obligations, including the essential requirements and conformity assessment, apply from 11 December 2027.
What to do first
- Inventory your products with digital elements sold in the EU and classify each: default, important (Class I or II) or critical.
- Stand up reporting now: 24-hour early warning, 72-hour notification and final reports for exploited vulnerabilities and severe incidents.
- Set a support period for each product and plan security updates for it.
- Build a vulnerability handling process, including a coordinated disclosure policy and a software bill of materials.
- Gap-assess designs against the Annex I essential requirements before December 2027.
- Check your open-source components and the due diligence you do on them.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
EU Cyber Resilience Act reporting obligations take effect for manufacturers
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security. As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related to their products.
Effective: 11 September 2026.
Source: Hunton Privacy & Cybersecurity Law Blog. CRA in the regulations library.
-
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management. ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report actively exploited vulnerabilities and severe incidents through the SRP. The platform enables coordinated notification to national CSIRTs and ENISA.
Source: ENISA news. CRA in the regulations library.
Sources
- Regulation (EU) 2024/2847 EUR-Lex · Official text or regulator