Cyber Resilience Act

Mandatory · Products

The Cyber Resilience Act — manufacturer is a role, not an industry.

The EU regulation that puts cybersecurity inside CE marking. Reporting has been live since 11 September 2026; the full product regime lands 11 December 2027. We establish whether it reaches you, then build the evidence that says so.

Overview

CE marking, extended to cybersecurity.

The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the first EU law to make cybersecurity a condition of putting a product on the market. It applies in three steps: Chapter IV (notification of conformity assessment bodies) from 11 June 2026, the Article 14 reporting obligations from 11 September 2026, and everything else — essential requirements, conformity assessment, CE marking — from 11 December 2027.

Its subject is the product with digital elements: any software or hardware product, and its remote data processing solutions, connecting to a device or network. That net is drawn around a role, not an industry. Under Article 3(13) you are the manufacturer if you develop a product — or have one developed for youand market it under your own name or trademark. Article 21 pulls in importers and distributors who rebrand; Article 22, anyone who substantially modifies a product already on the market.

What makes this urgent rather than a 2027 problem is Article 69(3): the reporting duty reaches products already on the EU market. Learn today that a vulnerability in something you shipped in 2023 is being exploited, and the 24-hour clock is running — a different clock from the one a NIS2, DORA or GDPR process tracks, because the trigger sits at a customer, not on your network. The engineering load stays with your product team; ours is the governance layer around it, and where you hold ISO 27001 much of that substrate is reusable.

Who the CRA applies to

Four routes into the definition. Only the first is the one organisations expect — the other three are where SMBs are caught.

  • Manufacturers (Art. 3(13))

    You develop a product with digital elements — or have one developed for you — and market it under your own name or trademark, for payment or free of charge. The trademark is the hinge, not the factory.

  • Own-brand importers and distributors (Art. 21)

    An importer or distributor placing a product under its own name or trademark is treated as the manufacturer and carries Articles 13 and 14 in full — the white-label device rebadged as your own product line.

  • Anyone who substantially modifies (Art. 21 · 22)

    Substantially modify a product already on the market and you become the manufacturer — for the modified part, or the whole product where the change affects its cybersecurity overall. This catches integrators and OEM customisation more often than software vendors.

  • Software, SaaS and remote data processing

    Software sold as a product is in scope; software delivered purely as a service generally is not. But Article 3(2) captures remote data processing built by or for the manufacturer without which the product loses a function — the cloud half of a connected product travels with it.

Key obligations

What the regulation requires, by article.

Which of these bind you, and how hard, is settled in Phase 1 by your role and your product classification. These are the ones that land on an SMB manufacturer.

  1. 01Art. 13(2) · Annex I Part I

    Risk assessment and product properties

    A documented risk assessment per product, kept current across the support period, and thirteen essential properties applied on its basis — among them no known exploitable vulnerabilities at release, secure-by-default configuration, security updates, access control, confidentiality and integrity protection, and secure data deletion.

  2. 02Annex I Part II · Art. 13(5)

    Vulnerability handling and third-party components

    A software bill of materials covering at least top-level dependencies, remediation without undue delay, regular testing, public disclosure of fixed vulnerabilities, a coordinated vulnerability disclosure policy, a reporting contact, and free secure updates — plus due diligence on the components you integrate, open-source included.

  3. 03Art. 13(8), (9), (19) · Annex II

    Support period — at least five years

    Set a period reflecting how long the product is realistically in use; the floor is five years. Updates issued during it stay available a further 10 years. Its end-date, month and year, must be stated at the point of purchase, alongside the vulnerability reporting contact and secure commissioning instructions.

  4. 04Art. 14

    Reporting — 24 hours, 72 hours, 14 days

    For an actively exploited vulnerability or a severe incident: early warning within 24 hours of becoming aware, full notification within 72 hours, final report within 14 days of a fix being available — one month for incidents. Filed once, via the ENISA single reporting platform.

  5. 05Art. 7 · Annex III

    Important products — class I and class II

    Products whose core functionality matches an Annex III category. Class I spans identity and access management, browsers, password managers, anti-malware, VPNs, SIEM, PKI, operating systems, routers and smart-home security products; class II covers hypervisors and container runtimes, firewalls and IDS/IPS, and tamper-resistant chips.

  6. 06Art. 32 · 13(13) · Annex VII

    Conformity assessment, CE marking and documentation

    Default products may self-assess under internal control (module A). Class I loses that option where harmonised standards or an equivalent scheme have not been applied; class II always needs a notified body or a European certification scheme at assurance level at least substantial, and Annex IV critical products sit above that again. Technical documentation is kept 10 years, or the support period if longer. Classification is the decision that sets your budget.

Penalties & consequences

Article 64: three bands, and a derogation narrower than it looks.

CRA fines are administrative, set by national market surveillance authorities, and calculated as the higher of a fixed amount or a share of worldwide annual turnover. Breaching the Annex I requirements or the Article 13 and 14 obligations sits in the top band; most other obligations in the middle; misleading information to a notified body or authority at the bottom.

The relief for the smallest firms is narrower than it looks. Article 64(10)(a) removes the fine for microenterprises and small enterprises — under 50 staff, and turnover or balance sheet of €10M or less — for missing the deadline in Article 14(2)(a) or 14(4)(a): the 24-hour early warning, and only that. Not the 72-hour notification, not the final report, not the duty to report. The fine is rarely the first consequence anyway — market access does not wait: no conformity, no CE mark, no EU market, and a NIS2-covered customer running Article 21(2)(d) due diligence will ask for your CRA position long before a regulator does.

  • Annex I, Art. 13 & 14

    €15M / 2.5%

    whichever is higher, of total worldwide annual turnover.

  • Other obligations

    €10M / 2%

    Articles 18–23, 28, 30, 31, 32, 33(5), 39, 41, 47, 49 and 53.

  • Incorrect information

    €5M / 1%

    to notified bodies and market surveillance authorities, in reply to a request.

Our approach

CRA readiness, scoped to the products you actually place on the market.

What we deliver

  • Manufacturer determination — the Article 3(13), 21 and 22 test across every product and rebadged line you sell, reasoning written down
  • Product inventory and classification against Implementing Regulation (EU) 2025/2392 — default, Annex III class I or II, or Annex IV critical
  • Annex I gap analysis across Parts I and II, with a prioritised, costed remediation roadmap
  • Article 14 reporting playbook — decision chain, named filer, CSIRT determination, and a tabletop triggered by a customer call
  • Support-period policy and the documented reasoning behind each end-date
  • Coordinated vulnerability disclosure policy, single point of contact, and SBOM governance
  • Conformity assessment route selection — self-assessment, notified body, or certification scheme
  • Technical documentation (Annex VII), user information pack (Annex II), and the evidence file an authority opens first

Typical timeline

Reporting is already live, so scope determination is urgent and the rest is a 2027 programme. Gap analysis, remediation and a documentation build run six to nine months — which puts a comfortable December 2027 start somewhere in 2026.

  1. 1–2 weeks

    Scope & classification

    Manufacturer determination per product line, inventory, Annex III classification, and a Service Profile scoping the rest. This phase either ends the engagement or changes the conversation entirely.

  2. Immediate

    Reporting readiness

    The one obligation already in force. Decision chain, named filer and deputy, EU Login account, CSIRT determination under Article 14(7), and a live-fire rehearsal.

  3. Following scoping

    Annex I gap analysis

    Parts I and II assessed per product, with a roadmap separating what engineering must build from what governance can close.

  4. Pre-December 2027

    Documentation & conformity

    Technical documentation, support-period reasoning, user information pack, conformity route, and the sign-off that makes the declaration of conformity defensible.

Free tool

Where does your product stand on the CRA?

Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.

Start the CRA assessment

About 8 minutes · Personalized PDF · No spam

FAQ

Common questions.

We are not a hardware company. Does the CRA really apply to us?
Possibly — the test is not what industry you are in. Under Article 3(13) you are a manufacturer if you develop a product with digital elements, or have one developed for you, and market it under your own name or trademark. Article 21 adds importers and distributors that rebrand; Article 22, anyone who substantially modifies a product already on the market. An industrial firm shipping a white-label controller under its own badge, an equipment company adding a connectivity module, a distributor rebranding a device — all are manufacturers here. A product you merely use creates no obligation.
Is SaaS in scope?
Generally not on its own. The CRA regulates products placed on the market, and software delivered purely as a service falls outside it — that surface belongs to NIS2 and, for financial entities, DORA. The exception is Article 3(2): a remote data processing solution built by or for the manufacturer, without which the product loses a function, is treated as part of the product. Sell a connected device with a cloud back end you built, and the back end travels with the device.
What changed on 11 September 2026, and what is left for December 2027?
Article 71 splits the regulation in three. Chapter IV — notification of conformity assessment bodies — applied from 11 June 2026; Article 14 reporting from 11 September 2026; everything else from 11 December 2027, including the Annex I requirements, conformity assessment, CE marking, the support period and the Article 64 penalties. Article 69 then splits the back catalogue: products placed on the market before that date are caught by the product regime only if substantially modified, but Article 69(3) applies the reporting duty to all of them. A vulnerability in a 2023 product being actively exploited today is reportable today.
How large are the fines, and is there SME relief?
Article 64 sets three bands, each the higher of a fixed sum or a share of worldwide annual turnover: €15M or 2.5% for the Annex I requirements and the Article 13 and 14 obligations, €10M or 2% for most other obligations, and €5M or 1% for misleading information to a notified body or authority. The relief for micro and small enterprises removes the fine for missing the 24-hour early warning only — not the 72-hour notification, the final report, or the duty to report.
How does the CRA relate to NIS2, the EU AI Act and ISO 27001?
They interlock rather than overlap. NIS2 regulates your organisation; the CRA regulates your products — and a NIS2-covered customer running Article 21(2)(d) due diligence will treat your CRA position as procurement evidence. For AI, Article 12 means a product that is also a high-risk AI system is deemed to satisfy the AI Act’s Article 15 cybersecurity requirements where it meets Annex I. ISO 27001 is not CRA conformity, but its vulnerability management, supplier, change and documentation controls carry much of the Annex I Part II load — cheaper built together than sequentially.