The Cyber Resilience Act — manufacturer is a role, not an industry.
The EU regulation that puts cybersecurity inside CE marking. Reporting has been live since 11 September 2026; the full product regime lands 11 December 2027. We establish whether it reaches you, then build the evidence that says so.
Overview
CE marking, extended to cybersecurity.
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the first EU law to make cybersecurity a condition of putting a product on the market. It applies in three steps: Chapter IV (notification of conformity assessment bodies) from 11 June 2026, the Article 14 reporting obligations from 11 September 2026, and everything else — essential requirements, conformity assessment, CE marking — from 11 December 2027.
Its subject is the product with digital elements: any software or hardware product, and its remote data processing solutions, connecting to a device or network. That net is drawn around a role, not an industry. Under Article 3(13) you are the manufacturer if you develop a product — or have one developed for you — and market it under your own name or trademark. Article 21 pulls in importers and distributors who rebrand; Article 22, anyone who substantially modifies a product already on the market.
What makes this urgent rather than a 2027 problem is Article 69(3): the reporting duty reaches products already on the EU market. Learn today that a vulnerability in something you shipped in 2023 is being exploited, and the 24-hour clock is running — a different clock from the one a NIS2, DORA or GDPR process tracks, because the trigger sits at a customer, not on your network. The engineering load stays with your product team; ours is the governance layer around it, and where you hold ISO 27001 much of that substrate is reusable.
Who the CRA applies to
Four routes into the definition. Only the first is the one organisations expect — the other three are where SMBs are caught.
Manufacturers (Art. 3(13))
You develop a product with digital elements — or have one developed for you — and market it under your own name or trademark, for payment or free of charge. The trademark is the hinge, not the factory.
Own-brand importers and distributors (Art. 21)
An importer or distributor placing a product under its own name or trademark is treated as the manufacturer and carries Articles 13 and 14 in full — the white-label device rebadged as your own product line.
Anyone who substantially modifies (Art. 21 · 22)
Substantially modify a product already on the market and you become the manufacturer — for the modified part, or the whole product where the change affects its cybersecurity overall. This catches integrators and OEM customisation more often than software vendors.
Software, SaaS and remote data processing
Software sold as a product is in scope; software delivered purely as a service generally is not. But Article 3(2) captures remote data processing built by or for the manufacturer without which the product loses a function — the cloud half of a connected product travels with it.
Key obligations
What the regulation requires, by article.
Which of these bind you, and how hard, is settled in Phase 1 by your role and your product classification. These are the ones that land on an SMB manufacturer.
- 01Art. 13(2) · Annex I Part I
Risk assessment and product properties
A documented risk assessment per product, kept current across the support period, and thirteen essential properties applied on its basis — among them no known exploitable vulnerabilities at release, secure-by-default configuration, security updates, access control, confidentiality and integrity protection, and secure data deletion.
- 02Annex I Part II · Art. 13(5)
Vulnerability handling and third-party components
A software bill of materials covering at least top-level dependencies, remediation without undue delay, regular testing, public disclosure of fixed vulnerabilities, a coordinated vulnerability disclosure policy, a reporting contact, and free secure updates — plus due diligence on the components you integrate, open-source included.
- 03Art. 13(8), (9), (19) · Annex II
Support period — at least five years
Set a period reflecting how long the product is realistically in use; the floor is five years. Updates issued during it stay available a further 10 years. Its end-date, month and year, must be stated at the point of purchase, alongside the vulnerability reporting contact and secure commissioning instructions.
- 04Art. 14
Reporting — 24 hours, 72 hours, 14 days
For an actively exploited vulnerability or a severe incident: early warning within 24 hours of becoming aware, full notification within 72 hours, final report within 14 days of a fix being available — one month for incidents. Filed once, via the ENISA single reporting platform.
- 05Art. 7 · Annex III
Important products — class I and class II
Products whose core functionality matches an Annex III category. Class I spans identity and access management, browsers, password managers, anti-malware, VPNs, SIEM, PKI, operating systems, routers and smart-home security products; class II covers hypervisors and container runtimes, firewalls and IDS/IPS, and tamper-resistant chips.
- 06Art. 32 · 13(13) · Annex VII
Conformity assessment, CE marking and documentation
Default products may self-assess under internal control (module A). Class I loses that option where harmonised standards or an equivalent scheme have not been applied; class II always needs a notified body or a European certification scheme at assurance level at least substantial, and Annex IV critical products sit above that again. Technical documentation is kept 10 years, or the support period if longer. Classification is the decision that sets your budget.
Penalties & consequences
Article 64: three bands, and a derogation narrower than it looks.
CRA fines are administrative, set by national market surveillance authorities, and calculated as the higher of a fixed amount or a share of worldwide annual turnover. Breaching the Annex I requirements or the Article 13 and 14 obligations sits in the top band; most other obligations in the middle; misleading information to a notified body or authority at the bottom.
The relief for the smallest firms is narrower than it looks. Article 64(10)(a) removes the fine for microenterprises and small enterprises — under 50 staff, and turnover or balance sheet of €10M or less — for missing the deadline in Article 14(2)(a) or 14(4)(a): the 24-hour early warning, and only that. Not the 72-hour notification, not the final report, not the duty to report. The fine is rarely the first consequence anyway — market access does not wait: no conformity, no CE mark, no EU market, and a NIS2-covered customer running Article 21(2)(d) due diligence will ask for your CRA position long before a regulator does.
Annex I, Art. 13 & 14
€15M / 2.5%
whichever is higher, of total worldwide annual turnover.
Other obligations
€10M / 2%
Articles 18–23, 28, 30, 31, 32, 33(5), 39, 41, 47, 49 and 53.
Incorrect information
€5M / 1%
to notified bodies and market surveillance authorities, in reply to a request.
Our approach
CRA readiness, scoped to the products you actually place on the market.
What we deliver
- Manufacturer determination — the Article 3(13), 21 and 22 test across every product and rebadged line you sell, reasoning written down
- Product inventory and classification against Implementing Regulation (EU) 2025/2392 — default, Annex III class I or II, or Annex IV critical
- Annex I gap analysis across Parts I and II, with a prioritised, costed remediation roadmap
- Article 14 reporting playbook — decision chain, named filer, CSIRT determination, and a tabletop triggered by a customer call
- Support-period policy and the documented reasoning behind each end-date
- Coordinated vulnerability disclosure policy, single point of contact, and SBOM governance
- Conformity assessment route selection — self-assessment, notified body, or certification scheme
- Technical documentation (Annex VII), user information pack (Annex II), and the evidence file an authority opens first
Typical timeline
Reporting is already live, so scope determination is urgent and the rest is a 2027 programme. Gap analysis, remediation and a documentation build run six to nine months — which puts a comfortable December 2027 start somewhere in 2026.
1–2 weeks
Scope & classification
Manufacturer determination per product line, inventory, Annex III classification, and a Service Profile scoping the rest. This phase either ends the engagement or changes the conversation entirely.
Immediate
Reporting readiness
The one obligation already in force. Decision chain, named filer and deputy, EU Login account, CSIRT determination under Article 14(7), and a live-fire rehearsal.
Following scoping
Annex I gap analysis
Parts I and II assessed per product, with a roadmap separating what engineering must build from what governance can close.
Pre-December 2027
Documentation & conformity
Technical documentation, support-period reasoning, user information pack, conformity route, and the sign-off that makes the declaration of conformity defensible.
Free tool
Where does your product stand on the CRA?
Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.
Start the CRA assessmentFAQ