Regulation (EU) 2024/2847

The Cyber Resilience Act Security for products with digital elements.

The CRA requires hardware and software with digital elements to be secure across their whole life cycle. Manufacturers must handle vulnerabilities, deliver updates and report incidents. The first reporting obligations have applied since September 2026.

At a glance

Legal basis
Regulation (EU) 2024/2847, in force since 10 December 2024
Reporting
Since 11 September 2026 (Art. 14)
Fully applicable
From 11 December 2027, with CE marking under the CRA
Fines
Up to €15m or 2.5% of worldwide annual turnover, whichever is higher

Who the CRA applies to

  • Manufacturers of products with digital elements, from software to connected devices.
  • Importers and distributors that make such products available in the EU.
  • Areas with their own rules, such as medical devices, vehicles or aviation, are outside its scope.
Team discussing priorities at a conference table

What the CRA requires

  • 01

    Security by design

    Essential requirements from Annex I: secure defaults, protection against unauthorised access, a minimal attack surface.

  • 02

    Vulnerability handling

    Identify, document and promptly fix vulnerabilities with security updates throughout the support period.

  • 03

    Reporting (Art. 14)

    Actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident) – to the coordinating CSIRT and ENISA.

  • 04

    Conformity

    Technical documentation, conformity assessment and CE marking before a product is placed on the market.

Deadlines and dates

  1. CRA enters into force

  2. Reporting obligations for manufacturers apply

  3. All obligations apply, CE marking under the CRA

83testable requirements in UniqSuite

How UniqSuite helps

UniqSuite takes you through the CRA requirements, from the support period and the software bill of materials to the declaration of conformity. Classify an event as an actively exploited vulnerability or a severe incident and UniqSuite shows the reports that are due and their deadlines.

Frequently asked questions

We only sell software. Does the CRA apply?

In many cases, yes. Standalone software can be a product with digital elements. There are exceptions, for example for certain open-source software outside a commercial activity.

Do the reporting obligations cover older products?

Yes. The reporting obligations that have applied since September 2026 also cover products placed on the market before December 2027.

How long do we have to provide security updates?

Throughout the support period, which must be at least five years. If a product is expected to be in use for less time, the support period matches that expected use time (Art. 13(8)). Each security update provided must remain available for at least ten years (Art. 13(9)).

Do we need a third-party assessment?

For products without a special classification, the manufacturer’s internal control is enough. Important products of class I, such as routers or password managers, need a third-party assessment if you do not fully apply harmonised standards. For class II, such as firewalls, it is always required (Art. 32).

Where should manufacturers start?

Check which of your products fall under the CRA and whether they are classed as important or critical, and set up a process for the reporting obligations that already apply. Also build a software bill of materials (SBOM) in a machine-readable format, as Annex I requires. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.

See what is still open for you.

In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.