Regulation (EU) 2024/2847
The Cyber Resilience Act Security for products with digital elements.
The CRA requires hardware and software with digital elements to be secure across their whole life cycle. Manufacturers must handle vulnerabilities, deliver updates and report incidents. The first reporting obligations have applied since September 2026.
At a glance
- Legal basis
- Regulation (EU) 2024/2847, in force since 10 December 2024
- Reporting
- Since 11 September 2026 (Art. 14)
- Fully applicable
- From 11 December 2027, with CE marking under the CRA
- Fines
- Up to €15m or 2.5% of worldwide annual turnover, whichever is higher
Who the CRA applies to
- Manufacturers of products with digital elements, from software to connected devices.
- Importers and distributors that make such products available in the EU.
- Areas with their own rules, such as medical devices, vehicles or aviation, are outside its scope.

What the CRA requires
- 01
Security by design
Essential requirements from Annex I: secure defaults, protection against unauthorised access, a minimal attack surface.
- 02
Vulnerability handling
Identify, document and promptly fix vulnerabilities with security updates throughout the support period.
- 03
Reporting (Art. 14)
Actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident) – to the coordinating CSIRT and ENISA.
- 04
Conformity
Technical documentation, conformity assessment and CE marking before a product is placed on the market.
Deadlines and dates
CRA enters into force
Reporting obligations for manufacturers apply
All obligations apply, CE marking under the CRA
How UniqSuite helps
UniqSuite takes you through the CRA requirements, from the support period and the software bill of materials to the declaration of conformity. Classify an event as an actively exploited vulnerability or a severe incident and UniqSuite shows the reports that are due and their deadlines.
Frequently asked questions
We only sell software. Does the CRA apply?
In many cases, yes. Standalone software can be a product with digital elements. There are exceptions, for example for certain open-source software outside a commercial activity.
Do the reporting obligations cover older products?
Yes. The reporting obligations that have applied since September 2026 also cover products placed on the market before December 2027.
How long do we have to provide security updates?
Throughout the support period, which must be at least five years. If a product is expected to be in use for less time, the support period matches that expected use time (Art. 13(8)). Each security update provided must remain available for at least ten years (Art. 13(9)).
Do we need a third-party assessment?
For products without a special classification, the manufacturer’s internal control is enough. Important products of class I, such as routers or password managers, need a third-party assessment if you do not fully apply harmonised standards. For class II, such as firewalls, it is always required (Art. 32).
Where should manufacturers start?
Check which of your products fall under the CRA and whether they are classed as important or critical, and set up a process for the reporting obligations that already apply. Also build a software bill of materials (SBOM) in a machine-readable format, as Annex I requires. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.
See what is still open for you.
In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.
