The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity obligations for products with digital elements within its scope. Determine applicability, product category and economic-operator role before planning conformity or reporting.
CRA scope and application dates
The CRA entered into force on 10 December 2024. Article 14 reporting has applied since 11 September 2026; the main product requirements apply from 11 December 2027. Article 69 contains transitional rules for previously placed products. Products subject to MDR or IVDR are excluded under Article 2(2); other exclusions and non-commercial free/open-source scope must also be checked.
CRA product classification
CRA classification follows core functionality, Annexes III/IV and the technical descriptions in Regulation 2025/2392. Operating systems are important Class I; Class II includes firewalls/IDS/IPS, specified hypervisors/container runtimes and tamper-resistant microprocessors/microcontrollers. Smartcards and similar devices, including secure elements, are critical categories. Integrating such a component does not automatically give the complete product its category. Article 32 defines the applicable assessment routes.
CRA: requirements and engineering choices
CRA requirements are outcome-oriented and technology-neutral, based on the product’s cybersecurity risk assessment and applicability. Secure boot, a hardware root of trust, TPM, TrustZone and wireless OTA can be appropriate engineering controls; they are not universal legal mandates for every product. Document why the chosen controls satisfy the applicable requirements rather than equating one architecture with compliance.
Support, updates and SBOM
CRA Annex I requires applicable secure vulnerability-handling and update mechanisms. Automatic security updates have conditions and exceptions; automatic does not mean wireless. The support period is determined under Article 13(8), normally at least five years; where expected use is shorter, it corresponds to that use, while longer-use factors can require longer support. An SBOM must be machine-readable and cover at least top-level dependencies.
Reporting obligations already in force
CRA Article 14 concerns actively exploited vulnerabilities and severe incidents affecting product security, not every CVE. Both require an early warning within 24 hours and a notification within 72 hours of awareness. The final vulnerability report is due within 14 days after a corrective or mitigating measure becomes available; the final severe-incident report is due one month after the incident notification. Reporting is separate from conformity assessment and update requirements.
Practical checklist
- Identify the product, intended use, market and applicable legal scope.
- Record the exact legal provisions, dates and applicable standard editions, including restrictions.
- Select the permitted assessment route and document the evidence needed.
- Link risk assessment, tests, product versions and declarations in the technical documentation.
- Assign responsibility for changes, support and responses to authorities.
This checklist supports planning; the applicable legal requirements determine the final assessment.