EU Cyber Resilience Act (CRA) Compliance

Cyber Resilience Act, Regulation (EU) 2024/2847

  • Who it's for

    Manufacturers, importers and distributors that place products with digital elements (PDE) — hardware or software — on the EU market on a commercial basis.

  • Problems we solve

    Mandatory CRA cybersecurity requirements, CE marking and the already-in-force vulnerability/incident reporting duties — with uncertainty over whether a product is in scope and which risk class it falls into.

  • Benefits

    Clarify applicability and risk classification, close gaps in secure design and vulnerability handling, complete conformity assessment and earn the compliance ticket into the EU market.

In one sentence: if you place a network-capable or digitally-enabled software or hardware product on the EU market on a commercial basis, and it is not already covered by sector-specific law (medical, automotive, aviation, etc.), it almost certainly falls under the CRA — the only question is which risk class it lands in and whether you self-assess or need a third party.

What is the CRA?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU's first horizontal law to set mandatory cybersecurity requirements for products with digital elements (PDE). Its scope is broad, covering both hardware and software, and it requires products to remain secure throughout their whole lifecycle.

Four core principles: security built in at the design stage, continuous vulnerability handling and updates by the manufacturer, CE marking as the conformity mark, and reporting duties when a product is exploited or a severe incident occurs. It applies to any product placed on the EU market, regardless of where the manufacturer is located.

Compliance timeline: the clock is already running

DateMilestoneWhat it means
2024/12/10Regulation enters into forceNo product-level obligations yet; the preparation window begins.
2026/09/11Reporting duties apply (in force)Actively exploited vulnerabilities and severe incidents must be reported within set deadlines.
2027/12/11Full applicationAll requirements apply; products must complete conformity assessment and bear CE marking.

Key point: full application is only about 15 months away, and the vulnerability/incident reporting duties are already in force — even before a product is fully compliant, once it is on the EU market the reporting duty applies.

Which products are in scope?

The test is "products with digital elements": if the intended or reasonably foreseeable use includes a direct or indirect, logical or physical data connection to a device or network, it is in scope. The definition covers both hardware and software, including remote data-processing components required for the product to function.

In scope (typical examples)

  • IoT / smart home / wearables / cameras / connected toys
  • Routers, switches, modems and other network equipment
  • Laptops, phones, tablets and other endpoints
  • Operating systems, desktop & mobile apps, browsers
  • Software libraries, firmware, and required remote data-processing components

Excluded or special treatment

  • Already covered by sector law: medical devices (MDR/IVDR), automotive, civil aviation, marine equipment
  • Products developed exclusively for defense / national security / classified use
  • Pure cloud/SaaS generally not directly in scope (covered by NIS2 etc.); but cloud functions essential to a product count as part of it
  • Non-commercial open source is exempt; "open-source stewards" bear lighter duties, but once commercialized, manufacturer responsibilities apply

Four risk classes and compliance intensity

The CRA sorts products into four tiers by risk, which determine the compliance intensity and whether a third party is required:

ClassTypical examplesCompliance route
Default (~90%)Most software and general connected productsManufacturer self-assessment
Important IPassword managers, VPNs, firewalls, antivirus, home routersSelf-assess if fully using harmonized standards; otherwise third party
Important IIOperating systems, industrial firewalls, hardware with security functionsMandatory third party (Notified Body)
CriticalHardware security modules (HSM), smart-meter gateways, smart cardsMay require European cybersecurity certification (EUCC, etc.)

Six things every manufacturer must do

  • Security by design & secure by default: build in security from design and development; ship with a secure default configuration.
  • Vulnerability handling: monitor continuously, maintain a coordinated disclosure policy, and push timely security updates decoupled from feature updates.
  • Software Bill of Materials (SBOM): create and maintain a machine-readable inventory of components and dependencies.
  • Support-period commitment: provide security updates over a defined support period (generally recommended at least 5 years, unless the expected product life is shorter).
  • Conformity assessment & CE marking: complete assessment per risk class, compile technical documentation and the EU Declaration of Conformity (DoC), and affix CE marking.
  • Vulnerability & incident reporting: report to ENISA and the national CSIRT on a 24 / 72-hour / 14-day basis (this duty took effect on 2026/09/11).

Do I need "certification"?

This is clients' most common question. The key distinction: every product must complete a "conformity assessment" and bear CE marking, but only some risk classes require "third-party certification." The two are not the same.

  • Route A — manufacturer self-assessment: for the Default class, or Important I when harmonized standards are fully used. Self-assess against the Annex I essential requirements, compile technical documentation, sign the EU DoC and affix CE yourself; responsibility stays with the manufacturer.
  • Route B — third party / certification: for Important II (mandatory) and Critical (may require certification). A Notified Body performs type examination or QA assessment; Critical products may need European cybersecurity certification (e.g. EUCC), so budget time and cost for assessment.

Reporting duties already in force (key)

Since 11 September 2026, manufacturers must report two situations: (1) actively exploited vulnerabilities; and (2) severe security incidents. Reporting goes through the Single Reporting Platform (SRP) operated by ENISA, to the CSIRT of the member state of main establishment and to ENISA, with affected users notified "without undue delay."

DeadlineContent
24 hours (early warning)Submit an initial early warning within 24 hours of becoming aware.
72 hours (detailed notification)Affected products, severity, scope of impact and corrective measures taken.
14 days / 1 month (final report)Within 14 days where a fix is available; within 1 month for a severe incident.

The cost of non-compliance: administrative fines

  • €15 million or 2.5% of global annual turnover: breaches of essential cybersecurity requirements, core manufacturer duties, and vulnerability-handling and reporting obligations.
  • €10 million or 2% of turnover: other breaches (importer/distributor non-compliance, missing DoC, improper CE marking, failing Notified Body requirements).
  • €5 million or 1% of turnover: providing incorrect, incomplete or misleading information to a Notified Body or market surveillance authority.

Fines take the higher of the fixed amount or the turnover percentage; for large enterprises the percentage often exceeds the fixed amount.

IngSafe's CRA consulting services

We help clients meet the CRA in a practical, workable way, covering: applicability and classification assessment, gap analysis and a compliance roadmap, building the reporting process, and preparing technical documentation and Notified Body engagement. We tailor the most suitable route — self-assessment or third-party certification — to your products and their risk classification.

Compliance roadmap

  • 1. Product inventory & scoping: determine which products are PDE and their respective risk classes.
  • 2. Gap analysis: assess the current state clause-by-clause against the Annex I essential cybersecurity requirements.
  • 3. Build the reporting process (priority): get the 24/72-hour reporting mechanism working first, because this duty is already in force.
  • 4. Adopt a secure development lifecycle: establish SBOM, dependency management, vulnerability response and secure-update processes.
  • 5. Technical documentation & assessment route: compile technical documentation and decide on self-assessment or a Notified Body.
  • 6. Declaration of Conformity & CE: complete the DoC, affix CE marking and prepare for market surveillance.

Want to confirm whether your products fall under the CRA and which risk class they belong to? Contact us to arrange an initial assessment of your products.