The EU Cyber Resilience Act (CRA) is no longer something businesses can watch from a distance and deal with later.

The Cyber Resilience Act entered into force on 11 December 2024

, and its first major operational deadline — mandatory vulnerability and incident reporting —

has already arrived, meaning all organisations that sell products in EU member countries are now subject to strict reporting obligations.

If your business manufactures, imports, or distributes any product with a digital component, this regulation almost certainly applies to you. And the penalties for getting it wrong are severe. This guide breaks down exactly what the CRA demands, who it covers, and the concrete steps you must take to build a compliant programme right now.


What Is the EU Cyber Resilience Act?

The Cyber Resilience Act aims to make sure all digital products are safe from cyber threats, requiring that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.

Prior to the CRA, there was no consistent, horizontal EU-wide framework governing the cybersecurity of products with digital elements. Manufacturers faced a patchwork of voluntary standards and sector-specific rules, creating significant disparities in security levels and enabling a "race to the bottom" in which products were routinely placed on the market with known vulnerabilities, without security updates, and with little transparency for consumers or business users.

The CRA changes all of that.

Before the CRA, cybersecurity was a product feature. Under the CRA, it is a condition for placing a product on the EU market. Every connected product must be secure by design, shipped without known exploitable vulnerabilities, and capable of receiving security updates.


Who Does the CRA Apply To?

This is one of the most important questions for businesses to answer — and the scope is broader than many expect.

The CRA applies to any organisation selling digital products in the EU, no matter where that organisation may be based. It touches a broad range of entities, including hardware manufacturers with connected or digital functionality, software vendors offering commercial or enterprise solutions, developers of embedded systems and firmware, and importers and distributors selling products under their own name in the EU. Non-EU companies are fully in scope if their products are sold in the EU.

The obligations differ by role:

- Manufacturers must meet the CRA's essential security requirements and perform conformity assessments.

Importers and distributors must verify that products are compliant, technically documented, and CE-marked before they enter circulation.

Providers of remote data-processing solutions — such as cloud services that support connected products — are also in scope.

Critically,

the CRA applies regardless of where the manufacturer is established: a company outside the EU that sells into the Union is in scope and must ensure an economic operator in the EU is responsible for the relevant obligations.

Products already covered by sector-specific rules — such as medical devices, motor vehicles, and civil aviation — are excluded. Non-commercial open-source software developed outside a commercial activity is largely outside scope, and open-source stewards have a lighter, tailored set of obligations.


The CRA Compliance Timeline: Key Deadlines You Cannot Miss

The EU Cyber Resilience Act has already entered into force, but its obligations are being implemented in multiple phases. The vulnerability reporting mandate took effect in September 2026, and full conformity — including CE marking — is required by December 2027.

Here is the phased timeline at a glance:

Manufacturers of connected products are subject to mandatory reporting of vulnerabilities and incidents via the Single Reporting Platform.

The broader requirements, including secure-by-design controls, technical documentation, conformity assessment, and CE marking, apply in full.

The organisations most likely to struggle are those that only begin compliance work when the final deadline approaches. That starting position is now risky because the CRA requires both process maturity and regulatory evidence well before full conformity is due.


The Reporting Obligations: What You Must Report and When

The reporting requirements under Article 14 are arguably the CRA's most operationally demanding element — and they are already active.

Any manufacturer that learns of an actively exploited vulnerability in one of its connected products must file a structured early warning with ENISA and its designated national Computer Security Incident Response Team (CSIRT) within 24 hours. A more detailed technical notification follows within 72 hours.

A final comprehensive report must be submitted no later than 14 days after a corrective measure is available for actively exploited vulnerabilities.

The Single Reporting Platform is now operational, having become live on 11 September 2026 — the date of entry into application of the CRA reporting requirements.

To put the challenge in perspective:

without an automated pipeline, a security team must manually review incoming CVE data, check each against their entire product lineup, and assemble a structured early warning — all within 24 hours — while potentially managing 131 or more new CVE entries per day, which was the average rate in 2025.

There is, however, one important clarification for businesses just getting started:

there is no retroactive reporting requirement — you do not have to report vulnerabilities whose active exploitation you were already aware of before 11 September 2026.


Product Classification and the Three-Tier Risk System

Not all products face identical compliance burdens.

The CRA creates a three-tier hierarchy based on cybersecurity risk, and the tier a product falls into determines the conformity assessment route.

- Default products may self-certify through a conformity assessment.

Important (Class I) products are subject to more prescriptive requirements, including the mandatory use of applicable harmonised standards. In many cases, these standards are required to demonstrate conformity, depending on the product category.

Important (Class II) products are subject to mandatory third-party assessment — you cannot self-certify your way to compliance.

Critical products, like firewalls or intrusion detection systems, require third-party conformity assessments.

Understanding which tier your product falls into is one of the first — and most consequential — steps in your CRA compliance journey.


Software Bills of Materials: A New Non-Negotiable

Alongside incident reporting, the CRA introduces a landmark new requirement for Software Bills of Materials (SBOMs).

The CRA mandates that manufacturers of products with software components create and maintain a software bill of materials (SBOM).

An SBOM is an inventory of the software components within a product, including operating system packages, third-party libraries, and dependencies. The regulation requires the SBOM to use a machine-readable format and to cover at least the product's top-level dependencies.

While the CRA does not require manufacturers to make the SBOM publicly available, they must include it in the product's technical documentation and provide it to market surveillance authorities upon request.

The practical case for building SBOMs now — even though the formal mandate doesn't kick in until December 2027 — is compelling.

Most modern products are assembled from open-source and third-party components, and a single flawed library can put an entire device at risk. When a new vulnerability hits, the manufacturers with an accurate SBOM know in minutes whether they're exposed. The ones without it start guessing.


Penalties for Non-Compliance

The CRA's enforcement teeth are real.

Failure to comply could result in fines of up to €15 million or 2.5 percent of the offender's total worldwide annual turnover for the preceding financial year.

If you're manufacturing or placing digital products on the European market — hardware with embedded software, standalone software products, or components bound for other manufacturers' supply chains — you need a concrete plan today. The deadlines are firm, the penalties are significant, and the technical groundwork required to meet them takes longer than most organisations anticipate.


Practical Tips: What to Do Right Now

Given that reporting obligations are already active, here is what your business should be doing immediately:

  1. Determine your scope. Map every product you sell into the EU market.

A product with digital elements is broadly defined as any software or hardware product whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.

  1. Classify your products. Run each product through the CRA's three-tier risk classification system to understand your conformity assessment obligations before the December 2027 deadline arrives.

  2. Stand up your vulnerability intake pipeline. You need automated systems to monitor CVE feeds and cross-reference them against your entire product portfolio — doing this manually within a 24-hour reporting window is operationally unviable at scale.

  3. Build your SBOMs now.

The formal SBOM mandate requiring machine-readable component inventories in CycloneDX or SPDX format does not technically apply until December 2027 — but the reporting obligation that is already active is structurally very difficult to meet without one.

  1. Read the Commission's guidance.

The European Commission published practical guidance on 27 July 2026 — designed specifically to lower the compliance barrier for smaller organisations, with 67 practical examples, flowcharts, and use cases covering scope, reporting obligations, and risk assessment.

  1. Appoint an EU authorised representative if needed.

If the manufacturer is outside the EU, the CRA places specific duties on importers and distributors who bring the product to the EU market, and often requires an authorised representative established in the EU.

  1. Check awareness across your supply chain.

A 2026 CRA Awareness and Readiness Report published by the Linux Foundation and OpenSSF found that 66% of respondents remain unfamiliar with the CRA

— a statistic that creates both risk and competitive opportunity for businesses that get ahead of the curve.


Conclusion: The Window to Act Responsibly Is Now

The EU Cyber Resilience Act represents the most significant shift in digital product regulation Europe has ever seen.

For companies that act early, CRA compliance can become more than a regulatory obligation — it can strengthen product security, improve software supply chain visibility, accelerate vulnerability response, and build customer confidence in a more closely scrutinised EU market.

The reporting obligations are live today. The full compliance regime arrives in December 2027. Every week you delay makes meeting both deadlines harder, costlier, and riskier.

Don't wait for a vulnerability incident or a market surveillance investigation to force your hand. Conduct a CRA readiness assessment, map your products against the regulation's requirements, and begin building the processes, documentation, and tooling that compliance demands. If you need expert guidance on navigating the Cyber Resilience Act — from product classification and SBOM generation to vulnerability management and conformity assessments — get in touch with a specialist today. The regulation won't wait, and neither should you.