Regulation (EU) 2024/2847
The Cyber Resilience Act is already running.
Two of its three dates have passed. Reporting duties start 11 September 2026.
Small or medium sized business? The self-check is free.
- done10 Dec 2024In force
- done11 Jun 2026Notified bodies
- next11 Sep 2026Reporting duties
- ahead11 Dec 2027Full application
ReferenceCRA Article 71(2)
Scope
If it has software in it, start from yes.
Not a list of gadgets. A component sold on its own counts by itself, and so does the cloud service your device needs to work.
Toggle a part.
What these words mean
- Product with digital elements
- The law's name for a software or hardware product together with the remote data processing it needs to work. A component placed on the market on its own counts as one too.
ReferenceCRA Article 3(1)
Classification
Your tier decides who signs off.
26 categories are named. Everything else is default.
In plain words
Most products sit in the default tier, where you assess your own product. The named categories are treated more strictly, and the strictest always need an independent third party.
Everything not named
Default
You assess it yourself
You check the product yourself, under internal control (module A).
Drag, or use the arrow keys.
What these words mean
- Harmonised standard
- A standard whose reference the EU has published in its Official Journal. Follow one and you are presumed to meet the requirements it covers.
- Third party
- An independent body that assesses the product instead of you assessing it yourself. The CRA calls these notified bodies.
ReferenceCRA Annexes III and IV; Implementing Regulation (EU) 2025/2392
What applies when
Two dates down, two to go.
Reporting arrives well before the rest.
In plain words
The rules switch on in stages, not all at once. The next stage is the duty to report, on 11 September 2026.
10 Dec 2024
The law enters into force
11 Jun 2026
Rules for notified bodies, Articles 35 to 51
11 Sep 2026
Reporting duties begin, Article 14
11 Dec 2027
The whole Regulation applies
ReferenceCRA Article 71(2)
Annex I
The part you actually have to build.
Thirteen properties the product must have, and eight things you never stop doing.
In plain words
Annex I is where the Regulation says what your product must do, and what you must keep doing about vulnerabilities while you support it.
These apply on the basis of your own cybersecurity risk assessment, and only where applicable. Annex I is not thirteen boxes every product ticks.
Part I: what the product must do
No known exploitable vulnerabilities
At the point it is made available on the market.
Cycling. Pick one to take over.
Part II: what you keep doing after it ships
1Identify and document components
A software bill of materials (SBOM) in a machine-readable format, covering at the very least the top-level dependencies.
2Fix vulnerabilities without delay
Security fixes go out separately from functionality updates, where that is technically feasible.
3Test and review regularly
Effective and regular security tests of the product.
4Disclose what you fixed
Once the update is out, with enough detail for users to act.
5Run a disclosure policy
A coordinated vulnerability disclosure policy, put in place and enforced.
6Publish a reporting contact
An address for vulnerabilities found in the product or its components.
7Distribute updates securely
Automatically as well, where applicable for security updates.
8Free of charge, unless otherwise agreed
Updates carry advisory messages. The exception is a business user agreeing otherwise on a tailor-made product.
Open any step for the detail.
at least 5 yr
How long Part II binds
The support period, and a floor rather than an answer: longer where the product is expected to be in use for longer.
2.5 % or EUR 15 M
Getting Annex I wrong
Of total worldwide annual turnover, whichever is higher.
What these words mean
- SBOM
- A software bill of materials: a machine-readable list of the components a product is built from. The CRA asks for the top-level dependencies at the very least, not every nested one.
- Support period
- The time for which you must keep handling vulnerabilities in the product. At least five years, and longer where the product is expected to be in use for longer.
ReferenceCRA Annex I Parts I and II; Articles 13(8) and 64
The standard, in draft
The standard everyone is waiting for is not finished.
The CRA says what to achieve. The draft EN 40000 series will say how to show it.
In plain words
EN 40000 is the standard being written for the CRA. It is still a draft, so following it does not yet give you the presumption that you comply.
- draft
Principles for cyber resilience
30 Aug 2026
- draft
Vulnerability Handling
30 Aug 2026
- draft
Generic Security Requirements
30 Oct 2027
Official Journal
Empty
What these words mean
- Presumption of conformity
- Follow a harmonised standard the EU has cited in the Official Journal, and you are presumed to meet the requirements that standard covers.
- Official Journal
- The EU's official gazette. A standard only carries presumption of conformity once its reference is published there.
ReferenceCRA Article 27(1); CEN, CENELEC and ETSI work programme M/606
AuCRA Platform
Somewhere to put the evidence.
A workspace laid out to follow the draft EN 40000 sections.
Product name
Intended purpose
Users
Operating environment
Auditable documentation. Not a CE mark, not a certificate, not legal advice.
ReferenceAuCRA Platform
Next step
Talk to the lab that tests this.
Auray is Asia's first O-RAN Alliance-authorised third-party testing laboratory, with EN 18031 security testing and ISO 27001 consulting.
Small or medium sized business? Start free with our self-check tool
Checked against
- Regulation (EU) 2024/2847 (CRA)
- Implementing Reg. (EU) 2025/2392
- ENISA SME Cyber Resilience Maturity Model
- BSI TR-03183 Parts 1-3
- EN 40000 series (draft)
- Commission CRA Guidance & FAQ
- Blue Guide 2022