Skip to content
CRA Navigator

Regulation (EU) 2024/2847

The Cyber Resilience Act, reduced to what a manufacturer must actually do

The CRA makes cybersecurity a condition of market access for products with digital elements. It applies horizontally across sectors, covers the entire support period rather than the moment of sale, and carries penalties of up to EUR 15 million or 2.5% of worldwide annual turnover.

Reporting applies
11 Sep 2026
Full application
11 Dec 2027
Max penalty
EUR 15M / 2.5%

The dates that drive your plan

The reporting obligation arrives more than a year before full application, and it applies to products you have already shipped. That is the deadline most teams underestimate.

  1. 10 December 2024

    Entry into force

    Regulation (EU) 2024/2847 enters into force following publication in the Official Journal. The transition period begins.

  2. 11 June 2026

    Notified body provisions apply

    Rules covering conformity assessment bodies take effect, allowing notified bodies to be designated so they are available before manufacturers need them.

  3. 11 September 2026

    Reporting obligations apply

    Article 14 reporting begins. Manufacturers must notify actively exploited vulnerabilities and severe incidents to their CSIRT and ENISA — including for products already on the market.

  4. 11 December 2027

    Full application

    All remaining obligations apply. Products with digital elements placed on the EU market must meet the essential requirements and carry CE marking on that basis.

Step one

Classification determines everything downstream

Your product class sets the conformity assessment route, whether a notified body must be involved, and how much lead time you need. Get this wrong and the rest of the plan is built on sand.

CRA product classes and their conformity assessment routes
ClassAssessment routeWhat falls here
DefaultSelf-assessmentThe majority of products with digital elements. The manufacturer performs the conformity assessment internally and issues the EU declaration of conformity.
Important — Class IStandards or third partyAnnex III Class I products such as password managers, standalone routers, VPNs, and operating systems. Self-assessment is available only where harmonised standards are applied in full.
Important — Class IIThird party requiredAnnex III Class II products such as hypervisors, firewalls, and tamper-resistant microprocessors. A notified body must be involved in the conformity assessment.
CriticalEuropean certificationAnnex IV products including hardware devices with security boxes, smart meter gateways, and smartcards. May be required to hold certification under an EU cybersecurity certification scheme.
Run the classification check

Annex I

The essential cybersecurity requirements

Part I governs the product itself. Part II governs the processes you run around it for the whole support period. Part II is where most manufacturers have the furthest to go.

Part I

Product requirements

  • 01Delivered with no known exploitable vulnerabilities
  • 02Secure-by-default configuration, with the ability to reset
  • 03Security updates available, and automatic where appropriate
  • 04Protection against unauthorised access with strong authentication
  • 05Confidentiality of stored, transmitted, and processed data
  • 06Integrity protection for data, commands, and configuration
  • 07Data minimisation limited to what the product actually needs
  • 08Availability of essential functions and resilience to denial of service
  • 09Minimised attack surface, including exposed interfaces
  • 10Mitigation of exploitation impact through hardening and segmentation
  • 11Recording and monitoring of security-relevant activity
  • 12Secure and complete deletion of data and settings on demand

Part II

Vulnerability handling

  • 01Identify and document vulnerabilities and components, including an SBOM
  • 02Remediate vulnerabilities without delay via security updates
  • 03Apply regular testing and reviews of product security
  • 04Publicly disclose fixed vulnerabilities with descriptions and remediation guidance
  • 05Enforce a coordinated vulnerability disclosure policy
  • 06Provide a contact address for reporting vulnerabilities
  • 07Provide mechanisms to securely distribute updates
  • 08Disseminate security patches without delay and free of charge

Article 14

The reporting clock is measured in hours

When you become aware of an actively exploited vulnerability in your product, or a severe incident affecting its security, notification runs on a fixed escalation schedule through a single reporting platform.

  1. 24h

    Early warning

    An initial notification to the coordinating CSIRT and ENISA indicating that an actively exploited vulnerability or severe incident has been detected.

  2. 72h

    Vulnerability notification

    A fuller report covering the nature of the vulnerability, any corrective measures taken or available, and the exploitation status.

  3. 14d

    Final report

    A closing report describing the vulnerability, its severity and impact, and the remediation deployed. Users must be informed where relevant.

Meeting these windows is an operational problem before it is a legal one. You need a defined intake path, a triage owner, a decision authority available outside business hours, and pre-drafted notification templates. Building that after the first incident is too late.

Find out where you stand against Annex I

The readiness assessment scores your position across all eight domains and returns a prioritised gap list mapped to specific articles.

Start the readiness assessment