# Cyber Resilience Act (CRA)

EU cybersecurity requirements for products with digital elements

> The CRA has applied in part since 11 September 2026 and applies in full from 11 December 2027. This page covers which products are in scope, the dates, what manufacturers must do and the penalties.

Updated: 5 October 2026  
URL: https://sbom.se/en/cra/overview

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements that are made available on the EU market, hardware and software alike. The obligations fall on manufacturers, importers and distributors. As a regulation it applies directly in every member state, without national legislation.

This page is a summary, not legal advice. The regulation text is linked under References.

## Dates

| Date              | What applies                                                                                               |
| ----------------- | ---------------------------------------------------------------------------------------------------------- |
| 10 December 2024  | The regulation entered into force.                                                                         |
| 11 June 2026      | The rules on conformity assessment bodies (Chapter IV) apply.                                              |
| 11 September 2026 | Reporting obligations apply: manufacturers report actively exploited vulnerabilities and severe incidents. |
| 11 December 2027  | All other requirements apply, including the essential cybersecurity requirements and the SBOM.             |

The reporting obligations cover all products in scope, including those placed on the market before 11 December 2027. The other requirements apply to older products only if they are substantially modified after that date.

## Products in scope

A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately. The CRA applies when the intended or reasonably foreseeable use of the product includes a data connection to a device or a network. Operating systems, routers, password managers, smart home devices, mobile apps and software libraries sold as products are all examples.

Some products are outside the scope because other EU rules cover them:

* medical devices and in vitro diagnostic medical devices
* motor vehicles covered by the vehicle type-approval rules
* certified civil aviation products
* marine equipment
* products developed or modified exclusively for national security or defence

Free and open-source software is in scope only when it is made available on the market in the course of a commercial activity. Organisations that support open-source projects on a sustained basis without being manufacturers are called open-source software stewards. They have lighter obligations and are not subject to the administrative fines.

## Product classes

Most products belong to the default category, where the manufacturer assesses conformity itself. Two annexes list products with stricter rules.

| Category            | Examples                                                                                   | Conformity assessment                                                                                         |
| ------------------- | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------- |
| Default             | Most software and connected devices                                                        | The manufacturer's own assessment (internal control)                                                          |
| Important, class I  | Identity management systems, browsers, password managers, VPNs, operating systems, routers | Own assessment if harmonised standards or a certification scheme are applied in full, otherwise a third party |
| Important, class II | Hypervisors and container runtime systems                                                  | A third party (notified body) or a European cybersecurity certification scheme                                |
| Critical            | Hardware devices with security boxes, smart meter gateways, smartcards                     | A European cybersecurity certification scheme, or the class II procedures                                     |

## What manufacturers must do

The essential cybersecurity requirements are in Annex I, which has two parts.

Part I covers the product itself. A product must, among other things:

* be made available without known exploitable vulnerabilities
* have a secure default configuration
* support security updates, automatic where applicable
* protect against unauthorised access
* protect the confidentiality and integrity of data
* limit its attack surface

Part II covers vulnerability handling during the support period. Manufacturers must:

1. identify and document vulnerabilities and components, including by drawing up a software bill of materials (SBOM)
2. address and remediate vulnerabilities without delay, with security updates
3. test and review the security of the product regularly
4. publish information about fixed vulnerabilities once an update is available
5. have a policy on coordinated vulnerability disclosure
6. provide a contact address for reporting vulnerabilities
7. distribute updates securely
8. provide security updates without delay and free of charge

Manufacturers must also carry out a cybersecurity risk assessment, keep technical documentation, draw up an EU declaration of conformity and affix the CE marking. When they integrate components from third parties, open source included, they must exercise due diligence so that the components do not compromise the security of the product.

[SBOM requirements in the CRA](https://sbom.se/en/cra/sbom-requirements) describes what the regulation says about the SBOM. [Vulnerability reporting under the CRA](https://sbom.se/en/cra/vulnerability-reporting) describes the reporting obligations that already apply.

## Support period

The manufacturer decides the support period based on how long the product is expected to be in use. It must be at least five years, unless the product is expected to be in use for a shorter time. Each security update must remain available for at least ten years after it was issued, or for the rest of the support period if that is longer. The technical documentation must be kept for at least ten years after the product was placed on the market.

## Penalties

| Infringement                                                                                 | Maximum fine                                                             |
| -------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| The essential requirements in Annex I and the manufacturer obligations in Articles 13 and 14 | EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher |
| Other obligations, for example those of importers and distributors                           | EUR 10 million or 2% of worldwide annual turnover                        |
| Incorrect, incomplete or misleading information to authorities                               | EUR 5 million or 1% of worldwide annual turnover                         |

Microenterprises and small enterprises are not fined for missing the 24-hour deadline for an early warning.

## Guidance from the Commission

On 27 July 2026 the European Commission published guidance on how the CRA applies. It covers when a product is in scope, remote data processing, open source, what counts as a substantial modification and how to set the support period, with 67 examples. The Commission also maintains an FAQ. Both are linked under References.

## Video

A conference talk from the Linux Foundation, published in June 2026, on what the CRA and its SBOM requirement mean for development teams (in English, 38 minutes).

Video: [From Compliance To Code: The Cyber Resilience Act, SBOMs, DevTeams (The Linux Foundation)](https://www.youtube.com/watch?v=ZkJhtRGXwQk)

## References

- [Regulation (EU) 2024/2847 (Cyber Resilience Act)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng): The full text of the regulation in the Official Journal of the European Union.
- [European Commission: Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act): The Commission's overview page, with dates and links to guidance.
- [European Commission: guidance on the application of the CRA](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation): Guidance published on 27 July 2026 on scope, remote data processing, open source, substantial modification and support periods, with 67 examples.
- [European Commission: CRA implementation FAQ](https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-implementation-frequently-asked-questions): Frequently asked questions about implementing the CRA.
