Cyber Resilience Act (CRA)

EU cybersecurity requirements for products with digital elements

Updated 5 October 2026

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements that are made available on the EU market, hardware and software alike. The obligations fall on manufacturers, importers and distributors. As a regulation it applies directly in every member state, without national legislation.

This page is a summary, not legal advice. The regulation text is linked under References.

Dates

DateWhat applies
10 December 2024The regulation entered into force.
11 June 2026The rules on conformity assessment bodies (Chapter IV) apply.
11 September 2026Reporting obligations apply: manufacturers report actively exploited vulnerabilities and severe incidents.
11 December 2027All other requirements apply, including the essential cybersecurity requirements and the SBOM.

The reporting obligations cover all products in scope, including those placed on the market before 11 December 2027. The other requirements apply to older products only if they are substantially modified after that date.

Products in scope

A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately. The CRA applies when the intended or reasonably foreseeable use of the product includes a data connection to a device or a network. Operating systems, routers, password managers, smart home devices, mobile apps and software libraries sold as products are all examples.

Some products are outside the scope because other EU rules cover them:

  • medical devices and in vitro diagnostic medical devices
  • motor vehicles covered by the vehicle type-approval rules
  • certified civil aviation products
  • marine equipment
  • products developed or modified exclusively for national security or defence

Free and open-source software is in scope only when it is made available on the market in the course of a commercial activity. Organisations that support open-source projects on a sustained basis without being manufacturers are called open-source software stewards. They have lighter obligations and are not subject to the administrative fines.

Product classes

Most products belong to the default category, where the manufacturer assesses conformity itself. Two annexes list products with stricter rules.

CategoryExamplesConformity assessment
DefaultMost software and connected devicesThe manufacturer's own assessment (internal control)
Important, class IIdentity management systems, browsers, password managers, VPNs, operating systems, routersOwn assessment if harmonised standards or a certification scheme are applied in full, otherwise a third party
Important, class IIHypervisors and container runtime systemsA third party (notified body) or a European cybersecurity certification scheme
CriticalHardware devices with security boxes, smart meter gateways, smartcardsA European cybersecurity certification scheme, or the class II procedures

What manufacturers must do

The essential cybersecurity requirements are in Annex I, which has two parts.

Part I covers the product itself. A product must, among other things:

  • be made available without known exploitable vulnerabilities
  • have a secure default configuration
  • support security updates, automatic where applicable
  • protect against unauthorised access
  • protect the confidentiality and integrity of data
  • limit its attack surface

Part II covers vulnerability handling during the support period. Manufacturers must:

  1. identify and document vulnerabilities and components, including by drawing up a software bill of materials (SBOM)
  2. address and remediate vulnerabilities without delay, with security updates
  3. test and review the security of the product regularly
  4. publish information about fixed vulnerabilities once an update is available
  5. have a policy on coordinated vulnerability disclosure
  6. provide a contact address for reporting vulnerabilities
  7. distribute updates securely
  8. provide security updates without delay and free of charge

Manufacturers must also carry out a cybersecurity risk assessment, keep technical documentation, draw up an EU declaration of conformity and affix the CE marking. When they integrate components from third parties, open source included, they must exercise due diligence so that the components do not compromise the security of the product.

SBOM requirements in the CRA describes what the regulation says about the SBOM. Vulnerability reporting under the CRA describes the reporting obligations that already apply.

Support period

The manufacturer decides the support period based on how long the product is expected to be in use. It must be at least five years, unless the product is expected to be in use for a shorter time. Each security update must remain available for at least ten years after it was issued, or for the rest of the support period if that is longer. The technical documentation must be kept for at least ten years after the product was placed on the market.

Penalties

InfringementMaximum fine
The essential requirements in Annex I and the manufacturer obligations in Articles 13 and 14EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher
Other obligations, for example those of importers and distributorsEUR 10 million or 2% of worldwide annual turnover
Incorrect, incomplete or misleading information to authoritiesEUR 5 million or 1% of worldwide annual turnover

Microenterprises and small enterprises are not fined for missing the 24-hour deadline for an early warning.

Guidance from the Commission

On 27 July 2026 the European Commission published guidance on how the CRA applies. It covers when a product is in scope, remote data processing, open source, what counts as a substantial modification and how to set the support period, with 67 examples. The Commission also maintains an FAQ. Both are linked under References.

Video

A conference talk from the Linux Foundation, published in June 2026, on what the CRA and its SBOM requirement mean for development teams (in English, 38 minutes).

References

Regulation (EU) 2024/2847 (Cyber Resilience Act)

The full text of the regulation in the Official Journal of the European Union.

CRA, EU

European Commission: Cyber Resilience Act

The Commission's overview page, with dates and links to guidance.

CRA, EU

European Commission: guidance on the application of the CRA

Guidance published on 27 July 2026 on scope, remote data processing, open source, substantial modification and support periods, with 67 examples.

CRA, EU, Guidance

European Commission: CRA implementation FAQ

Frequently asked questions about implementing the CRA.

CRA, EU, Guidance

Cyber Resilience Act (CRA) | SBOM Guide