The EU Cyber Resilience Act, explained
If you place any product with digital elements on the EU market, you need a technical file, a Declaration of Conformity and a CE mark by 11 December 2027. Most manufacturers can do this themselves under Module A self-assessment, without a notified body. Reporting obligations for actively exploited vulnerabilities already applied from 11 September 2026.
What the CRA actually is
The Cyber Resilience Act is CE marking for cybersecurity. Before it, if you sold a smart doorbell or a piece of business software into the EU, nothing required you to demonstrate it was secure. The CRA changes that for every product with digital elements — any hardware or software placed on the EU market that connects to a device or network.
It is a horizontal regulation, meaning it cuts across sectors rather than applying to one industry. It imposes four broad duties on manufacturers: design against the essential requirements in Annex I, handle vulnerabilities across a declared support period, produce technical documentation, and affix a CE mark.
The dates that matter
| Date | What applies |
|---|---|
| 10 Dec 2024 | Regulation enters into force. No obligations yet. |
| 11 Jun 2026 | Chapter IV — rules for notified bodies. |
| 11 Sep 2026 | Article 14 reporting. Actively exploited vulnerabilities and severe incidents must be reported, with an early warning within 24 hours. What this means in practice. |
| 11 Dec 2027 | Full application. Essential requirements, technical documentation, conformity assessment, CE marking. |
Who is in scope
The test is not what your company does — it is what you place on the market. If your product has digital elements and it reaches EU users, you are almost certainly in scope, including if you are based outside the EU.
There are carve-outs: products already covered by sector rules such as medical devices, motor vehicles and civil aviation; pure cloud services that are not part of a product; and non-commercial open-source software. The boundaries are genuinely subtle, which is why the Commission's July 2026 guidance devotes 67 worked examples to them.
Work through whether it applies to your product →
What you must produce
Three artefacts, and a process behind them.
- Technical documentation — the contents are enumerated in Annex VII. This is the substantial one.
- EU Declaration of Conformity — a short document in which you state the product meets the regulation.
- CE marking — affixed once the above are complete.
Behind them sits a cybersecurity risk assessment, a vulnerability handling process, a coordinated disclosure policy, a software bill of materials, and a declared support period during which you will keep issuing security updates.
The conformity assessment route
This is where most of the fear comes from, and most of it is misplaced.
| Category | Examples | Route |
|---|---|---|
| Default | Most business and consumer software, mobile apps, ordinary connected devices | Module A — self-assessment. No notified body. |
| Important Class I | Password managers, VPNs, network management, boot managers | Module A if harmonised standards are applied in full; otherwise a notified body |
| Important Class II | Hypervisors, firewalls, intrusion detection, tamper-resistant microprocessors | Notified body involvement required |
| Critical | Hardware devices with security boxes, smart meter gateways, smartcards | Notified body, or European cybersecurity certification |
The overwhelming majority of products fall in the default category. How Module A self-assessment works →
The standards problem, stated honestly
This matters practically. You cannot currently point to a harmonised standard and claim presumption of conformity. What you can do — and what the guidance explicitly suggests — is read the matching draft, anticipate the requirements, and build the Annex I evidence regardless. The obligations apply on 11 December 2027 whether the standards are published or not.
Penalties
Article 64 sets three tiers:
- €15,000,000 or 2.5% of worldwide annual turnover — breaches of the Annex I essential requirements, or of Articles 13 and 14
- €10,000,000 or 2% — breaches of other obligations
- €5,000,000 or 1% — supplying incorrect or misleading information to notified bodies or market surveillance authorities
Whichever is higher, in each case.
Where to go next
Does it apply to me?
Scope, exclusions and the edge cases the Commission's guidance clarifies.
Read →What goes in the technical file
Annex VII section by section, with what each one actually means.
Read →The Commission's 2026 guidance
What the 27 July 2026 guidance says, in plain English.
Read →Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.