The EU Cyber Resilience Act, explained

Last reviewed: 11 September 2026~9 min read Regulation (EU) 2024/2847

If you place any product with digital elements on the EU market, you need a technical file, a Declaration of Conformity and a CE mark by 11 December 2027. Most manufacturers can do this themselves under Module A self-assessment, without a notified body. Reporting obligations for actively exploited vulnerabilities already applied from 11 September 2026.

What the CRA actually is

The Cyber Resilience Act is CE marking for cybersecurity. Before it, if you sold a smart doorbell or a piece of business software into the EU, nothing required you to demonstrate it was secure. The CRA changes that for every product with digital elements — any hardware or software placed on the EU market that connects to a device or network.

It is a horizontal regulation, meaning it cuts across sectors rather than applying to one industry. It imposes four broad duties on manufacturers: design against the essential requirements in Annex I, handle vulnerabilities across a declared support period, produce technical documentation, and affix a CE mark.

The dates that matter

CRA obligations and when they apply
DateWhat applies
10 Dec 2024Regulation enters into force. No obligations yet.
11 Jun 2026Chapter IV — rules for notified bodies.
11 Sep 2026Article 14 reporting. Actively exploited vulnerabilities and severe incidents must be reported, with an early warning within 24 hours. What this means in practice.
11 Dec 2027Full application. Essential requirements, technical documentation, conformity assessment, CE marking.

Who is in scope

The test is not what your company does — it is what you place on the market. If your product has digital elements and it reaches EU users, you are almost certainly in scope, including if you are based outside the EU.

There are carve-outs: products already covered by sector rules such as medical devices, motor vehicles and civil aviation; pure cloud services that are not part of a product; and non-commercial open-source software. The boundaries are genuinely subtle, which is why the Commission's July 2026 guidance devotes 67 worked examples to them.

Work through whether it applies to your product →

What you must produce

Three artefacts, and a process behind them.

  1. Technical documentation — the contents are enumerated in Annex VII. This is the substantial one.
  2. EU Declaration of Conformity — a short document in which you state the product meets the regulation.
  3. CE marking — affixed once the above are complete.

Behind them sits a cybersecurity risk assessment, a vulnerability handling process, a coordinated disclosure policy, a software bill of materials, and a declared support period during which you will keep issuing security updates.

The conformity assessment route

This is where most of the fear comes from, and most of it is misplaced.

Which route applies to your product
CategoryExamplesRoute
DefaultMost business and consumer software, mobile apps, ordinary connected devicesModule A — self-assessment. No notified body.
Important Class IPassword managers, VPNs, network management, boot managersModule A if harmonised standards are applied in full; otherwise a notified body
Important Class IIHypervisors, firewalls, intrusion detection, tamper-resistant microprocessorsNotified body involvement required
CriticalHardware devices with security boxes, smart meter gateways, smartcardsNotified body, or European cybersecurity certification

The overwhelming majority of products fall in the default category. How Module A self-assessment works →

The standards problem, stated honestly

None of the 35 CRA harmonised standards is published. All 17 ETSI product-specific drafts were still in public enquiry as of August 2026, and the presumption of conformity under Article 27 is therefore unavailable to anyone. The Commission set 30 October 2026 as a delivery deadline for product-specific standards, but delivery is not publication and no citation timetable has been confirmed.

This matters practically. You cannot currently point to a harmonised standard and claim presumption of conformity. What you can do — and what the guidance explicitly suggests — is read the matching draft, anticipate the requirements, and build the Annex I evidence regardless. The obligations apply on 11 December 2027 whether the standards are published or not.

Penalties

Article 64 sets three tiers:

  • €15,000,000 or 2.5% of worldwide annual turnover — breaches of the Annex I essential requirements, or of Articles 13 and 14
  • €10,000,000 or 2% — breaches of other obligations
  • €5,000,000 or 1% — supplying incorrect or misleading information to notified bodies or market surveillance authorities

Whichever is higher, in each case.

Where to go next

Sources