The Cyber Resilience Act (CRA), officially Regulation (EU) 2024/2847, is the European Union’s first horizontal regulatory framework introducing harmonized mandatory cybersecurity requirements for products with digital elements.
Its objective is to ensure that hardware and software remain secure throughout the entire product lifecycle, from development and manufacturing to maintenance and market withdrawal.
Objectives
Tha CRA aims to:
- Ensure security by design and by default
- Reduce the number of vulnerabilities in products
- Introduce mandatory vulnerability management
- Ensure timely distribution of security patches
- Increase transparency for users
- Establish a single set of rules across the EU market
Who Is Subject to the CRA?
The CRA applies to almost all Products with Digital Elements (PDEs) placed on the EU market.
- Manufacturers
This includes:
- Hardware manufacturers
- Software manufacturers
- SaaS solutions when they form an integral part of a product
- OEM manufacturers
- IoT device manufacturers
- Products Within the Scope of the CRA
Examples include:
- Hardware manufacturers
- Software manufacturers
- SaaS solutions when they form an integral part of a product
- OEM manufacturers
- IoT device manufacturers
- Economic operators
The CRA also applies to:
- Authorized representatives
- Importers
- Distributors
- Entities placing products on the EU market
Key obligations of Manufacturers
- The Cyber Resilience Act introduces a range of new responsibilities for manufacturers. Organizations developing or placing products on the EU market must:
- Conduct cybersecurity risk assessments
- Implement security according to the secure-by-design principle
- Maintain vulnerability management processes
- Provide security updates throughout the expected support period
- Prepare technical documentation related to product security
- Carry out appropriate conformity assessment procedures
- Issue an EU Declaration of Conformity
- Affix the CE marking once all applicable requirements have been met
Reporting Vulnerabilities and Security Incidents
One of the most significant innovations introduced by the CRA is the obligation to report actively exploited vulnerabilities and serious security incidents.
As of 11 September 2026, manufacturers must report such events through the system managed by ENISA (European Union Agency for Cybersecurity).
Reporting Deadlines:
- Initial warning within 24 hours of becoming aware of the issue
- More detailed notification within 72 hours
- Final report no later than 14 days after a corrective measure becomes available for an actively exploited vulnerability, or within one month for a serious security incident
This approach enables faster coordination between manufacturers, national authorities, and cybersecurity experts while reducing the risk of cybersecurity threats spreading further.
Important Dates
The CRA entered into force on 10 December 2024, but its provisions are applied gradually.
- Incident reporting obligations apply from 11 September 2026
- The full set of requirements, including mandatory product compliance and CE marking, will apply from 11 December 2027
Impact on Organizations
The Cyber Resilience Act will affect more than just technology manufacturers. Organizations that purchase or use digital products will also benefit from improved security and transparency.
The CRA is expected to:
- Increase user trust in digital products
- Reduce costs associated with cybersecurity incidents
- Improve risk management within organizations
- Encourage the development of more secure products and services
CE Marking
Once compliance with the CRA has been demonstrated, products must bear the CE marking, through which the manufacturer declares that the product meets the requirements of the Regulation.
Most Important CRA Articles
Article 13 – Obligations of Manufacturers
Article 13 requires manufacturers to:
- Conduct cybersecurity risk assessments
- Develop products according to the secure-by-design principle
- Provide security updates
- Maintain vulnerability management processes
- Keep technical documentation
Article 14 – Vulnerability Management and Incident Reporting
Article 14 defines:
- Reporting of actively exploited vulnerabilities
- Reporting of serious incidents
- 24-hour / 72-hour reporting timelines
- Communication with ENISA and national CSIRT authorities
Annex I
Part I: Essential Cybersecurity Requirements
- Secure configuration
- Protection against unauthorized access
- Authentication
- Data integrity
- Minimization of the attack surface
Part II: Vulnerability Handling Requirements
- Vulnerability monitoring
- Coordinated Vulnerability Disclosure (CVD)
- Patch management
- Security updates throughout the product lifecycle
Annex III
Defines Important Products, such as:
- Network equipment
- Password managers
- VPN devices
- Security tools
Annex IV
Defines Critical Products, such as:
- Smart card devices
- Secure elements
- Certain cryptographic components
Conclusion
The Cyber Resilience Act represents one of the most important European cybersecurity regulations of recent years.
By introducing mandatory cybersecurity requirements throughout the entire lifecycle of digital products, the European Union aims to strengthen the resilience of the digital ecosystem and protect citizens, businesses, and public institutions from growing cyber threats.
Organizations that begin preparing for CRA compliance in a timely manner will gain not only regulatory compliance but also a significant competitive advantage in an increasingly demanding digital marketplace.
Source: The Cyber Resilience Act – Summary of the legislative text | Shaping Europe’s digital future

