The EU Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847 — is essentially "CE marking for cybersecurity." It's a product regulation: any manufacturer that places a product with digital elements on the EU market must build it securely, patch it for years, and report actively exploited vulnerabilities within 24 hours. Unlike NIS2, which governs how organisations run their security, the CRA governs how products are made. If you ship connected hardware or software in the EU, it applies to you.

The Cyber Resilience Act at a glance

  • Instrument: Regulation (EU) 2024/2847 — directly applicable, no national transposition
  • Who: manufacturers (plus importers & distributors) of products with digital elements
  • Core duties: secure-by-design, vulnerability handling, an SBOM, security updates, CE marking, 24h incident reporting to ENISA
  • Penalties: up to €15M or 2.5% of global annual turnover
  • Applies from: reporting duties 11 Sept 2026 · full application 11 Dec 2027

What is a "product with digital elements"?

The CRA's scope is broad: a product with digital elements (PDE) is any hardware or software placed on the EU market whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. That covers IoT devices, routers and firewalls, operating systems, desktop and mobile applications, and even software libraries and components sold or distributed commercially.

Some products are carved out because they're already covered by sector- specific rules — medical devices (MDR/IVDR), motor vehicles, civil aviation, and marine equipment. Pure cloud/SaaS is largely outside the CRA (it falls under NIS2 instead), except where remote data processing is integral to a product. Non-commercial open-source is excluded, and "open-source software stewards" carry lighter obligations.

Who has to comply?

The core obligations

The 24-hour reporting duty

This is the obligation arriving first (11 September 2026). A manufacturer must notify ENISA (and the relevant CSIRT) of an actively exploited vulnerability or a severe incident affecting the product's security — an early warning within 24 hours, a fuller notification within 72 hours, and a final report later. The cadence mirrors NIS2's incident reporting, but here it's tied to your product, not your organisation.

Penalties & timeline

Breaching the essential requirements or the vulnerability-handling obligations can cost up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher — a higher ceiling than NIS2. The regulation entered into force in December 2024 and applies in phases: the reporting obligations from 11 September 2026 and the full set of obligations from 11 December 2027.

CRA vs the other EU cyber regimes

The CRA sits alongside — not instead of — NIS2, GDPR and DORA. The simplest way to keep them straight: NIS2 and DORA govern how you operate; the CRA governs what you ship. A company can easily be caught by both — e.g. a manufacturer of connected devices (CRA) that is also an important entity under NIS2. For the operational side, see CRA vs NIS2 and NIS2 vs DORA.

Where risk quantification fits

The CRA is a product-lifecycle regime — SBOMs, secure development, conformity assessment — so it isn't something an external scan can certify. But two parts intersect directly with cyber risk quantification: the "no known exploitable vulnerabilities" bar and the 24-hour exploited-vulnerability report both hinge on knowing which of your vulnerabilities are actually being exploited. That's exactly what live EPSS, CISA KEV and SSVC signals tell you. Scanning your external attack surface shows which of your internet-facing products an attacker can already reach — a useful early-warning input, even though it's not a substitute for a secure-development programme.

Sources & official references

General information, not legal advice. Whether the CRA applies to a specific product, and in which conformity class, depends on the product and its intended use — confirm with qualified counsel.