The EU Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847 — is essentially "CE marking for cybersecurity." It's a product regulation: any manufacturer that places a product with digital elements on the EU market must build it securely, patch it for years, and report actively exploited vulnerabilities within 24 hours. Unlike NIS2, which governs how organisations run their security, the CRA governs how products are made. If you ship connected hardware or software in the EU, it applies to you.
The Cyber Resilience Act at a glance
- Instrument: Regulation (EU) 2024/2847 — directly applicable, no national transposition
- Who: manufacturers (plus importers & distributors) of products with digital elements
- Core duties: secure-by-design, vulnerability handling, an SBOM, security updates, CE marking, 24h incident reporting to ENISA
- Penalties: up to €15M or 2.5% of global annual turnover
- Applies from: reporting duties 11 Sept 2026 · full application 11 Dec 2027
What is a "product with digital elements"?
The CRA's scope is broad: a product with digital elements (PDE) is any hardware or software placed on the EU market whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. That covers IoT devices, routers and firewalls, operating systems, desktop and mobile applications, and even software libraries and components sold or distributed commercially.
Some products are carved out because they're already covered by sector- specific rules — medical devices (MDR/IVDR), motor vehicles, civil aviation, and marine equipment. Pure cloud/SaaS is largely outside the CRA (it falls under NIS2 instead), except where remote data processing is integral to a product. Non-commercial open-source is excluded, and "open-source software stewards" carry lighter obligations.
Who has to comply?
- Manufacturers bear the bulk of the obligations — design, documentation, vulnerability handling, updates, conformity assessment.
- Importers must only place compliant products on the market and verify the manufacturer did its part.
- Distributors must act with due care that a product carries CE marking and the required documentation.
The core obligations
- Security by design and by default — meet the essential cybersecurity requirements in Annex I, including shipping with no known exploitable vulnerabilities and secure default settings.
- Vulnerability handling — a coordinated vulnerability disclosure policy, and security updates provided free for a support period (default around five years).
- An SBOM (software bill of materials) documenting the components in the product.
- Conformity assessment + CE marking — self-assessment for most products; third-party assessment for "important" (class I/II) and "critical" product categories.
The 24-hour reporting duty
This is the obligation arriving first (11 September 2026). A manufacturer must notify ENISA (and the relevant CSIRT) of an actively exploited vulnerability or a severe incident affecting the product's security — an early warning within 24 hours, a fuller notification within 72 hours, and a final report later. The cadence mirrors NIS2's incident reporting, but here it's tied to your product, not your organisation.
Penalties & timeline
Breaching the essential requirements or the vulnerability-handling obligations can cost up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher — a higher ceiling than NIS2. The regulation entered into force in December 2024 and applies in phases: the reporting obligations from 11 September 2026 and the full set of obligations from 11 December 2027.
CRA vs the other EU cyber regimes
The CRA sits alongside — not instead of — NIS2, GDPR and DORA. The simplest way to keep them straight: NIS2 and DORA govern how you operate; the CRA governs what you ship. A company can easily be caught by both — e.g. a manufacturer of connected devices (CRA) that is also an important entity under NIS2. For the operational side, see CRA vs NIS2 and NIS2 vs DORA.
Where risk quantification fits
The CRA is a product-lifecycle regime — SBOMs, secure development, conformity assessment — so it isn't something an external scan can certify. But two parts intersect directly with cyber risk quantification: the "no known exploitable vulnerabilities" bar and the 24-hour exploited-vulnerability report both hinge on knowing which of your vulnerabilities are actually being exploited. That's exactly what live EPSS, CISA KEV and SSVC signals tell you. Scanning your external attack surface shows which of your internet-facing products an attacker can already reach — a useful early-warning input, even though it's not a substitute for a secure-development programme.
Sources & official references
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — essential requirements (Annex I), vulnerability-handling and reporting obligations (Art. 14), conformity assessment, and phased application dates.
- European Commission — Cyber Resilience Act overview and product-class guidance.
- ENISA — coordinated vulnerability disclosure and single reporting platform.
General information, not legal advice. Whether the CRA applies to a specific product, and in which conformity class, depends on the product and its intended use — confirm with qualified counsel.