Regulations · CRA

Cyber Resilience Act

Regulation (EU) 2024/2847CRA (Regulation EU 2024/2847) applies to digital products from December 2027. Vulnerability reporting from September 2026. Check scope, penalties and obligations free.

Days until enforcement
497days
Atomic obligations
34
Max exposure
€15M
or 2.5% global turnover

Who is concerned?

The CRA applies to anyone placing a product with digital elements on the EU market — manufacturers, importers, distributors. "Digital elements" is broad : it includes :

  • Hardware with embedded software (IoT devices, industrial controllers, medical devices)
  • Standalone software products (desktop, mobile, server-side SaaS shipped as a product)
  • Connected devices with remote data processing
  • Components and remote data processing solutions integrated into products

If your product talks to the internet, has firmware, or processes data remotely — CRA likely applies to you.

What it requires (high-level)

The CRA imposes obligations across the full product lifecycle :

  • Essential cybersecurity requirements (Annex I) : secure by design, secure defaults, vulnerability handling, no exploitable known vulnerabilities at the time of placement on the market.
  • Vulnerability handling and SBOM (Article 13) : maintain a Software Bill of Materials, monitor known vulnerabilities, deliver security updates for the support period.
  • Conformity assessment (Module A/B+C/H) : self-assessment for default category, Notified Body audit for "important" and "critical" products.
  • CE marking : required before placing on the market.
  • Importer and distributor obligations (Articles 19, 20) : verify CE marking, retain documentation, support traceability.
  • Reporting : actively exploited vulnerabilities and severe incidents to ENISA within 24h.

Penalty exposure

Up to €15M or 2.5% of global annual turnover, whichever is higher.

Beyond fines : market withdrawal, recall obligations, reputational damage, importer/distributor liability cascading up the supply chain.

How NexCyber helps with CRA

NexCyber automates CRA readiness end-to-end :

  • SBOM as a compliance artifact — auto-mapped to Article 13. Accepted formats : SPDX 2.3, CycloneDX 1.5. Versioned, signed, downloadable.
  • Article-by-article readiness — every claim traces back to the article that produced it. EUR-Lex links live.
  • CE-marking workflow — conformity dossier ready for Notified Body review. No more "what do I show them?".
  • MRCC issuance — Machine-Readable Compliance Certificate signed cryptographically, verifiable by auditors and procurement teams in seconds.

Get started

Run a free CRA readiness assessment — 5 minutes, no credit card, EU-hosted.

CRA — Frequently asked questions

When does the EU Cyber Resilience Act apply?+

The CRA entered into force in December 2024. Manufacturer vulnerability and incident reporting obligations apply from 11 September 2026, and full compliance with all essential cybersecurity requirements is mandatory from 11 December 2027 for any product with digital elements placed on the EU market.

Which products fall in scope of the CRA?+

Any product with digital elements (software, hardware with embedded software, IoT devices, mobile apps, SaaS components delivered with a physical product) placed on the EU market, regardless of where the manufacturer is based. Class I and Class II categories carry tighter obligations including third-party conformity assessment.

What penalties apply for CRA non-compliance?+

Up to €15 million or 2.5% of worldwide annual turnover for breaches of essential requirements, whichever is higher. Member State authorities can also order product withdrawal from the EU market and disclose the violation publicly.

How do I check if my product is in CRA scope?+

Run the free CRA Scope Checker at nexcyber.eu/tools/cra-scope-checker — six guided questions, instant verdict, no login required. The NexCyber engine maps your product profile to Annex III categories and outputs an applicability letter and gap list.

See your CRA readiness in 5 minutes.

Free assessment. No credit card. EU-hosted. Auditable engine.

Run free assessment