Skip to content
Distr
Book DemoStart free trialLogin

EU Cyber Resilience Act

CRA compliance for software vendors with self-hosted customers

If your customers run your software themselves, the Cyber Resilience Act applies to you. Practical guides on scope, deadlines, secure update distribution, and what to do first, written without legalese and with the sources cited.

50 days until the 24-hour vulnerability reporting obligation starts on September 11, 2026.

What is the Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on December 10, 2024 and applies in three stages: provisions on conformity assessment bodies apply since June 11, 2026, reporting obligations for actively exploited vulnerabilities start on September 11, 2026, and the full set of requirements, including CE marking, technical documentation, SBOM, and conformity assessment, applies from December 11, 2027.

The regulation covers both hardware and software and applies regardless of where the manufacturer is established; what matters is whether the product is placed on the EU market. Manufacturers must build products securely, handle vulnerabilities throughout a defined support period, distribute security updates through a secure mechanism, and report actively exploited vulnerabilities to their CSIRT and ENISA. Non-compliance with the essential requirements can be fined with up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.

See also the Cyber Resilience Act glossary entry and the official European Commission page on the Cyber Resilience Act.

How much time do you have?

Dec 10, 2024

CRA enters into force

Regulation (EU) 2024/2847 becomes law.

Action required: Start your scope memo and classify your products.

Jun 11, 2026

Assessment bodies ready

Conformity assessment body provisions apply.

Action required: Plan third-party assessments for Class I and II products.

Sep 11, 2026

Reporting obligations start

Actively exploited vulnerabilities: 24h early warning to your CSIRT and ENISA. Applies to products already on the market.

Action required: Have the reporting runbook and per-customer version tracking ready.

Dec 11, 2027

Full compliance required

Essential requirements, SBOM, technical documentation, conformity assessment, and CE marking.

Action required: Complete the technical file and secure update distribution.

Frequently Asked Questions

Does the Cyber Resilience Act apply to non-EU companies?

Yes. The CRA applies to any product with digital elements placed on the EU market, regardless of where the manufacturer is headquartered. A US vendor selling software to EU customers is covered exactly like an EU vendor.

Does the CRA apply to SaaS?

Software offered purely as a service is not placed on the market as a product and is out of CRA scope, though NIS2 or DORA may apply depending on sector and size. Self-hosted editions, on-prem agents, desktop clients, and installers are products in scope.

Is open-source software exempt?

Non-commercial open-source software is out of scope. Monetized editions carry full manufacturer obligations. Open-core companies typically act as manufacturer for the enterprise edition and as open-source software steward for the community edition, a light regime without fines.

What happens if we do nothing?

From September 11, 2026 you are subject to 24-hour reporting duties for actively exploited vulnerabilities. From December 11, 2027, non-compliant products cannot be newly placed on the EU market. Fines reach EUR 15 million or 2.5% of worldwide annual turnover, and market surveillance authorities can force withdrawals and recalls.

What does "Cyber Resilience Act" mean?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU regulation that sets mandatory cybersecurity requirements for products with digital elements placed on the EU market, including standalone software. Reporting obligations start September 11, 2026; full application begins December 11, 2027. Read the full glossary entry.

What does "Product with digital elements" mean?

A product with digital elements is any software or hardware product and its remote data processing solutions, including components placed on the market separately (Article 3(1) CRA). Standalone software qualifies on its own, without any hardware. Read the full glossary entry.

What does "Remote data processing solution" mean?

A remote data processing solution is data processing at a distance designed by or for the manufacturer, without which a product with digital elements could not perform one of its functions (Article 3(1)-(2) CRA). It marks the boundary between regulated products and pure SaaS. Read the full glossary entry.

What does "Open-source software steward" mean?

An open-source software steward is a legal person, other than a manufacturer, that systematically provides sustained support for the development of specific open-source products intended for commercial activities and ensures their viability (Article 3(14) CRA). Stewards carry light obligations and are exempt from fines. Read the full glossary entry.

What does "Support period" mean?

The support period under the Cyber Resilience Act is the time during which a manufacturer must handle vulnerabilities in a product, at least 5 years under Article 13(8) unless the product is expected to be in use for a shorter time. Read the full glossary entry.

What does "Security update" mean?

Under the Cyber Resilience Act, a security update addresses vulnerabilities and must be delivered separately from functionality updates where technically feasible (Annex I, Part II, point 2), so customers can take the patch without being forced onto new features. Read the full glossary entry.

What does "Coordinated vulnerability disclosure" mean?

Coordinated vulnerability disclosure is a process in which finders report vulnerabilities to the responsible manufacturer, who remediates them before details are published. The CRA makes a CVD policy and a reporting contact mandatory (Annex I, Part II, points 5 and 6). Read the full glossary entry.

Turn self-hosted into a repeatable sales motion

From your first on-prem POC to dozens of enterprise customers, the Distr platform gives you the tooling to deploy, update and manage self-hosted customers, backed by a team that supports you hands-on with the deployment knowledge and implementation help.

Proof from teams shipping self-hosted software

GovCloud deployments without extra overhead

"Distr gives us a clean way to deploy and update our software in GovCloud without breaking security or adding operational overhead."

Corbin Klett

Corbin Klett

Co-Founder, Artifact

Manual operations become one-click workflows

"Our main goal is to simplify the daily operations. No more manual installations, updates, or rollbacks — everything can now be handled with a single click with Distr."

Jefferson Rodrigues

Jefferson Rodrigues

Co-Founder & CTO, Lerian

Read case study

Updates that took days now take minutes

"Distr eliminated nearly all deployment headaches. Updates that used to take days now take minutes."

Ansh Gupta

Ansh Gupta

CTO, Sophris.ai

Read case study

One place for every self-hosted customer

"Having a dedicated space for all our self-hosted customers that can manage authenticated registry access is great."

Derek Reynolds

Derek Reynolds

Product Engineer, Basedash

Read case study

From guided setup to scalable delivery

"We went from hands-on Docker setup calls to an install flow that can be running in minutes."

Daniel Kasen

Daniel Kasen

Chief Engineer for Customer Success, Ozgar AI

Read case study

Self-hosted without the engineering tax

"Weave has a fully self-hosted offering. It's a huge unlock for us, but we almost didn't build it. Distr made such a huge difference in getting us there."

Andrew Churchill

Andrew Churchill

Co-Founder & CTO, Weave

Read case study