EU Cyber Resilience Act
CRA compliance for software vendors with self-hosted customers
If your customers run your software themselves, the Cyber Resilience Act applies to you. Practical guides on scope, deadlines, secure update distribution, and what to do first, written without legalese and with the sources cited.
50 days until the 24-hour vulnerability reporting obligation starts on September 11, 2026.
What is the Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on December 10, 2024 and applies in three stages: provisions on conformity assessment bodies apply since June 11, 2026, reporting obligations for actively exploited vulnerabilities start on September 11, 2026, and the full set of requirements, including CE marking, technical documentation, SBOM, and conformity assessment, applies from December 11, 2027.
The regulation covers both hardware and software and applies regardless of where the manufacturer is established; what matters is whether the product is placed on the EU market. Manufacturers must build products securely, handle vulnerabilities throughout a defined support period, distribute security updates through a secure mechanism, and report actively exploited vulnerabilities to their CSIRT and ENISA. Non-compliance with the essential requirements can be fined with up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
See also the Cyber Resilience Act glossary entry and the official European Commission page on the Cyber Resilience Act.
How much time do you have?
CRA enters into force
Regulation (EU) 2024/2847 becomes law.
Action required: Start your scope memo and classify your products.
Assessment bodies ready
Conformity assessment body provisions apply.
Action required: Plan third-party assessments for Class I and II products.
Reporting obligations start
Actively exploited vulnerabilities: 24h early warning to your CSIRT and ENISA. Applies to products already on the market.
Action required: Have the reporting runbook and per-customer version tracking ready.
Full compliance required
Essential requirements, SBOM, technical documentation, conformity assessment, and CE marking.
Action required: Complete the technical file and secure update distribution.
Cyber Resilience Act Content Hub
Written for vendors, checked against the regulation text, and kept current as the Commission guidance evolves.
The Cyber Resilience Act for Software Vendors Who Ship Self-Hosted Software
The complete overview: who is in scope, the three deadlines, every manufacturer duty, and the order of operations to get compliant.
Does the Cyber Resilience Act Apply to Your Company? A Decision Tree
SaaS or self-hosted, US or EU, open source or commercial: work through the tree and know in five minutes whether you are in scope.
What the Cyber Resilience Act Means for Open-Source Companies
Community edition, enterprise edition, steward regime: exactly which obligations land where, based on the regulation and the 2026 draft guidance.
Delivering Security Updates to On-Prem and Air-Gapped Customers Under the CRA
The hardest CRA duty for vendors with self-hosted customers: getting patches into environments you don't control, and proving it.
What Software Vendors Must Monitor Under the CRA (and the Reporting Clocks)
Dependencies, exploitation signals, customer versions, and your CVD inbox: the four things to watch before the 24-hour clock starts.
CRA Compliance Tooling: An Honest Map
No single tool makes you CRA-compliant. Here is the whole stack, layer by layer, including the one almost everyone forgets.
Frequently Asked Questions
Does the Cyber Resilience Act apply to non-EU companies?
Does the CRA apply to SaaS?
Is open-source software exempt?
What happens if we do nothing?
What does "Cyber Resilience Act" mean?
What does "Product with digital elements" mean?
What does "Remote data processing solution" mean?
What does "Open-source software steward" mean?
What does "Support period" mean?
What does "Security update" mean?
What does "Coordinated vulnerability disclosure" mean?
Turn self-hosted into a repeatable sales motion
From your first on-prem POC to dozens of enterprise customers, the Distr platform gives you the tooling to deploy, update and manage self-hosted customers, backed by a team that supports you hands-on with the deployment knowledge and implementation help.
Proof from teams shipping self-hosted software
GovCloud deployments without extra overhead
"Distr gives us a clean way to deploy and update our software in GovCloud without breaking security or adding operational overhead."

Corbin Klett
Co-Founder, Artifact
Manual operations become one-click workflows
"Our main goal is to simplify the daily operations. No more manual installations, updates, or rollbacks — everything can now be handled with a single click with Distr."
Updates that took days now take minutes
"Distr eliminated nearly all deployment headaches. Updates that used to take days now take minutes."
One place for every self-hosted customer
"Having a dedicated space for all our self-hosted customers that can manage authenticated registry access is great."
From guided setup to scalable delivery
"We went from hands-on Docker setup calls to an install flow that can be running in minutes."
Self-hosted without the engineering tax
"Weave has a fully self-hosted offering. It's a huge unlock for us, but we almost didn't build it. Distr made such a huge difference in getting us there."




