Cyber Resilience Act (CRA): What It Is and Who Must Comply
The EU Cyber Resilience Act explained: scope, deadlines, manufacturer obligations, and penalties for software and hardware vendors.
The Cyber Resilience Act is Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on December 10, 2024 and applies in three stages: provisions on conformity assessment bodies apply since June 11, 2026, reporting obligations for actively exploited vulnerabilities start on September 11, 2026, and the full set of requirements, including CE marking, technical documentation, SBOM, and conformity assessment, applies from December 11, 2027.
The regulation covers both hardware and software and applies regardless of where the manufacturer is established; what matters is whether the product is placed on the EU market. Manufacturers must build products securely, handle vulnerabilities throughout a defined support period, distribute security updates through a secure mechanism, and report actively exploited vulnerabilities to their CSIRT and ENISA. Non-compliance with the essential requirements can be fined with up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
For vendors shipping self-hosted software, we cover the practical side in our CRA hub for software vendors, including who is in scope and how to deliver security updates to on-prem and air-gapped customers.





