Skip to content
Distr
Book DemoStart free trialLogin
← Back to Glossary

Cyber Resilience Act (CRA): What It Is and Who Must Comply

The EU Cyber Resilience Act explained: scope, deadlines, manufacturer obligations, and penalties for software and hardware vendors.

The Cyber Resilience Act is Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on December 10, 2024 and applies in three stages: provisions on conformity assessment bodies apply since June 11, 2026, reporting obligations for actively exploited vulnerabilities start on September 11, 2026, and the full set of requirements, including CE marking, technical documentation, SBOM, and conformity assessment, applies from December 11, 2027.

The regulation covers both hardware and software and applies regardless of where the manufacturer is established; what matters is whether the product is placed on the EU market. Manufacturers must build products securely, handle vulnerabilities throughout a defined support period, distribute security updates through a secure mechanism, and report actively exploited vulnerabilities to their CSIRT and ENISA. Non-compliance with the essential requirements can be fined with up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.

For vendors shipping self-hosted software, we cover the practical side in our CRA hub for software vendors, including who is in scope and how to deliver security updates to on-prem and air-gapped customers.

Frequently Asked Questions

When does the Cyber Resilience Act apply?

It entered into force on December 10, 2024. Reporting obligations for actively exploited vulnerabilities start on September 11, 2026, and the full requirements, including CE marking and technical documentation, apply from December 11, 2027.

Does the CRA apply to non-EU companies?

Yes. What matters is whether a product is placed on the EU market, not where the manufacturer is established. A US vendor selling software to EU customers is covered.

What are the penalties for CRA non-compliance?

Breaches of the essential requirements can be fined with up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Market surveillance authorities can also restrict, withdraw, or recall products.

Turn self-hosted into a repeatable sales motion

From your first on-prem POC to dozens of enterprise customers, the Distr platform gives you the tooling to deploy, update and manage self-hosted customers, backed by a team that supports you hands-on with the deployment knowledge and implementation help.

Proof from teams shipping self-hosted software

GovCloud deployments without extra overhead

"Distr gives us a clean way to deploy and update our software in GovCloud without breaking security or adding operational overhead."

Corbin Klett

Corbin Klett

Co-Founder, Artifact

Manual operations become one-click workflows

"Our main goal is to simplify the daily operations. No more manual installations, updates, or rollbacks — everything can now be handled with a single click with Distr."

Jefferson Rodrigues

Jefferson Rodrigues

Co-Founder & CTO, Lerian

Read case study

Updates that took days now take minutes

"Distr eliminated nearly all deployment headaches. Updates that used to take days now take minutes."

Ansh Gupta

Ansh Gupta

CTO, Sophris.ai

Read case study

One place for every self-hosted customer

"Having a dedicated space for all our self-hosted customers that can manage authenticated registry access is great."

Derek Reynolds

Derek Reynolds

Product Engineer, Basedash

Read case study

From guided setup to scalable delivery

"We went from hands-on Docker setup calls to an install flow that can be running in minutes."

Daniel Kasen

Daniel Kasen

Chief Engineer for Customer Success, Ozgar AI

Read case study

Self-hosted without the engineering tax

"Weave has a fully self-hosted offering. It's a huge unlock for us, but we almost didn't build it. Distr made such a huge difference in getting us there."

Andrew Churchill

Andrew Churchill

Co-Founder & CTO, Weave

Read case study