Skip to content

Regulation (EU) 2024/2847

The CRA makes your product your responsibility.

ISO 27001 and SOC 2 describe how your company works. The EU Cyber Resilience Act asks about the thing you ship: what is inside it, how fast you react, and whether you can prove any of it. WardBee keeps that proof in one place.

The dates that matter

10 Dec 2024

In force

The regulation is law. The obligations phase in from here.

Already happened

11 Jun 2026

Conformity bodies

Rules for notified bodies apply, so assessment capacity starts to exist.

Prepare now

11 Sep 2026

Reporting duties

Actively exploited vulnerabilities and severe incidents become reportable — on a 24-hour clock.

Prepare now

11 Dec 2027

Full application

No CE marking under the CRA, no EU market. Every requirement applies.

Does it apply to you?

Scope follows the EU market, not your headquarters. If any of these describe you, the CRA is your problem.

  • Connected hardware and IoT devices sold in the EU
  • Commercial software products, on-premise or shipped
  • Remote data processing sold as part of a product
  • Components and libraries supplied to other manufacturers
  • Importers and distributors placing products on the market

Free and open-source software developed outside a commercial activity is largely out of scope.

What the CRA asks for

Ship without known exploitable vulnerabilities

Products go out secure by default, with a risk assessment behind the choices — and stay that way through the support period, typically five years or more.

Know what is inside the product

A component inventory (SBOM) per release, kept current, plus a coordinated disclosure route so researchers can reach you.

Report on the clock

Early warning within 24 hours of becoming aware of active exploitation, notification within 72, and a final report after that. Awareness starts the clock, not the fix.

Hold the paperwork

Technical documentation, the conformity assessment, the EU declaration of conformity, and user information — available for ten years.

What WardBee does about it

One workspace for the product side of compliance — the register, the components, the cases, and the documents an authority or a customer will ask to see.

Product register

Every product with digital elements in one place, with its CRA class, conformity route, support period, and release history. The answer to “which products are in scope” stops being a spreadsheet.

Components and SBOMs

Upload the SBOM your build already produces and WardBee keeps the component picture per release, so a new CVE turns into a list of affected releases instead of a week of archaeology.

Where releases run

Deployment records connect a release to the customers and environments running it, so exposure questions get answered with facts, not estimates.

Reporting timelines

Open a case, record when your team became aware, and the 24-hour, 72-hour, and final-report deadlines are tracked with what has been submitted against each one.

Technical files and exports

Assemble the technical documentation and CRA report packages as PDFs built from what was actually recorded — reproducible later, not regenerated from whatever the data looks like today.

Readiness, honestly

A live view of which CRA requirements are backed by evidence, which are waiting on a human, and which are simply not covered yet. Gaps are named, never rounded into green.

A deadline is only tracked once a person on your team records awareness.No scanner result and no AI suggestion can start a statutory clock, or close one.

December 2027 is a hard date

Reporting duties already apply. Set up the product register and the evidence trail while there is still time to do it calmly.

This page summarizes the regulation for orientation and is not legal advice. The binding text is Regulation (EU) 2024/2847.