Regulation (EU) 2024/2847
The CRA makes your product your responsibility.
ISO 27001 and SOC 2 describe how your company works. The EU Cyber Resilience Act asks about the thing you ship: what is inside it, how fast you react, and whether you can prove any of it. WardBee keeps that proof in one place.
The dates that matter
10 Dec 2024
In force
The regulation is law. The obligations phase in from here.
Already happened
11 Jun 2026
Conformity bodies
Rules for notified bodies apply, so assessment capacity starts to exist.
Prepare now
11 Sep 2026
Reporting duties
Actively exploited vulnerabilities and severe incidents become reportable — on a 24-hour clock.
Prepare now
11 Dec 2027
Full application
No CE marking under the CRA, no EU market. Every requirement applies.
Does it apply to you?
Scope follows the EU market, not your headquarters. If any of these describe you, the CRA is your problem.
- Connected hardware and IoT devices sold in the EU
- Commercial software products, on-premise or shipped
- Remote data processing sold as part of a product
- Components and libraries supplied to other manufacturers
- Importers and distributors placing products on the market
Free and open-source software developed outside a commercial activity is largely out of scope.
What the CRA asks for
Ship without known exploitable vulnerabilities
Products go out secure by default, with a risk assessment behind the choices — and stay that way through the support period, typically five years or more.
Know what is inside the product
A component inventory (SBOM) per release, kept current, plus a coordinated disclosure route so researchers can reach you.
Report on the clock
Early warning within 24 hours of becoming aware of active exploitation, notification within 72, and a final report after that. Awareness starts the clock, not the fix.
Hold the paperwork
Technical documentation, the conformity assessment, the EU declaration of conformity, and user information — available for ten years.
What WardBee does about it
One workspace for the product side of compliance — the register, the components, the cases, and the documents an authority or a customer will ask to see.
Product register
Every product with digital elements in one place, with its CRA class, conformity route, support period, and release history. The answer to “which products are in scope” stops being a spreadsheet.
Components and SBOMs
Upload the SBOM your build already produces and WardBee keeps the component picture per release, so a new CVE turns into a list of affected releases instead of a week of archaeology.
Where releases run
Deployment records connect a release to the customers and environments running it, so exposure questions get answered with facts, not estimates.
Reporting timelines
Open a case, record when your team became aware, and the 24-hour, 72-hour, and final-report deadlines are tracked with what has been submitted against each one.
Technical files and exports
Assemble the technical documentation and CRA report packages as PDFs built from what was actually recorded — reproducible later, not regenerated from whatever the data looks like today.
Readiness, honestly
A live view of which CRA requirements are backed by evidence, which are waiting on a human, and which are simply not covered yet. Gaps are named, never rounded into green.
A deadline is only tracked once a person on your team records awareness.No scanner result and no AI suggestion can start a statutory clock, or close one.
December 2027 is a hard date
Reporting duties already apply. Set up the product register and the evidence trail while there is still time to do it calmly.
This page summarizes the regulation for orientation and is not legal advice. The binding text is Regulation (EU) 2024/2847.