Skip to content
14/15RegulationSupported in WardBee

EU Cyber Resilience Act (CRA) explained

EU law making manufacturers responsible for the cybersecurity of any product with digital elements they sell.

What it is

Regulation (EU) 2024/2847 sets mandatory cybersecurity requirements for products with digital elements placed on the EU market — hardware and software alike. Manufacturers must ship products free of known exploitable vulnerabilities, maintain a component inventory and a coordinated disclosure process, provide security updates across a defined support period, report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs, and hold technical documentation backing the CE marking.

Certifiable?

Not a certification — it is law. Conformity is declared (and for higher-risk classes, assessed) and shown by CE marking.

Where it's used

Anywhere in the EU market: manufacturers, importers, and distributors of connected hardware, software products, and the remote data processing sold with them.

Effort level

Heavy and ongoing: it covers the whole product lifetime, with a 24-hour reporting clock once you are aware of active exploitation.

Typical trigger

You sell or distribute a product with digital elements in the EU. Scope follows the market, not your headquarters.

Related frameworks

Sits beside ISO 27001 and SOC 2 rather than replacing them — those cover your organization, the CRA covers your product.

Why it matters

The CRA moves product security from a selling point to a condition of market access. From December 2027, a product with digital elements cannot carry CE marking — and therefore cannot be sold in the EU — unless its security requirements, vulnerability handling, and technical documentation are in place. The reporting duties bite a year earlier, and they run on hours, not weeks.

When is it needed?

As soon as you place a product with digital elements on the EU market, or plan to. Teams usually start when a distributor asks how the product will be CE marked under the CRA, or when a customer asks for an SBOM. Article 14 reporting obligations have applied since 11 September 2026.

Use cases

  • Connected hardware and IoT devices sold into the EU
  • Commercial software products and on-premise applications
  • SaaS with remote data processing sold as part of a product
  • Component and library vendors supplying other manufacturers
  • Importers and distributors verifying manufacturer conformity

Who asks for it?

  • Market surveillance authorities in EU member states
  • National CSIRTs and ENISA for reportable vulnerabilities and incidents
  • Notified bodies assessing important and critical product classes
  • Distributors and importers before taking a product to market
  • Enterprise customers asking for an SBOM and a support commitment

Benefits

  • Market access: CE marking under the CRA is the entry ticket to the EU
  • One product register that answers customer SBOM and support questions
  • Reporting deadlines tracked from the moment awareness is recorded
  • Evidence assembled continuously instead of rebuilt before every audit
  • Clear split between what is proven and what still needs human sign-off
  • Groundwork that also serves ISO 27001, SOC 2, and IEC 62443 programs

Legal requirements

Yes. Regulation (EU) 2024/2847 entered into force on 10 December 2024. Reporting obligations under Article 14 apply from 11 September 2026 and the regulation applies in full from 11 December 2027. Non-compliance carries administrative fines and can remove a product from the EU market. This is a summary, not legal advice.

Key control areas

Secure-by-default configuration and no known exploitable vulnerabilities at release
Product risk assessment carried through design and development
Component inventory (SBOM) maintained per release
Coordinated vulnerability disclosure policy and contact point
Security updates for the declared support period
Early warning within 24 hours of awareness of active exploitation
Notification within 72 hours, followed by a final report
Technical documentation, conformity assessment, and EU declaration of conformity
User information and instructions covering secure use
Product classification: default, important class I or II, or critical

Want to see how WardBee maps your environment to EU Cyber Resilience Act?