EU Cyber Resilience Act (CRA) explained
EU law making manufacturers responsible for the cybersecurity of any product with digital elements they sell.
What it is
Regulation (EU) 2024/2847 sets mandatory cybersecurity requirements for products with digital elements placed on the EU market — hardware and software alike. Manufacturers must ship products free of known exploitable vulnerabilities, maintain a component inventory and a coordinated disclosure process, provide security updates across a defined support period, report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs, and hold technical documentation backing the CE marking.
Certifiable?
Not a certification — it is law. Conformity is declared (and for higher-risk classes, assessed) and shown by CE marking.
Where it's used
Anywhere in the EU market: manufacturers, importers, and distributors of connected hardware, software products, and the remote data processing sold with them.
Effort level
Heavy and ongoing: it covers the whole product lifetime, with a 24-hour reporting clock once you are aware of active exploitation.
Typical trigger
You sell or distribute a product with digital elements in the EU. Scope follows the market, not your headquarters.
Related frameworks
Sits beside ISO 27001 and SOC 2 rather than replacing them — those cover your organization, the CRA covers your product.
Why it matters
The CRA moves product security from a selling point to a condition of market access. From December 2027, a product with digital elements cannot carry CE marking — and therefore cannot be sold in the EU — unless its security requirements, vulnerability handling, and technical documentation are in place. The reporting duties bite a year earlier, and they run on hours, not weeks.
When is it needed?
As soon as you place a product with digital elements on the EU market, or plan to. Teams usually start when a distributor asks how the product will be CE marked under the CRA, or when a customer asks for an SBOM. Article 14 reporting obligations have applied since 11 September 2026.
Use cases
- Connected hardware and IoT devices sold into the EU
- Commercial software products and on-premise applications
- SaaS with remote data processing sold as part of a product
- Component and library vendors supplying other manufacturers
- Importers and distributors verifying manufacturer conformity
Who asks for it?
- Market surveillance authorities in EU member states
- National CSIRTs and ENISA for reportable vulnerabilities and incidents
- Notified bodies assessing important and critical product classes
- Distributors and importers before taking a product to market
- Enterprise customers asking for an SBOM and a support commitment
Benefits
- Market access: CE marking under the CRA is the entry ticket to the EU
- One product register that answers customer SBOM and support questions
- Reporting deadlines tracked from the moment awareness is recorded
- Evidence assembled continuously instead of rebuilt before every audit
- Clear split between what is proven and what still needs human sign-off
- Groundwork that also serves ISO 27001, SOC 2, and IEC 62443 programs
Legal requirements
Yes. Regulation (EU) 2024/2847 entered into force on 10 December 2024. Reporting obligations under Article 14 apply from 11 September 2026 and the regulation applies in full from 11 December 2027. Non-compliance carries administrative fines and can remove a product from the EU market. This is a summary, not legal advice.
Key control areas
Want to see how WardBee maps your environment to EU Cyber Resilience Act?