What the Cyber Resilience Act requires
Regulation (EU) 2024/2847 introduces EU-wide cybersecurity obligations for hardware and software with digital elements, including:
- 01Secure-by-design development against essential cybersecurity requirements
- 02Vulnerability handling across the product lifecycle, including security updates
- 03Reporting of actively exploited vulnerabilities and severe incidents — 24-hour early warning, 72-hour notification, then a final report
- 04CE marking backed by conformity assessment (notified bodies for important and critical products)
Application timeline
Key CRA milestones manufacturers should plan against:
| Milestone | Date | Status |
|---|---|---|
| Entry into force | 10 Dec 2024 | In force |
| Vulnerability & incident reporting | 11 Sept 2026 | Approaching |
| Full obligations · CE marking | 11 Dec 2027 | Horizon |
What we prepare
We act as your reporting concierge — not as a notified body. Where third-party conformity assessment is required, notified bodies certify.
- 01Secure intake of product, security, and vulnerability information
- 02Submission-ready CRA reports: early warnings, 72-hour notifications, and final reports
- 03Supporting technical documentation — risk assessment, SBOM, support periods, and update policy
Who is in scope of the Cyber Resilience Act?
When do CRA reporting duties start?
Do you replace a notified body?
What information do you need from us?
Scope your CRA reporting readiness
Share your product portfolio and reporting horizon. We will outline intake needs for vulnerability notifications, incident reports, and supporting technical documentation.