Règlement (UE) 2024/2847

Reporting au titre du Cyber Resilience Act UE

Le Cyber Resilience Act impose des exigences de cybersécurité pour les produits comportant des éléments numériques sur le marché de l’UE. Les obligations de signalement commencent le 11 septembre 2026. Nous préparons des rapports CRA complets et prêts à déposer.

À qui cela s’adresse

Fabricants et éditeurs de matériels et logiciels connectés sur le marché de l’UE

Service

Reporting Cyber Resilience Act

§ 01

Ce qu’exige le Cyber Resilience Act

Regulation (EU) 2024/2847 introduces EU-wide cybersecurity obligations for hardware and software with digital elements, including:

  • 01Secure-by-design development against essential cybersecurity requirements
  • 02Vulnerability handling across the product lifecycle, including security updates
  • 03Reporting of actively exploited vulnerabilities and severe incidents — 24-hour early warning, 72-hour notification, then a final report
  • 04CE marking backed by conformity assessment (notified bodies for important and critical products)
§ 02

Calendrier d’application

Key CRA milestones manufacturers should plan against:

JalonDateStatut
Entry into force10 Dec 2024In force
Vulnerability & incident reporting11 Sept 2026Approaching
Full obligations · CE marking11 Dec 2027Horizon
§ 03

Ce que nous préparons

We act as your reporting concierge — not as a notified body. Where third-party conformity assessment is required, notified bodies certify.

  • 01Secure intake of product, security, and vulnerability information
  • 02Submission-ready CRA reports: early warnings, 72-hour notifications, and final reports
  • 03Supporting technical documentation — risk assessment, SBOM, support periods, and update policy
§ 04Questions fréquentes
Who is in scope of the Cyber Resilience Act?
Manufacturers of products with digital elements placed on the EU market — from consumer devices to enterprise software — subject to the regulation’s definitions and product categories. Distributors and importers have related duties under the CRA framework.
When do CRA reporting duties start?
Reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026. Broader secure-by-design and CE marking obligations apply from 11 December 2027.
Do you replace a notified body?
No. We prepare documentation and submission-ready reports. Conformity assessment for important and critical products is performed by notified bodies where required.
What information do you need from us?
Typically product inventory, security architecture notes, vulnerability handling processes, incident facts, SBOM or component lists, and support/update policy details. We provide a structured intake checklist per engagement.

Évaluez votre préparation au reporting CRA

Partagez votre portefeuille produits et votre horizon de reporting. Nous définissons le besoin d’intake.