EU Cyber Resilience Act Programme

The CRA clock started in September 2026

From $3,000fixed quote after scoping·Reporting path first, then phased to December 2027·EU (for US, UK, Canadian, Australian and Indian vendors)

The EU Cyber Resilience Act applies to virtually every product with digital elements sold into the EU, which means connected hardware, embedded software, and a great deal of equipment whose makers have never thought of themselves as software vendors. Its reporting obligations became enforceable on 11 September 2026. Full compliance follows on 11 December 2027.

Two things make this harder than a normal conformity exercise. The CRA imposes continuing duties, not a one-off assessment: a vulnerability handling process, a coordinated disclosure policy, and the ability to report an actively exploited vulnerability within 24 hours. And it reaches manufacturers outside the EU as squarely as those inside it. Many US and UK hardware vendors haven't yet worked out that it applies to them.

This programme takes you the whole way. The part that's already enforceable, reporting, gets set up first. Then the essential requirements, the SBOM, vulnerability handling and the conformity route are worked through on a timeline that lands before December 2027.

What you receive

  • Scope and CRA class determined for each product
  • A working 24-hour reporting path to ENISA and your national CSIRT, set up first
  • Gap analysis against the Annex I essential cybersecurity requirements
  • An SBOM built and checked against what the regulation requires
  • Vulnerability handling process and coordinated disclosure policy in place
  • CRA technical documentation and conformity assessment route through to December 2027

Who this is for

  • You ship connected or software-containing hardware into the EU from outside it
  • You're not certain whether your product is in scope, or which CRA class applies
  • You have no SBOM, or one nobody has checked against the requirement
  • You have no documented vulnerability disclosure or incident reporting path

How it runs

  1. 1

    Scope determination

    Whether each product has digital elements in the CRA sense, and which class — default, important or critical — it falls into.

  2. 2

    Reporting path

    A workable route for the 24-hour early-warning obligation to ENISA and your national CSIRT, sized for a team without a security operations centre. This comes first because it already applies.

  3. 3

    Essential requirements

    Gap analysis against Annex I, then the SBOM, vulnerability handling process and disclosure policy built to close the gaps.

  4. 4

    Conformity

    Technical documentation assembled and the conformity assessment route completed, including third-party assessment where your class requires it.

Worth knowing

Checkable facts, with the source. Useful whether or not you buy anything from us.

  • The Cyber Resilience Act entered into force on 10 December 2024. Its reporting obligations became enforceable on 11 September 2026, and full compliance is required by 11 December 2027.

    Source: Regulation (EU) 2024/2847 (Cyber Resilience Act)

  • Manufacturers must report an actively exploited vulnerability with an early warning within 24 hours of becoming aware of it, to ENISA and the relevant national CSIRT.

    Source: CRA vulnerability and incident reporting obligations

  • Typical in-scope categories include IoT and embedded devices for home, healthcare and industrial use, industrial control and automation equipment, and consumer electronics such as wearables, smart appliances and connected security products.

    Source: 2026 CRA scope guidance for hardware manufacturers

Common questions

Does the CRA apply to us if we're not based in the EU?

If you place products with digital elements on the EU market, yes. The obligations attach to the product being made available in the Union, not to where the manufacturer sits.

What actually happens on 11 December 2027?

Full application of the regulation, including the essential cybersecurity requirements and the conformity assessment obligations. The reporting duties already apply as of 11 September 2026; that part isn't in the future.

Is an SBOM really mandatory?

Manufacturers must identify and document the components in their products, including through a software bill of materials in a commonly used machine-readable format covering at minimum the top-level dependencies. Building yours to that standard is part of the programme.

Do we need a notified body for the CRA?

It depends on class. Default-category products can generally self-assess; important and critical categories bring in third-party assessment. Establishing which one you're in is the first step, because it changes the cost of everything after it.

You might also need

Where we fit

What we do, and what we don't

Krono provides expert compliance advice and hands-on project work, built on real engineering experience. We work alongside the bodies that test and certify your product. We don't replace them.

We do

  • Work out what applies to your product and the route to legal sale
  • Plan your testing and coordinate with accredited labs and notified bodies on your behalf
  • Prepare and review your technical file, declarations and submissions
  • Advise on fixes, responses to authorities and ongoing obligations

We are not

  • A notified body, UK approved body or FCC TCB. We don't issue certificates or conformity decisions.
  • An accredited test laboratory. All testing is carried out by independent accredited labs.
  • A law firm. Our work is regulatory and engineering advice, not legal advice.
  • A guarantee of approval. Authorities, labs, notified bodies and marketplaces make their own decisions, and as the manufacturer you remain legally responsible for your product and sign every declaration.

The full terms for consulting engagements are in our Terms of Service.

Not sure this is the right engagement? Map your product free first — it takes about ten seconds and costs nothing.

Map your product