EU Cyber Resilience Act Programme
The CRA clock started in September 2026
The EU Cyber Resilience Act applies to virtually every product with digital elements sold into the EU, which means connected hardware, embedded software, and a great deal of equipment whose makers have never thought of themselves as software vendors. Its reporting obligations became enforceable on 11 September 2026. Full compliance follows on 11 December 2027.
Two things make this harder than a normal conformity exercise. The CRA imposes continuing duties, not a one-off assessment: a vulnerability handling process, a coordinated disclosure policy, and the ability to report an actively exploited vulnerability within 24 hours. And it reaches manufacturers outside the EU as squarely as those inside it. Many US and UK hardware vendors haven't yet worked out that it applies to them.
This programme takes you the whole way. The part that's already enforceable, reporting, gets set up first. Then the essential requirements, the SBOM, vulnerability handling and the conformity route are worked through on a timeline that lands before December 2027.
What you receive
- Scope and CRA class determined for each product
- A working 24-hour reporting path to ENISA and your national CSIRT, set up first
- Gap analysis against the Annex I essential cybersecurity requirements
- An SBOM built and checked against what the regulation requires
- Vulnerability handling process and coordinated disclosure policy in place
- CRA technical documentation and conformity assessment route through to December 2027
Who this is for
- You ship connected or software-containing hardware into the EU from outside it
- You're not certain whether your product is in scope, or which CRA class applies
- You have no SBOM, or one nobody has checked against the requirement
- You have no documented vulnerability disclosure or incident reporting path
How it runs
- 1
Scope determination
Whether each product has digital elements in the CRA sense, and which class — default, important or critical — it falls into.
- 2
Reporting path
A workable route for the 24-hour early-warning obligation to ENISA and your national CSIRT, sized for a team without a security operations centre. This comes first because it already applies.
- 3
Essential requirements
Gap analysis against Annex I, then the SBOM, vulnerability handling process and disclosure policy built to close the gaps.
- 4
Conformity
Technical documentation assembled and the conformity assessment route completed, including third-party assessment where your class requires it.
Worth knowing
Checkable facts, with the source. Useful whether or not you buy anything from us.
The Cyber Resilience Act entered into force on 10 December 2024. Its reporting obligations became enforceable on 11 September 2026, and full compliance is required by 11 December 2027.
Source: Regulation (EU) 2024/2847 (Cyber Resilience Act)
Manufacturers must report an actively exploited vulnerability with an early warning within 24 hours of becoming aware of it, to ENISA and the relevant national CSIRT.
Source: CRA vulnerability and incident reporting obligations
Typical in-scope categories include IoT and embedded devices for home, healthcare and industrial use, industrial control and automation equipment, and consumer electronics such as wearables, smart appliances and connected security products.
Source: 2026 CRA scope guidance for hardware manufacturers
Common questions
Does the CRA apply to us if we're not based in the EU?
If you place products with digital elements on the EU market, yes. The obligations attach to the product being made available in the Union, not to where the manufacturer sits.
What actually happens on 11 December 2027?
Full application of the regulation, including the essential cybersecurity requirements and the conformity assessment obligations. The reporting duties already apply as of 11 September 2026; that part isn't in the future.
Is an SBOM really mandatory?
Manufacturers must identify and document the components in their products, including through a software bill of materials in a commonly used machine-readable format covering at minimum the top-level dependencies. Building yours to that standard is part of the programme.
Do we need a notified body for the CRA?
It depends on class. Default-category products can generally self-assess; important and critical categories bring in third-party assessment. Establishing which one you're in is the first step, because it changes the cost of everything after it.