EU regulation
The Cyber Resilience Act: what it requires and when
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU. It entered into force on 10 December 2024; manufacturers must report actively exploited vulnerabilities from 11 September 2026, and the full set of obligations applies from 11 December 2027.
Free plan, no card required.
What is the Cyber Resilience Act?
The Cyber Resilience Act, usually shortened to CRA, is the first EU law that puts binding cybersecurity requirements on products themselves rather than on the organisations that operate them. A product with digital elements, in the Regulation's words, is a software or hardware product together with its remote data processing solutions. That covers connected devices, industrial equipment, desktop and mobile applications, operating systems and the components other manufacturers build on.
The Regulation has two halves. Annex I Part I lists security properties a product must have when it is placed on the market, such as secure-by-default configuration, protection against unauthorised access and a minimised attack surface. Annex I Part II lists how the manufacturer must handle vulnerabilities for as long as the product is supported. Most of the day-to-day work sits in the second half.
Who has to comply?
The main obligations fall on the manufacturer: whoever develops or manufactures a product with digital elements, or has it developed, and markets it under its own name or trademark, whether it is sold, monetised or given away. Importers and distributors have their own duties, and a company that substantially modifies a product can become its manufacturer. Being based outside the EU does not change anything; what matters is that the product is made available on the EU market.
Some products are excluded because sector rules already cover them, including medical devices, motor vehicles and civil aviation. Software offered purely as a service falls under the NIS2 Directive instead, unless it is the remote data processing solution of a product.
- Manufacturers: the full set of obligations in Article 13 and Annex I.
- Importers and distributors: checks that products carry the CE marking and required documentation.
- Open-source software stewards: a lighter regime, and no administrative fines.
- Important and critical products (Annexes III and IV): stricter conformity assessment.
Key CRA dates
Article 71 staggers the Regulation. Reporting arrives more than a year before everything else, and it also covers products that were placed on the market before December 2027.
| Date | What applies |
|---|---|
| 10 December 2024 | Entry into force |
| 11 June 2026 | Chapter IV: notification of conformity assessment bodies |
| 11 September 2026 | Article 14: reporting of actively exploited vulnerabilities and severe incidents |
| 11 December 2027 | All remaining obligations, including essential requirements and CE marking |
What manufacturers must be able to show
The vulnerability-handling requirements produce evidence that a market surveillance authority can ask to see. The technical documentation must describe how vulnerabilities are handled, including the software bill of materials, the coordinated vulnerability disclosure policy and a contact address.
The support period must reflect how long the product is expected to be used and be at least five years, unless the product is expected to be used for less. Each security update must remain available for at least ten years or for the rest of the support period, whichever is longer.
- An SBOM in a commonly used, machine-readable format, covering at least the top-level dependencies.
- Vulnerabilities identified, documented and remediated without delay, including through security updates.
- Regular security testing and review of the product.
- A coordinated vulnerability disclosure policy and a contact address for reports.
- Security updates distributed securely, free of charge and without delay, with advisory messages.
- Technical documentation, a conformity assessment, an EU declaration of conformity and the CE marking.
Reporting under Article 14
From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in its product must send an early warning within 24 hours, a vulnerability notification within 72 hours and a final report no later than 14 days after a corrective or mitigating measure is available. Severe incidents follow a parallel track with a final report within one month. Reports go simultaneously to the CSIRT designated as coordinator and to ENISA through the single reporting platform, which ENISA opened on 11 September 2026.
Fines under Article 64
Member States set the penalties within the ceilings below; in each band the higher of the two amounts applies. Micro and small enterprises cannot be fined for missing the 24-hour early-warning deadline, and open-source software stewards cannot be fined at all.
| Breach | Up to |
|---|---|
| Essential requirements in Annex I, or obligations in Articles 13 and 14 | €15 million or 2.5% of worldwide annual turnover |
| Other obligations of economic operators listed in Article 64(3) | €10 million or 2% of worldwide annual turnover |
| Incorrect, incomplete or misleading information to authorities | €5 million or 1% of worldwide annual turnover |
Available in KROMSE today
KROMSE gives a manufacturer the evidence side of the CRA; the decisions stay with your people.
- Scans of repositories, container images and Linux-based firmware images for known vulnerabilities, secrets and misconfigurations.
- A CycloneDX and an SPDX SBOM for every scan, ready to download.
- Each finding explained in plain language, with CISA KEV, EPSS, NVD and ENISA EUVD context.
- CRA response cases with deadlines and recorded human decisions.
- On paid plans, internal Article 14 drafts for all six reporting stages, which a person completes, approves and submits.
- A CRA evidence pack and a signed audit-log export.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q4 2026CRA conformity assessment. A guided workflow will map your evidence to the Annex I requirements, for a person to review and complete.
- Coming · Q4 2026EU Declaration of Conformity generator. KROMSE will draft the EU Declaration of Conformity from your product record, for your signatory to check and sign.
- Coming · Q1 2027Submission to ENISA's single reporting platform. After a person approves an Article 14 report, KROMSE will send it to ENISA's single reporting platform.
- Coming · Q1 2027Machinery Regulation evidence. KROMSE will collect evidence for the cybersecurity-related requirements of the EU Machinery Regulation (EU) 2023/1230, next to your CRA record.
Frequently asked questions
Does the Cyber Resilience Act apply to software?
Yes. A product with digital elements can be software alone, such as a desktop or mobile application, an operating system or a software component placed on the market separately. Software offered purely as a service is covered by the NIS2 Directive rather than the CRA, unless it is the remote data processing solution of a product.
Does the CRA apply to products already on the market?
Partly. Products placed on the EU market before 11 December 2027 only fall under the Regulation if they are substantially modified from that date. The Article 14 reporting obligations are the exception: they apply to all in-scope products, including those placed on the market before December 2027.
When do CRA reporting obligations start?
On 11 September 2026. From that date a manufacturer must report actively exploited vulnerabilities and severe incidents affecting its products through ENISA's single reporting platform: an early warning within 24 hours, a notification within 72 hours and a final report later.
What are the fines under the Cyber Resilience Act?
Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaching the essential requirements or the obligations in Articles 13 and 14. Lower ceilings of €10 million or 2% and €5 million or 1% apply to other breaches and to misleading information given to authorities.
Does KROMSE make my product CRA compliant?
No tool can do that on its own, and KROMSE does not certify compliance. It finds known vulnerabilities in what you ship, produces SBOMs and keeps the evidence and decisions a CRA file needs. Whether the Regulation applies, and whether the product conforms, is decided by your organisation.