Regulation (EU) 2024/2847

The EU Cyber Resilience Act regulation, explained article by article

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for products with digital elements sold in the EU. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking, applies from 11 December 2027. This guide covers who is in scope, every obligation, the penalties, and all 40 articles and annexes in plain English.

CRA timeline and key dates

The application dates come from Article 71 of the regulation. Reporting bites first. A manufacturer that waits for the 2027 deadline will already be non-compliant on reporting for over a year.

EU Cyber Resilience Act key dates under Regulation (EU) 2024/2847
MilestoneDateLegal basis
Regulation entered into force10 December 2024Article 71(1)
Notified body provisions apply (Chapter IV)11 June 2026Article 71(2)
Article 14 vulnerability and incident reporting applies11 September 2026Article 71(2)
Full regulation applies, including CE marking11 December 2027Article 71(2)

Follow enforcement as it develops in the CRA enforcement tracker or watch the live countdown to 11 September 2026.

Who is in scope

The CRA applies to products with digital elements placed on the EU market. Article 3 defines these as software or hardware products, including their remote data processing solutions, with a direct or indirect data connection to a device or network. Where the manufacturer sits does not matter. A US or Asian vendor selling into the EU carries the same obligations as a European one.

Three classification tiers decide how demanding the conformity route gets. Default products self-assess. Important products listed in Annex III (Class I includes routers, password managers, and smart home devices, Class II includes firewalls and hypervisors) face stricter assessment. Critical products listed in Annex IV (smart meter gateways, smartcards, secure elements) face the strictest route.

Excluded are products already covered by sector rules, such as medical devices, vehicles, aviation, and marine equipment. SaaS is out of scope unless it is remote data processing integral to a product. Open-source software developed outside a commercial activity is exempt, with light-touch duties for open-source stewards under Article 24. Unsure where your product lands? Run the free classification tool.

The obligations, in order of work

Which products are covered?

The CRA covers products with digital elements, meaning hardware and software whose intended use includes a direct or indirect data connection to a device or network. That reaches from smart thermostats and routers to operating systems, mobile apps, and industrial controllers sold in the EU.

Scope and exclusions (Article 2)

What security must products meet by design?

Annex I Part I sets the essential requirements a product must meet before it reaches the market. Secure default configuration, no known exploitable vulnerabilities at release, access control, data protection, and attack surface minimisation, all driven by a documented cybersecurity risk assessment.

Essential requirements (Annex I)

What are the manufacturer obligations?

Article 13 is the master obligations article. It covers the risk assessment, SBOM and component due diligence, security updates across a declared support period, post-market vulnerability handling, and a coordinated vulnerability disclosure policy with a public security contact.

Manufacturer obligations (Article 13)

What must be reported, and how fast?

From 11 September 2026, an actively exploited vulnerability or a severe incident must reach ENISA and your coordinator CSIRT as an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days or one month depending on the trigger.

Reporting deadlines (Article 14)

What paperwork does conformity require?

Annex VII technical documentation proves the product meets Annex I. On top of it sit the EU Declaration of Conformity under Article 28 and the CE marking under Article 30. Most products self-assess under Module A, while Annex III and IV classes face stricter routes.

Technical documentation (Annex VII)

Which conformity route applies?

Article 32 decides whether you can self-assess or need a notified body. Default products use internal control (Module A). Important products under Annex III can keep self-assessment only by fully applying harmonised standards, and critical products under Annex IV face the strictest treatment.

Conformity assessment (Article 32)

Penalties

Article 64 sets three fine tiers. Breaching the Annex I essential requirements or the Article 13 and 14 obligations reaches 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. Other obligations reach 10 million euros or 2 percent. Supplying misleading information to notified bodies or market surveillance authorities reaches 5 million euros or 1 percent. Market surveillance authorities can also order corrective action, restrict availability, or force a product off the market. Details in the Article 64 explainer.

Frequently asked questions

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU law setting mandatory cybersecurity requirements for hardware and software sold in the EU. It requires products with digital elements to be secure by design, kept secure with updates through a declared support period, and backed by vulnerability handling and incident reporting processes.

When does the Cyber Resilience Act take effect?

The regulation entered into force on 10 December 2024. Article 14 reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026, and the full regulation, including CE marking and conformity assessment, applies from 11 December 2027.

Who does the CRA apply to?

The CRA applies to manufacturers placing products with digital elements on the EU market, wherever the manufacturer is based. Importers and distributors carry their own obligations, and they are treated as manufacturers when they sell under their own brand or substantially modify a product.

Does the CRA apply to software?

Yes. Standalone software is a product with digital elements, so operating systems, desktop and mobile applications, and embedded firmware are all in scope. Pure services such as SaaS fall outside the CRA unless they qualify as remote data processing integral to a product, and open-source software developed outside a commercial activity is exempt.

What are the penalties for CRA non-compliance?

Breaching the essential requirements or the core manufacturer obligations can draw administrative fines of up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. Lesser breaches reach 10 million euros or 2 percent, and supplying misleading information to authorities reaches 5 million euros or 1 percent.

What is a product with digital elements?

A product with digital elements is any software or hardware product, including its remote data processing solutions, whose intended purpose involves a direct or indirect logical or physical data connection to a device or network. The definition sits in Article 3 of the regulation.

What is the difference between important and critical products under the CRA?

Annex III lists important products, split into Class I such as password managers and routers and Class II such as firewalls and hypervisors, which face stricter conformity assessment. Annex IV lists critical products such as smart meter gateways and secure elements, which face the strictest route and can be required to obtain European cybersecurity certification.

How does the CRA relate to NIS2?

The CRA regulates products while NIS2 regulates organisations that operate essential and important services. A manufacturer can be covered by both at once, and the reporting clocks differ, so incident processes need to handle CRA product reporting and NIS2 entity reporting side by side.

Do I need a notified body for CRA compliance?

Most products can self-assess under Module A internal control. A notified body becomes relevant for Annex III important products that do not fully apply harmonised standards, and for Annex IV critical products. Chapter IV provisions on notified bodies apply from 11 June 2026 so the assessment capacity can build up ahead of the 2027 deadline.

What should a manufacturer do first for CRA compliance?

Classify each product against Annex III and IV to learn your conformity route, then run the cybersecurity risk assessment against Annex I. In parallel, stand up the coordinated vulnerability disclosure process and the Article 14 reporting workflow, because reporting applies from 11 September 2026, before the rest of the regulation.

Longer answers, with the sources

The CRA FAQ answers each of these questions in depth, with every claim pinpointed to the Regulation, Commission guidance or a harmonised standard, and each source marked as binding or interpretive.

Browse the CRA FAQ →

The regulation, article by article

Plain-English explainers for all 40 articles and annexes relevant to manufacturers, each verified against the final text of Regulation (EU) 2024/2847 and linked to the official EUR-Lex source.

CVD & Incident Reporting

Article 13

Obligations of Manufacturers

Article 13 of the EU Cyber Resilience Act is the master obligations article for manufacturers, and it applies in full to products placed on the EU market from 11 December 2027. It is one of the longest and most operationally significant provisions in the regulation, covering the full lifecycle of a product's security: initial design and risk assessment (paragraphs 1–5), SBOM and component due diligence (paragraphs 6–8), security updates and support periods (paragraphs 9–11), post-market monitoring and vulnerability handling (paragraphs 12–14), coordinated vulnerability disclosure (paragraphs 15–17), and cooperation with market surveillance authorities and users (paragraphs 18–20).

Read →
Article 15

Voluntary Reporting of Vulnerabilities and Incidents

Article 15 of the EU Cyber Resilience Act creates a voluntary reporting pathway alongside the mandatory Article 14 deadlines, letting manufacturers and other parties notify a national CSIRT of vulnerabilities that are not yet actively exploited, near-misses, and security-relevant information that could benefit the broader cybersecurity community. Voluntary notifications are encouraged and acknowledge reporters' good-faith cooperation with EU cybersecurity objectives.

Read →
Article 16

Establishment of the Single Reporting Platform and ENISA's Vulnerability Coordination Role

Article 16 of the EU Cyber Resilience Act mandates ENISA to create and operate the single reporting platform that receives Article 14 vulnerability and incident notifications when reporting begins on 11 September 2026. It also covers ENISA's role in establishing the European Vulnerability Database (EVDB) as the EU's authoritative registry for vulnerabilities in CRA-regulated products, and ENISA's coordination function across national CSIRTs for cross-border vulnerability disclosure.

Read →

Product & Manufacturer Obligations

Article 3

Definitions: Key Terms in the Cyber Resilience Act

Article 3 contains the statutory definitions that underpin the entire Cyber Resilience Act. The most consequential definition is 'product with digital elements' — any hardware or software product capable of connecting, directly or indirectly, to a device or network. Other defined terms establish who bears obligations (manufacturer, importer, distributor, authorised representative) and what types of activity are regulated (placing on the market, making available, substantial modification). Correctly applying these definitions is the essential first step in CRA compliance planning.

Read →
Article 6

Essential Cybersecurity Requirements for Products with Digital Elements

Article 6 is the pivotal compliance provision of the CRA: it requires manufacturers to ensure their products with digital elements satisfy the essential requirements set out in Annex I. Annex I is divided into two parts - Part I covers the security properties products must have at the point of design and manufacture, and Part II covers the vulnerability handling processes manufacturers must maintain after placing products on the market. Compliance with Article 6 is the condition for bearing the CE marking and accessing the EU single market.

Read →
Article 20

Distributor Obligations Under the Cyber Resilience Act

Article 20 addresses distributors - entities in the supply chain that make products with digital elements available on the EU market but who are not the manufacturer or importer. Distributors have lighter obligations than manufacturers and importers, but they still have a duty to verify that products are compliant before making them available and to cooperate with authorities when issues arise. Distributors who modify products or sell them under their own name take on manufacturer-level obligations.

Read →

Annexes — Product Classification

Other Articles

Annex II

Information and Instructions to Users Required Under the CRA

Annex II defines the minimum information and instructions that manufacturers must provide to users of products with digital elements. This user-facing information package is a legally required element of CRA compliance - it enables users to assess the security properties of a product before purchase and to take appropriate action throughout the product's lifetime. Failure to provide the required information is a CRA violation subject to penalties under Article 64.

Read →
Annex V

EU Declaration of Conformity: Required Fields and Structure

Annex V provides the model structure for the EU Declaration of Conformity required under Article 28. It specifies every element that must appear, from product identification through to the conformity assessment procedure used and the signatory's details. Manufacturers preparing a declaration should use Annex V as the checklist that ensures no required element is missing, and Annex VI where the short form pointing to it is supplied with the product instead.

Read →
Annex VI

Simplified EU Declaration of Conformity: Model Structure

Annex VI gives the model structure for the simplified EU Declaration of Conformity. Instead of reproducing the full Annex V declaration with every unit, the manufacturer supplies a short statement identifying itself and the product, declaring conformity with Regulation (EU) 2024/2847, and pointing to an internet address where the full declaration can be obtained. The simplified form is a delivery mechanism, not a lighter obligation: the full Annex V declaration must still exist, be signed and be kept available.

Read →
Annex VII

Technical Documentation Requirements Under the CRA

Annex VII specifies the content of the technical documentation that manufacturers must prepare and maintain to support CRA compliance. The technical file is the complete evidence base demonstrating that a product meets the essential requirements - it includes product design documentation, cybersecurity risk assessments, software bills of materials, test results, and references to the CVD policy. This documentation must be available to market surveillance authorities on request and must be maintained for 10 years after the last product is placed on the market.

Read →
Annex VIII

Conformity Assessment Procedures: Modules A, B, C and H

Annex VIII contains the conformity assessment procedures a manufacturer follows to demonstrate that a product with digital elements meets the essential requirements in Annex I. It describes internal control (Module A), EU type-examination (Module B), conformity to type based on internal production control (Module C) and conformity based on full quality assurance (Module H). Article 32 decides which of these are open to a given product, based on whether it is a default, important or critical product.

Read →
Article 1

Subject Matter and Purpose of the Cyber Resilience Act

Article 1 establishes the overarching purpose of the EU Cyber Resilience Act: to ensure that products with digital elements placed on the EU market meet baseline cybersecurity requirements throughout their lifecycle. It sets the foundation for all subsequent obligations by defining what the regulation aims to achieve and why. Manufacturers, importers, and distributors operating in the EU single market must understand Article 1 as the lens through which all other provisions are interpreted.

Read →
Article 17

Other Provisions Related to Reporting

Article 17 wraps up the CRA's reporting chapter. It lets ENISA share notification information with EU-CyCLONe for large-scale incident coordination, empowers the coordinating CSIRT to inform the public about a severe incident (or require the manufacturer to do so), provides that notifying does not by itself increase the notifier's liability, has ENISA add fixed, publicly known vulnerabilities to the European vulnerability database, gives manufacturers, especially SMEs, helpdesk support from the coordinating CSIRTs, and sets up ENISA's 24-month technical report on emerging cybersecurity risk trends.

Read →
Article 18

Authorised Representatives: EU Presence for Non-EU Manufacturers

Article 18 requires manufacturers established outside the European Union who place products with digital elements on the EU market to appoint an authorised representative established within the EU. The authorised representative is the legal point of contact for national market surveillance authorities, ENISA, and other competent bodies. This provision ensures that there is always an EU-based entity accountable for CRA compliance, regardless of where the manufacturer is located.

Read →
Article 19

Importer Obligations Under the Cyber Resilience Act

Article 19 places specific obligations on importers - entities that bring products with digital elements manufactured outside the EU into the EU market for the first time. Importers must verify that manufacturers have met their CRA obligations before placing products on the market, and they bear personal liability for non-compliant products they import. This provision creates a compliance gateway role for importers within the EU supply chain.

Read →
Article 2

Scope and Exclusions Under the Cyber Resilience Act

Article 2 defines the scope of the CRA - which products and economic operators are covered - and sets out important exclusions for sectors already regulated under other EU frameworks. Understanding the scope boundaries is critical for manufacturers who operate across multiple product categories or who supply products to regulated industries such as medical devices, aviation, or automotive. Where exclusions apply, the CRA does not impose additional obligations, but the underlying sector regulation typically has its own cybersecurity requirements.

Read →
Article 21

When Importers and Distributors Are Treated as Manufacturers

Article 21 closes a potential compliance gap by treating importers and distributors as manufacturers - with the full weight of manufacturer obligations - in two key scenarios: when they place a product on the market under their own name or brand, and when they modify a product in a way that could affect its compliance with CRA requirements. This provision prevents companies from avoiding CRA obligations by acting as intermediaries while substantively behaving as manufacturers.

Read →
Article 24

Obligations of Open-Source Software Stewards Under the CRA

Article 24 introduces the concept of 'open-source software steward' — an entity that provides a platform or support for the ongoing development of open-source software used in products with digital elements, without placing a product on the market itself. Open-source stewards are not manufacturers and are not subject to CE marking or EU Declaration of Conformity obligations. However, they must put a cybersecurity policy in place, publish a vulnerability disclosure process, and cooperate with market surveillance authorities — recognising their structural role in the supply chain.

Read →
Article 25

Security Attestation of Free and Open-Source Software

Article 25 establishes a voluntary security attestation programme for free and open-source software (FOSS). ENISA runs the programme, which enables open-source components to undergo a structured security assessment and receive an attestation certificate. Manufacturers integrating attested FOSS components into their products can reference the attestation as evidence of component due diligence under Article 13. The programme bridges the gap between the CRA's manufacturer obligations and the open-source ecosystem's development model.

Read →
Article 27

Presumption of Conformity, Harmonised Standards, and Common Specifications

Article 27 governs how harmonised European standards and common specifications create a legal presumption of conformity with the CRA's essential cybersecurity requirements. When a manufacturer applies a harmonised standard published in the EU Official Journal, their product is presumed to meet the essential requirements that standard covers. Article 27 also governs the Commission's power to object to harmonised standards that do not adequately cover the essential requirements.

Read →
Article 28

EU Declaration of Conformity: Content, Structure, and Requirements

Article 28 requires manufacturers to draw up an EU Declaration of Conformity (DoC) before placing a product with digital elements on the EU market. The DoC is the formal document in which the manufacturer declares that the product meets all applicable CRA essential requirements. Article 28 specifies exactly what information the DoC must contain, making it a legally binding compliance statement that supports the CE marking.

Read →
Article 30

Rules and Conditions for Affixing the CE Marking

Article 30 is the technical 'how-to' provision for the CE marking under the Cyber Resilience Act. It tells manufacturers where the CE marking must physically appear (on the product, packaging, EU Declaration of Conformity, or accompanying website for software), how visible and legible it must be, when it must be affixed (before the product is placed on the market), and what must follow it (a pictogram, a notified body identification number for Module H assessments, or markings from other applicable Union harmonisation legislation). It also empowers the Commission to specify additional technical labelling rules through implementing acts and obliges Member States to act against improper CE marking use.

Read →
Article 32

Conformity Assessment Procedures: Module A vs Third-Party Assessment

Article 32 decides which conformity assessment procedure applies to a product with digital elements. Default products may use internal control (Module A). Annex III Class I products may use it only where the relevant harmonised standards, common specifications or a qualifying European cybersecurity certification scheme are fully applied; otherwise a third-party route applies. Class II products always require a third party, and Annex IV critical products follow a certification scheme where the Commission has required one. The procedures themselves are set out in Annex VIII.

Read →
Article 35

Notification of Conformity Assessment Bodies to the European Commission

Article 35 establishes the process by which member states notify the European Commission of conformity assessment bodies authorised to perform third-party CRA assessments. Notified bodies are the organisations that conduct mandatory third-party conformity assessments for Class I and Class II products listed in Annex III. Understanding the notified body framework is essential for manufacturers of higher-risk products who require third-party certification rather than self-declaration.

Read →
Article 39

Notification of Conformity Assessment Bodies

Article 39 specifies the requirements that conformity assessment bodies must meet before a member state can notify them to the European Commission for CRA purposes. It establishes the competence, independence, and impartiality criteria that notified bodies must demonstrate, and the ongoing obligations they bear once notified. For manufacturers, understanding Article 39 helps in evaluating whether a potential assessment body genuinely qualifies to conduct CRA conformity assessments.

Read →
Article 4

Free Movement of CRA-Compliant Products in the EU Single Market

Article 4 is the market access provision at the heart of the CRA's regulatory logic: products that satisfy the essential cybersecurity requirements and bear the CE marking are entitled to free movement throughout the EU single market. Member states cannot impose additional national cybersecurity requirements on CE-marked products without specific EU authorisation. This provision benefits manufacturers by creating a single compliance pathway for the entire EU market rather than requiring country-by-country certification.

Read →
Article 5

Procurement and Professional Use of Products with Digital Elements

Article 5 addresses the obligations of organisations that procure or professionally deploy products with digital elements — particularly public sector bodies and operators of critical infrastructure. While most CRA obligations fall on manufacturers, Article 5 ensures that buyers and users of CRA-regulated products also play a role in maintaining cybersecurity, including applying security updates, considering cybersecurity in procurement decisions, and cooperating with manufacturers on security issues.

Read →
Article 52

Market Surveillance Coordination Between EU Member States

Article 52 establishes the framework for coordinating market surveillance activities across EU member states. Because the EU single market means products flow freely across borders, a non-compliant product identified in one member state may be on sale in 26 others. Article 52 ensures national surveillance authorities share information, coordinate investigations, and apply consistent enforcement standards so that manufacturers cannot exploit differences in national enforcement capacity.

Read →
Article 59

Joint Activities of Market Surveillance Authorities

Article 59 establishes the legal framework for national market surveillance authorities (MSAs) to carry out joint activities — principally joint investigations and coordinated enforcement actions — when addressing CRA non-compliance that has cross-border implications. Joint activities allow multiple national authorities to pool investigative resources, share evidence, and issue coordinated corrective measures against manufacturers whose products are sold across more than one EU member state. ENISA can participate in a technical advisory capacity and the Commission can support coordination. Joint activities under Article 59 are a significant escalation tool because their cross-border reach makes them much harder for manufacturers to outmanoeuvre than unilateral national enforcement.

Read →
Article 64

Administrative Fines for CRA Non-Compliance

Article 64 sets out the administrative fine regime for CRA violations. It creates a graduated penalty structure calibrated to the seriousness of the infringement: the most severe fines apply to products that fail the essential cybersecurity requirements or lack vulnerability handling processes; lower tiers apply to other obligation breaches; and a separate tier covers the provision of incorrect or misleading information to authorities. Member state market surveillance authorities apply these fines, subject to national procedural law.

Read →
Article 7

Important Products with Digital Elements - Annex III Classification

Article 7 designates certain products with digital elements as 'important' because their cybersecurity properties are critical to other systems or pose elevated risks. Products listed in Annex III fall into two classes: Class I (significant cybersecurity functions) and Class II (higher-risk products performing critical security roles). Important products face stricter conformity assessment — self-certification alone is not sufficient; Class I requires third-party documentation review and Class II requires full EU-type examination or quality assurance assessment.

Read →
Article 8

Critical Products with Digital Elements - Annex IV Classification

Article 8 designates a narrow category of products with digital elements as 'critical' — those whose compromise could have the most severe systemic impact on cybersecurity. Products listed in Annex IV must use an EU cybersecurity certification scheme under the EUCS (EU Cybersecurity Certification Scheme) for their conformity assessment, rather than the notified body routes available to Annex III products. This makes critical products the only CRA product category linked directly to ENISA's certification framework.

Read →

Deadline · 11 September 2026

Only three of these articles are legally required by September 2026.

EN 18031 §5.3.3.4, §5.3.2.4, §5.4.3.4 — intake channel, triage playbook, paper trail.

See what's required →

Ready to meet your CRA obligations?

CVD Portal provides a complete vulnerability disclosure programme. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market, and Article 14 filing with the SRP-ready package is on Reporting.

Set up your free portal