Cyber Resilience Act guides for manufacturers

What the reporting duty already requires, what lands on 11 December 2027, and how products with digital elements are classified.

The Cyber Resilience Act at a glance

The Cyber Resilience Act is Regulation (EU) 2024/2847, in force since 10 December 2024, and it arrives in two steps. Since 11 September 2026 the Article 14 reporting duty has applied: an actively exploited vulnerability or a severe security incident must be reported through ENISA's single reporting platform within 24 hours, with a fuller notification at 72 hours. That duty also covers products already on the market, including ones shipped years ago. Everything else starts on 11 December 2027: the Annex I essential requirements, conformity assessment, CE marking under the CRA, and a support period of at least five years. Scope is wide, covering hardware and software whose intended use includes a direct or indirect data connection to a device or network. If you already sell connected products in the EU, the first job is a reporting process that can meet the 24-hour deadline.

Read the Commission's Cyber Resilience Act guidance

Need to know if the CRA reaches your product?

A product compliance assessment tells you whether the CRA applies, which class your product falls into, and what has to be ready before 11 December 2027, at a fixed €399.

Book a call with our compliance teamBook an assessmentBrowse all compliance resources