Explore Cenitia’s compliance workflow and availability.Cenitia compliance workflow

How it works →
Cenitia
How it worksServicesLibraryGlossaryRegulationsToolsAbout
Reserve your spot
How it worksServicesLibraryGlossaryRegulationsToolsAbout
← Regulations

EU Regulation · CRA

Cyber Resilience Act

Regulation (EU) 2024/2847

The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements across their whole lifecycle — from secure design and a Software Bill of Materials to vulnerability handling and incident reporting.

What it covers

Products with digital elements whose intended or foreseeable use includes direct/indirect data connections, subject to statutory exclusions including MDR/IVDR.

How it applies to your product

In practice the CRA means a connected product needs secure-by-default configuration, a documented vulnerability-handling process, and a Software Bill of Materials — and the manufacturer must report actively exploited vulnerabilities and severe incidents through the EU single reporting platform to the relevant national CSIRT (with ENISA notified in parallel) within tight deadlines. It applies on top of a product’s other CE-marking obligations, not instead of them.

Key dates

Applies in full from 11 December 2027; the vulnerability and incident reporting obligations apply earlier, from 11 September 2026.

Authoritative source

Always confirm against the primary text on EUR-Lex — the official EU legal database.

Read Regulation (EU) 2024/2847 on EUR-Lex ↗

See also the CRA entry in the glossary.

Guides on CRA

From the Library

  • tutorial

    Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers

    Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.

  • reference

    Official Journal monitoring for hardware compliance — a quarterly review workflow

    A practical workflow for tracking EU product legislation, OJ standards citations, restrictions and transition dates, with a review record for each affected product.

  • guide

    CRA readiness countdown — scope, reporting, assessment and release checkpoints

    Planning checkpoints before CRA main product obligations apply on 11 December 2027, with reporting already in force, class-specific routes and release evidence.

  • reference

    CRA harmonised standards — citation and assessment checks

    How to check the role of harmonised standards in CRA assessment: exact citation, requirement coverage, route conditions and evidence. This is not a live OJ ledger.

  • tutorial

    How to check NANDO for Notified Bodies

    Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.

  • guide

    CE marking AI-enabled hardware — CRA + AI Act overlap

    A scope overview for AI-enabled hardware: updated high-risk application dates, category-specific assessment, and evidence needed alongside product legislation.

Check your product

Free tools

  • EU Directive Selector →
  • CRA Readiness Checker →
  • Do I need a Notified Body? →
Cenitia

The EU compliance engine for hardware manufacturers. Cited drafts, electronic signing, regulation watching — all in one place.

A product of Inovasense s.r.o., Bratislava, Slovakia · Data hosted in Stockholm, EU

Site

  • How it works
  • Expert services & pricing
  • Library
  • Glossary
  • Regulations
  • By product type
  • Tools
  • About

Legal

  • Imprint
  • Privacy
  • Terms

© 2026 Inovasense s.r.o. · cenitia.com

Operated in Slovakia · Evidence, expert review and clear service scope