Cenitia launchesLaunching September 2026 — first 250 founders get the launch price locked for life.

Reserve your spot →
Cenitia
How it worksLibraryGlossaryRegulationsToolsAbout
Reserve your spot
How it worksLibraryGlossaryRegulationsToolsAbout
← Regulations

EU Regulation · CRA

Cyber Resilience Act

Regulation (EU) 2024/2847

The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements across their whole lifecycle — from secure design and a Software Bill of Materials to vulnerability handling and incident reporting.

What it covers

Any product with digital elements that connects to a network or runs software, placed on the EU market.

How it applies to your product

In practice the CRA means a connected product needs secure-by-default configuration, a documented vulnerability-handling process, and a Software Bill of Materials — and the manufacturer must report actively exploited vulnerabilities and severe incidents through the EU single reporting platform to the relevant national CSIRT (with ENISA notified in parallel) within tight deadlines. It applies on top of a product’s other CE-marking obligations, not instead of them.

Key dates

Applies in full from 11 December 2027; the vulnerability and incident reporting obligations apply earlier, from 11 September 2026.

Authoritative source

Always confirm against the primary text on EUR-Lex — the official EU legal database.

Read Regulation (EU) 2024/2847 on EUR-Lex ↗

See also the CRA entry in the glossary.

Guides on CRA

From the Library

  • guide

    CE marking AI-enabled hardware — CRA + AI Act overlap

    How CE marking works for hardware embedding AI under the AI Act (Regulation (EU) 2024/1689) and the CRA — Article 6 high-risk routing, Article 48 CE, Annex I integration.

  • guide

    CE marking for industrial sensors and gateways

    EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.

  • guide

    CE marking medical wearables — MDR + CRA overlap

    How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.

  • guide

    CE marking for IoT consumer products — end-to-end

    End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.

  • reference

    IEC 62443 family overview for product manufacturers

    Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.

  • guide

    EC REP cost guide 2026: what you pay, what you get, what to avoid

    Cost guide for EU Authorised Representative services in 2026 by directive — CRA Article 18, RED Article 11, MDR Article 11 — what drives premium and how to verify a quote.

Check your product

Free tools

  • EU Directive Selector →
  • CRA Readiness Checker →
  • Do I need a Notified Body? →
Cenitia

The EU compliance engine for hardware manufacturers. Cited drafts, electronic signing, regulation watching — all in one place.

A product of Inovasense s.r.o., Bratislava, Slovakia · Data hosted in Stockholm, EU

Site

  • How it works
  • Library
  • Glossary
  • Regulations
  • By product type
  • Tools
  • About

Legal

  • Imprint
  • Privacy
  • Terms

© 2026 Inovasense s.r.o. · cenitia.com

EU sovereign · EU data residency by design · Customer data never trains models