Cyber Resilience Act: does it apply to your product?
The Cyber Resilience Act sets cybersecurity requirements for hardware and software products sold in the EU. Its reporting duties apply from 11 September 2026; the rest from 11 December 2027.
Checked against the sources on 7 October 2026
Which CRA class is your product in?
Pick the category that matches what the product itself mainly does, not one of its components.
Choose a category to see its class and the conformity assessment routes open to it.
Annexes III and IV and Articles 7, 8 and 32 of Regulation (EU) 2024/2847; technical descriptions in Implementing Regulation (EU) 2025/2392. Checked on 7 October 2026.
Technical file and notified-body readiness
Tick what you already have to see the gaps, with the Annex reference for each. The technical file is needed on every route; a notified body also asks for the application items below.
0 of 13 ready
Still missing:
- General description: intended purpose, software versions affecting compliance, photos or illustrations for hardware, and the user information of Annex II (Annex VII(1))
- Design and development information, including drawings and the system architecture where applicable (Annex VII(2)(a))
- Vulnerability handling: software bill of materials, coordinated vulnerability disclosure policy, contact address for reporting vulnerabilities, and how updates are distributed securely (Annex VII(2)(b))
- Production and monitoring processes and how they are validated (Annex VII(2)(c))
- Cybersecurity risk assessment (Article 13), showing how each essential requirement of Annex I Part I applies (Annex VII(3))
- The information used to set the support period (Article 13(8)) (Annex VII(4))
- Harmonised standards, common specifications or certification schemes applied, in full or in part, or the solutions used instead (Annex VII(5))
- Reports of the tests that verify conformity of the product and of the vulnerability handling processes (Annex VII(6))
- A copy of the EU declaration of conformity (Annex VII(7))
- Name and address of the manufacturer, and of the authorised representative if it applies (Annex VIII, Part II, 3.1)
- Written declaration that the same application has not been lodged with another notified body (Annex VIII, Part II, 3.2)
- Supporting evidence for the design and vulnerability handling solutions, including test results where necessary (Annex VIII, Part II, 3.4)
- Specimens of one or more critical parts of the product for the body to examine (Annex VIII, Part II, 2)
From Annex VII and Annex VIII of Regulation (EU) 2024/2847. The obligations apply from 11 December 2027; notified bodies can be designated from 11 June 2026 (Article 71(2)). A notified body may ask for more.
Which products
Products with digital elements: hardware and software products, including their remote data processing, whose intended or reasonably foreseeable use includes a data connection to a device or network. Smart home devices, routers, apps, connected toys and many industrial components are typical examples.
What is excluded
Products already covered by sector cybersecurity rules: medical devices and in vitro diagnostics, motor vehicles, civil aviation and marine equipment. Products developed only for national security or defence are also outside, as is free and open-source software not supplied in the course of a commercial activity.
Dates
| Date | What applies |
|---|---|
| 11 June 2026 | Rules for conformity assessment bodies. |
| 11 September 2026 | Manufacturers report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report. |
| 11 December 2027 | All other requirements: secure design, vulnerability handling, conformity assessment, CE marking, technical documentation. |
The reporting duty in detail: deadlines, the Single Reporting Platform and which CSIRT to use. See CRA reporting.
What it asks of manufacturers
- meet essential cybersecurity requirements in design and production;
- handle vulnerabilities for a support period, generally at least five years;
- a conformity assessment: self-assessment for most products; for important and critical products, harmonised standards or a third-party body;
- technical documentation, an EU declaration of conformity and the CE marking.
Connected consumer products are often under the GPSR as well. Check that with the GPSR check.