Skip to content
EU Rules Finder
English (Language)

Cyber Resilience Act: does it apply to your product?

The Cyber Resilience Act sets cybersecurity requirements for hardware and software products sold in the EU. Its reporting duties apply from 11 September 2026; the rest from 11 December 2027.

Checked against the sources on 7 October 2026

Which CRA class is your product in?

Pick the category that matches what the product itself mainly does, not one of its components.

Choose a category to see its class and the conformity assessment routes open to it.

Annexes III and IV and Articles 7, 8 and 32 of Regulation (EU) 2024/2847; technical descriptions in Implementing Regulation (EU) 2025/2392. Checked on 7 October 2026.

Technical file and notified-body readiness

Tick what you already have to see the gaps, with the Annex reference for each. The technical file is needed on every route; a notified body also asks for the application items below.

Which conformity assessment route will you use?
Technical documentation (Annex VII)
Application to the notified body (Annex VIII)

0 of 13 ready

Still missing:

  • General description: intended purpose, software versions affecting compliance, photos or illustrations for hardware, and the user information of Annex II (Annex VII(1))
  • Design and development information, including drawings and the system architecture where applicable (Annex VII(2)(a))
  • Vulnerability handling: software bill of materials, coordinated vulnerability disclosure policy, contact address for reporting vulnerabilities, and how updates are distributed securely (Annex VII(2)(b))
  • Production and monitoring processes and how they are validated (Annex VII(2)(c))
  • Cybersecurity risk assessment (Article 13), showing how each essential requirement of Annex I Part I applies (Annex VII(3))
  • The information used to set the support period (Article 13(8)) (Annex VII(4))
  • Harmonised standards, common specifications or certification schemes applied, in full or in part, or the solutions used instead (Annex VII(5))
  • Reports of the tests that verify conformity of the product and of the vulnerability handling processes (Annex VII(6))
  • A copy of the EU declaration of conformity (Annex VII(7))
  • Name and address of the manufacturer, and of the authorised representative if it applies (Annex VIII, Part II, 3.1)
  • Written declaration that the same application has not been lodged with another notified body (Annex VIII, Part II, 3.2)
  • Supporting evidence for the design and vulnerability handling solutions, including test results where necessary (Annex VIII, Part II, 3.4)
  • Specimens of one or more critical parts of the product for the body to examine (Annex VIII, Part II, 2)

From Annex VII and Annex VIII of Regulation (EU) 2024/2847. The obligations apply from 11 December 2027; notified bodies can be designated from 11 June 2026 (Article 71(2)). A notified body may ask for more.

Which products

Products with digital elements: hardware and software products, including their remote data processing, whose intended or reasonably foreseeable use includes a data connection to a device or network. Smart home devices, routers, apps, connected toys and many industrial components are typical examples.

What is excluded

Products already covered by sector cybersecurity rules: medical devices and in vitro diagnostics, motor vehicles, civil aviation and marine equipment. Products developed only for national security or defence are also outside, as is free and open-source software not supplied in the course of a commercial activity.

Dates

DateWhat applies
11 June 2026Rules for conformity assessment bodies.
11 September 2026Manufacturers report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report.
11 December 2027All other requirements: secure design, vulnerability handling, conformity assessment, CE marking, technical documentation.

The reporting duty in detail: deadlines, the Single Reporting Platform and which CSIRT to use. See CRA reporting.

What it asks of manufacturers

  • meet essential cybersecurity requirements in design and production;
  • handle vulnerabilities for a support period, generally at least five years;
  • a conformity assessment: self-assessment for most products; for important and critical products, harmonised standards or a third-party body;
  • technical documentation, an EU declaration of conformity and the CE marking.

Connected consumer products are often under the GPSR as well. Check that with the GPSR check.