EU Cyber Resilience Act (CRA) · Regulation (EU) 2024/2847

Turn CRA requirements into a working product-security process.

The EU Cyber Resilience Act introduces binding cybersecurity requirements for products with digital elements throughout their lifecycle. It can also affect companies based outside Europe when their products are made available on the EU market. Prepare product, engineering, PSIRT, support, compliance and management teams before the reporting obligations and full application dates arrive.

In force10 Dec 2024

The CRA is EU law.

Reporting11 Sep 2026

Article 14 reporting obligations apply.

Full application11 Dec 2027

The main CRA obligations apply.

LifecycleSecurity and support

From design through vulnerability handling.

Who should assess CRA scope?

The CRA generally concerns hardware and software products with digital elements made available on the EU market. The place of incorporation or development is not the only deciding factor: international vendors can be in scope when serving EU customers.

Manufacturers serving the EU

Own core product requirements, cybersecurity risk assessment, technical documentation, conformity assessment, CE marking and vulnerability handling.

Importers and distributors

Must verify relevant conformity information and act when they know or have reason to believe that a product is not compliant.

Product, engineering and PSIRT

Engineering, product management, PSIRT, support, procurement, legal, compliance and leadership need coordinated responsibilities and defensible evidence.

Six CRA readiness areas.

  • Scope and role: map products, components, economic operators, exceptions and regulatory overlaps.
  • Secure product development: translate Annex I requirements into design, development, production and release controls.
  • Cybersecurity risk assessment: document risks, security assumptions, intended use and proportionate measures.
  • Vulnerability handling: maintain intake, triage, remediation, coordinated disclosure, updates and support-period processes.
  • Reporting: prepare 24-hour early warning, 72-hour notification and final-report workflows for reportable cases.
  • Conformity evidence: align technical documentation, user information, conformity assessment and CE-marking decisions.

Reporting starts before full application.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security through the CRA Single Reporting Platform.

Processes should support an early warning within 24 hours, the main notification within 72 hours and the applicable final report. Classification, escalation, evidence preservation and communication therefore need to work before an incident occurs.

Where Paragamix can support.

CRA implementation is not only a technical-documentation project. International teams need to recognize their role and make consistent, defensible decisions across product, engineering, security, support and compliance.

Role-based awareness

Short learning formats for product management, engineering, PSIRT, support, procurement, sales, compliance and leadership.

Process exercises

Guided scenarios for vulnerability intake, escalation, secure release decisions, incident reporting, customer communication and recovery.

Documentation aids

Practical templates for responsibilities, awareness evidence and internal workflows that complement the technical compliance file.

Clear boundary.

Paragamix awareness and process support does not constitute legal advice, product certification, a notified-body conformity assessment or confirmation of CRA compliance. Product scope and conformity decisions should be validated by the responsible legal and technical specialists.

Official sources and status.

Status: 27 July 2026. Use the official text and current European Commission implementation guidance for decisions.

Frequently asked questions.

Does the CRA apply only to products developed in the EU?

No. The relevant question is generally whether a covered product with digital elements is made available on the EU market, not only where it was developed.

Is a cloud service automatically a CRA product?

Not necessarily. The CRA focuses on products with digital elements and certain remote data-processing solutions related to a product. Stand-alone services and overlaps with other EU rules require a specific assessment.

Is awareness sufficient for CRA compliance?

No. Awareness supports implementation. The manufacturer still needs product-security controls, risk assessment, vulnerability handling, technical documentation, conformity assessment and other applicable obligations.

Start with roles, products and reporting paths.

A focused CRA readiness session can identify the teams, products and workflows that need attention before September 2026 and December 2027.