The Cyber Resilience Act: what it asks of a product list
Regulation (EU) 2024/2847 binds products with digital elements made available on the EU market. Article 14 (reporting actively exploited vulnerabilities and severe incidents) applies from 11 September 2026, including to products placed on the market before 11 December 2027; Chapter IV (notified bodies) from 11 June 2026; the rest from 11 December 2027 (Art. 71(2), Art. 69(3)). A product's class follows the core function it has: Annex III (important, class I and II), Annex IV (critical), otherwise default.
Read from the held text: Article 71(2) sets the dates, Article 69(3) brings products placed on the market before 11 December 2027 under the reporting duty, Article 69(2) subjects them otherwise only on a substantial modification, and Article 2 takes out medical devices, in vitro diagnostics, vehicle systems under type approval, certificate-holding aviation equipment, marine equipment, identical spare parts and products made exclusively for national security or defence. Named, not quoted, beside it: Commission Implementing Regulation (EU) 2025/2392, the technical descriptions of the Annex III and IV categories; harmonised standards under the Cyber Resilience Act.
Duties by role
| Role | Clauses |
|---|---|
| manufacturer | CRA Art. 6 Condition for making a product available on the market CRA Art. 13(1) Design, development and production to Annex I Part I CRA Art. 13(2) Cybersecurity risk assessment used across the product lifecycle CRA Art. 13(8) first subparagraph Effective vulnerability handling for the support period CRA Art. 13(8) third subparagraph Minimum support period of five years CRA Art. 13(12) second subparagraph Carrying out the conformity assessment procedure CRA Art. 13(12) third subparagraph EU declaration of conformity and CE marking after demonstrated conformity CRA Art. 13(17) Single point of contact for users CRA Art. 13(19) End date of the support period stated at purchase, and end-of-support notice CRA Art. 14(1) Notifying actively exploited vulnerabilities to the CSIRT and ENISA CRA Art. 14(3) Notifying severe incidents affecting product security CRA Annex I Part I(1) Appropriate level of cybersecurity based on the risks CRA Annex I Part II(1) Identify and document vulnerabilities and components, including an SBOM CRA Annex I Part II(5) Coordinated vulnerability disclosure policy CRA Art. 31(1) Content of the technical documentation CRA Art. 28(1)-(2) Drawing up and maintaining the EU declaration of conformity CRA Art. 30(1)-(2) Affixing the CE marking |
| importer | CRA Art. 6 Condition for making a product available on the market CRA Art. 19(1) Importers place only conforming products on the market CRA Art. 19(2) Importer checks before placing on the market CRA Art. 19(6) Importer retention of the declaration and access to technical documentation |
| distributor | CRA Art. 6 Condition for making a product available on the market CRA Art. 20(1) Distributors act with due care CRA Art. 20(2) Distributor verification before making available |
| own brand (becomes the manufacturer) | CRA Art. 21 Importers and distributors who become manufacturers CRA Art. 13(1) Design, development and production to Annex I Part I CRA Art. 13(8) first subparagraph Effective vulnerability handling for the support period CRA Art. 13(8) third subparagraph Minimum support period of five years CRA Art. 14(1) Notifying actively exploited vulnerabilities to the CSIRT and ENISA CRA Art. 14(3) Notifying severe incidents affecting product security CRA Annex I Part II(1) Identify and document vulnerabilities and components, including an SBOM CRA Art. 28(1)-(2) Drawing up and maintaining the EU declaration of conformity CRA Art. 30(1)-(2) Affixing the CE marking |
Notes that cite it
CRA: every clause cited
51 of the 140 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
CRA Annex I Part I(1)Appropriate level of cybersecurity based on the risksProducts must be designed, developed and produced so that they ensure a level of cybersecurity appropriate to the risks identified.
CRA Annex I Part I(2)(b)Secure by default configuration with reset to original stateThe product must ship with a secure by default configuration, unless otherwise agreed with a business user for a tailor-made product, and must allow the product to be reset to its original state.
CRA Annex I Part I(2)(c)Vulnerabilities addressable through security updates, automatic by defaultThe product must allow vulnerabilities to be addressed through security updates, including, where applicable, automatic security updates installed within an appropriate time and enabled by default with a clear, easy opt-out, notification to users of available updates, and the option to postpone them temporarily.
CRA Annex I Part I(2)(d)Protection from unauthorised access and reporting of itThe product must protect against unauthorised access through appropriate control mechanisms, including authentication, identity or access management systems, and report on possible unauthorised access.
CRA Annex I Part I(2)(f)Integrity of data, commands, programs and configurationThe product must protect the integrity of stored, transmitted or processed data, commands, programs and configuration against manipulation or modification the user has not authorised, and report on corruptions.
CRA Annex I Part II(1)Identify and document vulnerabilities and components, including an SBOMManufacturers must identify and document the vulnerabilities and components in the product, including by drawing up a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies.
CRA Annex I Part II(2)Address and remediate vulnerabilities without delay, security updates separate from featuresManufacturers must address and remediate vulnerabilities without delay in relation to the risks, including by providing security updates, and where technically feasible must provide new security updates separately from functionality updates.
CRA Annex I Part II(5)Coordinated vulnerability disclosure policyManufacturers must put in place and enforce a policy on coordinated vulnerability disclosure.
CRA Annex I Part II(6)Facilitating vulnerability information sharing, with a contact addressManufacturers must take measures to facilitate sharing of information on potential vulnerabilities in the product and its third-party components, including providing a contact address for reporting vulnerabilities.
CRA Annex I Part II(7)Secure distribution of updatesManufacturers must provide mechanisms to distribute updates securely so vulnerabilities are fixed or mitigated in time and, where applicable for security updates, automatically.
CRA Annex I Part II(8)Dissemination of security updates without delay and free of charge, with advisoriesWhere security updates are available for identified issues, manufacturers must disseminate them without delay and, unless otherwise agreed with a business user for a tailor-made product, free of charge, with advisory messages giving users relevant information, including action they may need to take.
CRA Annex II 2User information: vulnerability contact point and CVD policy locationIt must give the single point of contact where vulnerability information can be reported and received, and where the manufacturer's coordinated vulnerability disclosure policy can be found.
CRA Annex II 7User information: type of support and end date of the support periodIt must state the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be received.
CRA Annex VII 4Technical file: information used to set the support periodIt must contain the relevant information taken into account to determine the support period under Article 13(8).
CRA Annex VIII Part IModule A: internal controlUnder internal control the manufacturer draws up the Annex VII technical documentation, takes all measures so that design, development, production and vulnerability handling and their monitoring ensure compliance with Annex I Parts I and II, affixes the CE marking to each conforming product, and draws up the declaration, keeping it with the technical documentation for ten years or the support period if longer. The authorised representative may handle marking and declaration under mandate.
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer dutiesFor EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.
CRA Art. 6Condition for making a product available on the marketA product with digital elements may be made available on the Union market only if, when properly installed, maintained and used as intended or under reasonably foreseeable conditions and with the necessary security updates applied, it meets the Part I essential cybersecurity requirements of Annex I, and only if the processes the manufacturer runs meet the Part II vulnerability handling requirements.
CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.
CRA Art. 8(1)Critical products and European cybersecurity certificationFor products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.
CRA Art. 13(1)Design, development and production to Annex I Part IWhen placing a product on the market the manufacturer must be able to show that it was designed, developed and produced in line with the essential cybersecurity requirements in Part I of Annex I.
CRA Art. 13(2)Cybersecurity risk assessment used across the product lifecycleThe manufacturer must assess the cybersecurity risks of the product and feed the outcome into planning, design, development, production, delivery and maintenance, aiming to minimise risk, prevent incidents and reduce their impact, including on users' health and safety.
CRA Art. 13(8) first subparagraphEffective vulnerability handling for the support periodFrom placing on the market and throughout the support period, the manufacturer must make sure that vulnerabilities in the product and its components are handled effectively and in line with the Part II requirements of Annex I.
CRA Art. 13(8) second subparagraphDetermining the support periodThe manufacturer sets the support period to reflect how long the product is expected to be in use, weighing reasonable user expectations, the nature and intended purpose of the product and relevant Union law on product lifetime. It may also weigh comparable products' support periods, the availability of the operating environment, support periods of key third-party components, and ADCO and Commission guidance. The information used must be recorded in the technical documentation (Annex VII point 4).
CRA Art. 13(8) sixth subparagraphPolicies and procedures for reported vulnerabilities, including coordinated disclosureThe manufacturer must have appropriate policies and procedures, coordinated vulnerability disclosure policies among them, to process and remediate potential vulnerabilities reported from inside or outside the organisation.
CRA Art. 13(8) third subparagraphMinimum support period of five yearsThe support period must be at least five years, unless the product is expected to be in use for less than five years, in which case it matches the expected use time. The Commission may set minimum support periods for specific product categories by delegated act where market surveillance data shows periods are inadequate.
CRA Art. 13(9)Security updates kept available for ten yearsEach security update issued to users during the support period must remain available for at least ten years after issue, or for the rest of the support period if that is longer.
CRA Art. 13(12) second subparagraphCarrying out the conformity assessment procedureThe manufacturer must carry out, or have carried out, the conformity assessment procedure it has chosen from those in Article 32 for the product's class.
CRA Art. 13(12) third subparagraphEU declaration of conformity and CE marking after demonstrated conformityOnce the conformity assessment has shown that the product meets Annex I Part I and the manufacturer's processes meet Part II, the manufacturer must draw up the EU declaration of conformity under Article 28 and affix the CE marking under Article 30.
CRA Art. 13(17)Single point of contact for usersThe manufacturer must designate a single point of contact through which users can communicate directly and quickly, including to report vulnerabilities. It must be easy to identify, appear in the Annex II information, let users choose their preferred means of communication and not be limited to automated tools.
CRA Art. 13(19)End date of the support period stated at purchase, and end-of-support noticeThe end date of the support period, at least month and year, must be stated clearly at the time of purchase in an easily accessible way and, where applicable, on the product, packaging or by digital means. Where technically feasible, users must be shown a notification when the product reaches the end of its support period.
CRA Art. 14(1)Notifying actively exploited vulnerabilities to the CSIRT and ENISAA manufacturer that becomes aware of an actively exploited vulnerability in its product must notify it at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16. Applies from 11 September 2026, including to products placed on the market before 11 December 2027 (Article 69(3)).
CRA Art. 14(2)(a)Early warning within 24 hours of awareness of an exploited vulnerabilityAn early warning of the actively exploited vulnerability must go in without undue delay and within 24 hours of the manufacturer becoming aware of it, naming, where applicable, the Member States where the manufacturer knows the product has been made available.
CRA Art. 14(2)(b)Vulnerability notification within 72 hoursUnless already provided, a vulnerability notification must follow without undue delay and within 72 hours of awareness, giving available general information on the product, the general nature of the exploit and vulnerability, corrective or mitigating measures taken and those users can take, and, where applicable, how sensitive the manufacturer considers the information.
CRA Art. 14(3)Notifying severe incidents affecting product securityA manufacturer that becomes aware of a severe incident with an impact on the security of its product must notify it at the same time to the coordinating CSIRT and ENISA via the single reporting platform. An incident is severe where it harms or can harm the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or run in the product or in users' systems (Article 14(5)).
CRA Art. 14(8)Informing impacted users of exploited vulnerabilities and severe incidentsAfter becoming aware of an actively exploited vulnerability or severe incident, the manufacturer must inform impacted users, and all users where appropriate, and where needed tell them of risk mitigation and corrective measures they can deploy, where appropriate in a structured, machine-readable format. If the manufacturer does not inform users in time, the notified CSIRTs may do so.
CRA Art. 18(1)-(2)Written mandate for an authorised representative, and what it cannot coverA manufacturer may appoint an authorised representative by written mandate. The mandate cannot include the Article 13(1) to (11) duties, the drawing up of technical documentation in 13(12) first subparagraph, or the series production duty in 13(14); those stay with the manufacturer.
CRA Art. 18(3)Tasks of the authorised representativeThe authorised representative performs the mandated tasks and gives the mandate to authorities on request. The mandate must at least let it keep the declaration and technical documentation available for ten years or the support period if longer, provide authorities with conformity information on a reasoned request, and cooperate with them on risk elimination.
CRA Art. 19(1)Importers place only conforming products on the marketImporters may place on the market only products that meet Annex I Part I and whose manufacturer's processes meet Annex I Part II.
CRA Art. 19(2)Importer checks before placing on the marketBefore placing the product, the importer must ensure the manufacturer carried out the right conformity assessment, drew up the technical documentation, applied the CE marking, supplied the EU declaration and the Annex II information in an understandable language, and met the identification, contact and support-end-date duties of Article 13(15), (16) and (19). The importer must be able to produce documents proving these checks.
CRA Art. 19(6)Importer retention of the declaration and access to technical documentationFor ten years after placing on the market or the support period if longer, importers must keep a copy of the EU declaration available to authorities and ensure the technical documentation can be made available on request.
CRA Art. 20(1)Distributors act with due careWhen making a product available, distributors must act with due care in relation to the Regulation's requirements.
CRA Art. 20(2)Distributor verification before making availableBefore making the product available, distributors must verify that it bears the CE marking and that the manufacturer and importer have met the identification, contact, user information, support end date and declaration duties of Article 13(15), (16), (18), (19) and (20) and Article 19(4), and supplied the necessary documents.
CRA Art. 21Importers and distributors who become manufacturersAn importer or distributor is treated as the manufacturer, and takes on Articles 13 and 14, where it places a product on the market under its own name or trademark or carries out a substantial modification of a product already on the market.
CRA Art. 28(1)-(2)Drawing up and maintaining the EU declaration of conformityThe manufacturer draws up the EU declaration of conformity stating that the applicable Annex I requirements have been shown to be met. It follows the Annex V model structure, contains the elements required by the Annex VIII procedure used, is updated as appropriate and is provided in the languages required by each Member State where the product is placed or made available. A simplified declaration follows Annex VI. By drawing up the declaration the manufacturer takes responsibility for compliance.
CRA Art. 30(1)-(2)Affixing the CE markingThe CE marking, subject to the general principles of Article 30 of Regulation (EC) No 765/2008, must be affixed visibly, legibly and indelibly to the product; where the product's nature does not allow it, to the packaging and the accompanying declaration. For software, it goes on the declaration or on the accompanying website, in a section directly accessible to consumers. It may be smaller than 5 mm if still visible and legible.
CRA Art. 31(1)Content of the technical documentationThe technical documentation must contain all relevant data or details of the means used to make the product and the manufacturer's processes meet Annex I, and at least the elements of Annex VII.
CRA Art. 31(2)Technical documentation kept current through the support periodThe technical documentation is drawn up before placing on the market and updated continuously, where appropriate, at least through the support period.
CRA Art. 32(1)Choosing a conformity assessment procedure (default products)The manufacturer must assess the product and its processes against Annex I and demonstrate conformity by one of: internal control (module A), EU-type examination (module B) followed by conformity to type (module C), full quality assurance (module H), or, where available, a European cybersecurity certification scheme under Article 27(9).
CRA Art. 32(2)Conformity assessment for important class I productsFor an Annex III class I product, internal control is available only where the manufacturer has applied in full harmonised standards, common specifications or a certification scheme at assurance level at least substantial. Where it has applied them in part, not at all, or none exist, the product and processes must go, for the uncovered requirements, through module B plus C or module H.
CRA Art. 32(3)Conformity assessment for important class II productsFor an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.
CRA Art. 32(4)Conformity assessment for critical productsA critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.