EU Regulation 2024/2847

    Updated: 24 February 2026

    Security,
    by Law

    Cyber Resilience Act (CRA) Compliance Guide

    The Cyber Resilience Act establishes mandatory cybersecurity requirements for all products with digital elements placed on the EU market. Vulnerability reporting obligations activate on 11 September 2026 - including for legacy products already on the market.

    11 Sep 2026

    Reporting obligations

    11 Dec 2026

    Notified bodies required

    11 Dec 2027

    Full compliance

    Key Articles - Reporting and Manufacturer Obligations

    The following articles establish the core obligations for manufacturers of products with digital elements. These represent the highest-priority compliance areas before the September 2026 reporting deadline.

    Article 13: Obligations of Manufacturers - Vulnerability & Incident Reporting

    Full text

    Establishes the core obligation for manufacturers to actively monitor for vulnerabilities, report actively exploited vulnerabilities and severe incidents, and maintain a coordinated vulnerability disclosure process throughout the product lifecycle.

    Key Requirements

    • Report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware
    • Provide intermediate notification within 72 hours with initial impact assessment
    • Submit comprehensive final report within 14 days describing the vulnerability, affected versions, and remediation
    • Maintain a coordinated vulnerability disclosure policy (CVD) accessible to security researchers
    • Cooperate with competent authorities and market surveillance authorities on request
    • Apply to products already on the market from 11 September 2026

    Article 14: Notification of Incidents and Actively Exploited Vulnerabilities

    Full text

    Defines what constitutes a notifiable incident and an actively exploited vulnerability, and establishes the reporting chain via the EU single reporting platform operated by ENISA.

    Key Requirements

    • Early warning (24hr): notification that an actively exploited vulnerability or severe incident has occurred
    • Intermediate notification (72hr): updated information including initial assessment of impact and severity
    • Final report (14 days): complete vulnerability description, affected products, remediation steps taken
    • Reports submitted via the EU single reporting platform (ENISA-operated)
    • ENISA distributes notifications to relevant national cybersecurity authorities and CSIRTs
    • Severe incidents defined as those with significant impact on service provision or data security

    Article 20: Conformity Assessment

    Full text

    Sets out how manufacturers must demonstrate compliance with the essential cybersecurity requirements in Annex I, including self-assessment for default-category products and third-party assessment for Class I and II products.

    Key Requirements

    • Default category: manufacturer self-assessment against Annex I requirements
    • Class I products: third-party conformity assessment or use of harmonised standards
    • Class II products: assessment by EU notified body mandatory
    • EU Declaration of Conformity must be prepared and kept for 10 years
    • CE marking affixed to product once conformity is demonstrated
    • Technical documentation must be maintained for inspection by market surveillance authorities

    Article 24: Obligations of Manufacturers - Lifecycle Requirements

    Full text

    Requires manufacturers to provide security support for the expected product lifetime or a minimum of five years, whichever is shorter - including free security updates and coordinated vulnerability handling.

    Key Requirements

    • Provide security updates for the expected product lifetime or minimum 5 years
    • Security updates must be delivered separately from feature updates where possible
    • Users must be informed about available security updates promptly
    • Maintain Software Bill of Materials (SBOM) in machine-readable format
    • Document and address vulnerabilities in third-party components (supply chain)
    • Notify affected users of end-of-support date at least 12 months in advance