Skip to main content
Informationssicherheit / NIS2

Cyber Resilience Act

The Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers, importers and distributors to make products with digital elements secure across their entire lifecycle, to handle vulnerabilities and to report actively exploited vulnerabilities.

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. It entered into force on 10 December 2024 and applies in full from 11 December 2027. Where the NIS2 Directive regulates organisations and their risk management, the CRA regulates the product itself: any software or hardware with digital elements placed on the EU single market must meet essential cybersecurity requirements, pass a conformity assessment and carry the CE marking. The CRA is therefore product safety legislation built on the New Legislative Framework, with obligations spread across manufacturers, authorised representatives, importers and distributors along the whole supply chain.

Annex I of the CRA sets out two layers of requirements. Part I concerns the product itself: shipping without known exploitable vulnerabilities, a secure-by-default configuration, protection of confidentiality, integrity and availability, minimised attack surface, access control, logging, and the ability to install security updates. Part II concerns the manufacturer's vulnerability handling processes: a software bill of materials (SBOM) covering at least the top-level dependencies, regular testing, timely and free security updates, a coordinated vulnerability disclosure policy and a contact point for reports. These duties apply throughout the support period, which under Art. 13(8) is generally at least five years, or the expected product lifetime where that is shorter. Compliance is evidenced through technical documentation and an EU declaration of conformity; the route depends on the product class — default products are usually self-assessed, while important products in classes I and II under Annex III and critical products under Annex IV follow stricter procedures involving notified bodies.

The CRA phases in, and the first step with real operational impact is the reporting regime under Art. 14, applicable from 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of the product through the ENISA single reporting platform to the relevant CSIRT and to ENISA — an early warning within 24 hours, a vulnerability or incident notification within 72 hours, and a final report thereafter. The rules on notifying conformity assessment bodies already apply from 11 June 2026. Breaches of the essential requirements can attract fines of up to EUR 15 million or 2.5 percent of worldwide annual turnover under Art. 64. As of August 2026, note that the European Commission is discussing simplification and omnibus initiatives affecting the EU digital rulebook; whether these will change the CRA or its deadlines is still open, so verify the current state in the Official Journal before fixing binding internal milestones.

Legal Basis

Regulation (EU) 2024/2847 (Cyber Resilience Act), in particular Art. 13, Art. 14, Art. 64 and Annexes I, III, IV and VII; complemented by the NIS2 Directive (EU) 2022/2555 and ISO/IEC 27001 as well as ISO/IEC 30111 and 29147

Practical Example

A mid-sized machinery manufacturer ships plant equipment with its own control software and a customer portal. The information security officer first inventories which of these qualify as products with digital elements and whether any fall into an Annex III class — the control software includes a remote maintenance feature, which matters for classification. She then builds three blocks: an automatically generated SBOM per release, a documented vulnerability handling process with fixed timelines for security updates and a public contact point at security@, and a reporting workflow that from September 2026 guarantees the 24-hour early warning to the competent CSIRT and ENISA. In parallel she reviews supplier contracts: wherever third-party components sit inside the product, the contract must oblige the supplier to provide vulnerability information and updates in time, otherwise the company cannot honour its own support period of at least five years.

FAQ

The CRA applies to every economic operator that places or makes available products with digital elements on the EU single market — manufacturers of hardware and software, authorised representatives, importers and distributors, regardless of where the company is established. Products already covered by sector-specific law, such as medical devices, motor vehicles or civil aviation products, are excluded. Pure cloud services fall in scope only where they are remote data processing solutions integral to a product.
The regulation entered into force on 10 December 2024 and applies in full from 11 December 2027. The rules on notifying conformity assessment bodies apply earlier, from 11 June 2026, and above all the Art. 14 reporting obligations apply from 11 September 2026. Because simplification and omnibus initiatives on the EU digital rulebook are under discussion, companies should verify the current position before locking internal milestones.
Both instruments protect the same interest but attach at different points: NIS2 obliges entities to run risk management, report incidents and secure their supply chain, while the CRA obliges manufacturers to ship secure products. In practice they reinforce each other — an entity that must impose security requirements on its suppliers under NIS2 can point to CRA conformity, the SBOM and the declared support period. An ISMS to ISO/IEC 27001 provides the organisational basis for both sets of duties.

How preeco supports you

Learn how our software supports you with this topic.

Learn more