Cybersecurity · EU Cyber Resilience Act

Secure by design, and evidenced.

The CRA makes cybersecurity binding for every product with digital elements sold in the EU — secure-by-design, SBOM, vulnerability reporting and CE marking, with fines up to €15M or 2.5% of turnover.

40
days → vulnerability & incident reporting (11 Sep 2026)
496
days → main obligations + CE marking (11 Dec 2027)
Secure by design

Products with digital elements must be designed, developed and produced to be secure — Annex I essential requirements.

Vulnerability handling

Coordinated disclosure, SBOM, and security updates throughout the defined support period.

Incident & vuln reporting

From 11 Sep 2026: report actively-exploited vulns & severe incidents — 24h early warning, 72h notification, via the Single Reporting Platform to your CSIRT and ENISA.

Conformity + CE marking

Conformity assessment, technical documentation and CE marking before placing on the EU market (from 11 Dec 2027).

Frequently asked

What is the EU Cyber Resilience Act (CRA)?

The CRA (Regulation (EU) 2024/2847) sets binding cybersecurity requirements for products with digital elements — hardware and software — sold in the EU: secure-by-design, vulnerability handling, SBOM, CE marking and security updates over a defined support period.

What are the CRA deadlines?

The CRA entered into force on 10 December 2024. Conformity-assessment-body rules apply from 11 June 2026, reporting obligations for actively-exploited vulnerabilities and severe incidents from 11 September 2026, and the main obligations from 11 December 2027.

What must be reported under the CRA and when?

Manufacturers must report actively-exploited vulnerabilities and severe incidents: an early warning within 24 hours, a full notification within 72 hours (via the CRA Single Reporting Platform to their CSIRT and ENISA), and a final report within 14 days of a fix (or one month for severe incidents).

How do the CRA and NIS2 relate?

They complement each other: the CRA secures digital products (hardware/software) placed on the market, while NIS2 secures the networks and systems of essential and important entities. CSOAI crosswalks both to one control set.

How does CSOAI help with CRA compliance?

CSOAI supports SBOM generation (CycloneDX), signed provenance (Sigstore/SLSA), coordinated vulnerability handling and Layer-0 (Ed25519) signed evidence of secure-by-design and reporting — reproducible for conformity assessment.

Dates verified July 2026. Indicative guidance, not legal advice — verify against primary EU sources.