CRA — Cyber Resilience Act

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU's horizontal cybersecurity law for products with digital elements. It applies from 11 December 2027 (the headline date depends on the obligation — see Article 71). This page is the CSOAI measurement surface for CRA compliance.

What the CRA covers

Where AI meets CRA

The CRA does not directly regulate AI. It regulates products with digital elements. AI components embedded in a regulated product (e.g. an AI safety component of a device, or an AI model made available as a separately-marketed component) inherit the CRA obligations. The interaction with the EU AI Act is governed by Reg 2026/1744, which moved the AI Act's high-risk regime into the existing product-safety framework in Annex I Section B.

The single CSOAI view: one gate, not two. A high-risk AI safety component under the AI Act cannot be placed on the market unless the embedded product passes the CRA — and the CRA cannot be met unless the AI component has the AI Act's conformity assessment. We measure against both surfaces and report one combined result.

What CSOAI measures for CRA

Boundary

CSOAI is not a CRA notified body. Where the CRA mandates a third-party conformity assessment for an Annex III product, you need an accredited notified body. We make the evidence layer cheaper and verifiable; the conformity call is the regulator's plus the notified body's. Nothing on this page is legal advice.