The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU's
horizontal cybersecurity law for products with digital elements. It applies from
11 December 2027 (the headline date depends on the obligation — see
Article 71). This page is the CSOAI measurement surface for CRA compliance.
What the CRA covers
Products with digital elements — any connected device, software, or embedded system placed on the EU market, with limited exceptions (medical devices, automotive, aviation, etc., which are covered by sectoral law).
Conformity routes — self-assessment for most products; third-party assessment (via notified body) for critical-product categories enumerated in Annex III.
Post-market — vulnerability disclosure obligations, secure update channels for the support period of the product.
Where AI meets CRA
The CRA does not directly regulate AI. It regulates products with digital elements.
AI components embedded in a regulated product (e.g. an AI safety component of a
device, or an AI model made available as a separately-marketed component) inherit
the CRA obligations. The interaction with the EU AI Act is governed by
Reg 2026/1744, which moved the AI Act's high-risk regime into the
existing product-safety framework in Annex I Section B.
The single CSOAI view: one gate, not two. A high-risk AI safety component
under the AI Act cannot be placed on the market unless the embedded product passes
the CRA — and the CRA cannot be met unless the AI component has the AI Act's
conformity assessment. We measure against both surfaces and report one combined
result.
What CSOAI measures for CRA
Vulnerability disclosure — does the vendor publish a vulnerability disclosure policy and a contact path?
Secure-by-default configuration — does the product's default configuration follow the CRA's secure-by-default baseline?
Update channel integrity — does the product deliver security updates through a signed, verifiable channel?
Article 50 marking survival — if the AI component generates synthetic content, does the CRA Article 50 marking survive the real-world transforms? (See ProvBench: 0 of 20 embedded manifests survive.)
Boundary
CSOAI is not a CRA notified body. Where the CRA mandates a third-party conformity
assessment for an Annex III product, you need an accredited notified body. We make
the evidence layer cheaper and verifiable; the conformity call is the regulator's
plus the notified body's. Nothing on this page is legal advice.