Overview
The Cyber Resilience Act is EU product law for the cybersecurity of software and hardware products with digital elements. It connects market access, secure design, vulnerability handling, conformity assessment, user information, and mandatory reporting into one horizontal framework.
Purpose and structure
The CRA is EU product law for the cybersecurity of products with digital elements. It is not only an incident-reporting law and it is not limited to consumer IoT. This overview maps the main questions: whether the product is in scope, who carries each duty, how the product is classified, which requirements apply, and when the main duties start.
The deeper pages explain the legal definitions, role boundaries, product categories, standards route, technical documentation, reporting route, and transition rules. Start with this page when you need the map before reading the detailed pages.
Core concepts
Scope
Scope asks whether the product is a product with digital elements, is supplied on the Union market in a commercial activity, has the required data connection, and is not excluded.
Role
Role asks whether the actor is a manufacturer, importer, distributor, authorised representative, or open-source software steward.
Classification
Classification starts after scope. It asks whether the product is in the default category, an important product, or a critical product.
Requirements
Annex I combines product security properties with the vulnerability-handling processes that must operate during the support period.
Manufacturer preparation map
A manufacturer normally reads the CRA in a fixed order. The order starts with the product and then moves to role, category, duties, standards, documentation, reporting, and timing. Skipping that order makes later conclusions unreliable.
- Start with Products in Scope and Placing on the Market .
- Identify the economic-operator role in Roles and Duties .
- Classify the product using Product Classification and Regulation 2025/2392 Technical Descriptions .
- Read the product and process duties in Essential Cybersecurity Requirements .
- Check the standards route in Standards and Harmonised Standards and Product Standards by Category .
- Connect the result to Cybersecurity Risk Assessment, Technical Documentation and User Information and Instructions.
- Prepare Article 14 reporting with Vulnerability Reporting and Article 14 Reporting Readiness .
- Use the key dates to separate reporting, notified-body, transition, and full-application timing.
Products in scope
This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.
Regulation (EU) 2024/2847, Article 2(1)
A product with digital elements can be software, hardware, a separately placed software or hardware component, and the product's remote data processing solution. Remote processing is part of the product only when it is designed and developed by, or under the responsibility of, the manufacturer and the product would not perform one of its functions without it.
The CRA does not turn every digital service into a product with digital elements. A website or cloud service outside the manufacturer's product responsibility is different from remote processing that the product needs in order to work. Explicit exclusions are handled on the scope page; the broader product-law background is handled on the basics page.
Roles and product categories
Role decides who carries the duty. Classification decides which conformity assessment route is available or required. These questions should not be merged: the same in-scope product can involve several economic operators, but its product category turns on the product's own core functionality.
- Default products remain subject to the CRA, but normally use the internal-control conformity route.
- Important products are listed in Annex III and divided into Class I and Class II.
- Critical products are listed in Annex IV and can face certification or stricter third-party assessment routes.
- Commission Implementing Regulation (EU) 2025/2392 gives technical descriptions for important and critical product categories.
A product is not important or critical merely because it contains a component that appears in a listed category. The relevant question is whether the whole product has the core functionality of that category.
Essential requirements and standards
Article 6 links the product and the manufacturer's processes. Annex I separates product cybersecurity requirements from vulnerability-handling process requirements. Harmonised standards can support presumption of conformity for the requirements they cover, but the legal duties remain in the regulation.
Use the detailed pages for the Annex I structure and the standards route. Essential Cybersecurity Requirements and Standards and Harmonised Standards.
Reporting and vulnerability handling
Vulnerability handling is a lifecycle duty. Reporting is a narrower event-triggered duty. From 11 September 2026, Article 14 applies when a manufacturer becomes aware of an actively exploited vulnerability in the product or a severe incident affecting the product's security.
The reporting route is separate
Reports go through the CRA Single Reporting Platform established by ENISA. Reporting an event does not replace the manufacturer's duty to assess, mitigate, remediate, update users, and maintain the product during the support period.
- Early warning: within 24 hours after the manufacturer becomes aware.
- Notification: within 72 hours after the manufacturer becomes aware, unless the relevant information was already provided.
- Final report for an actively exploited vulnerability: no later than 14 days after a corrective or mitigating measure is available.
- Final report for a severe incident: within one month after the 72-hour incident notification.
Key dates
The CRA was published in the Official Journal on 20 November 2024 and entered into force on 10 December 2024. Its application is phased, so the reporting and conformity-assessment-body dates arrive before full application.
Chapter IV, Articles 35 to 51, starts to apply. These rules cover notifying authorities and notified bodies.
Manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security when Article 14 requires reporting.
This is the main application date for the CRA's product, conformity, documentation, and market duties.
Products placed on the market before this date are subject to the CRA only if they are substantially modified, except that Article 14 reporting still applies to in-scope products already on the market.
Some EU type-examination certificates and approval decisions under other Union harmonisation legislation remain valid until this date unless they expire earlier or that legislation says otherwise.
Sources
- Regulation (EU) 2024/2847, Cyber Resilience Act
- European Commission CRA implementation page
- European Commission CRA implementation FAQ
- Commission Implementing Regulation (EU) 2025/2392
- European Commission CRA reporting obligations page
- ENISA Single Reporting Platform FAQ
- European Commission CRA standardisation page