Cybersecurity

Cyber Resilience Act (CRA): what it is, who it applies to, and how products are classified

Written by

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA), or Cyber Resilience Regulation, is Regulation (EU) 2024/2847 of the European Parliament and of the Council, the first European law to impose mandatory horizontal cybersecurity requirements on all products with digital elements that are placed on the market in the European Union. Its logic is simple and disruptive: if a product connects—directly or indirectly—to a data network, it cannot be sold in the EU without demonstrating that it is secure by design and that its manufacturer will maintain that security throughout the product’s lifetime.

Until now, cybersecurity for software and connected hardware was largely a voluntary commitment by the manufacturer. The CRA changes the starting point: it makes security a legal requirement for market access, on the same level as electrical safety or electromagnetic compatibility. The instrument that makes this real is familiar and recognisable: the CE marking, which under the CRA will also attest to cybersecurity compliance.

The scope is deliberately broad. The Regulation covers everything from a baby monitor or a smartwatch to an operating system, an industrial firewall, a mobile app, or a microcontroller. And it does not apply only to large tech manufacturers: importers, distributors, and any company that places a connected product on the European market under its own brand fall within scope.

This guide is divided into two parts. In this first part, we cover the scoping: what the CRA regulates, who it applies to, which products are covered and which are excluded, what is required on each date, how products are classified by risk, and what penalties apply for non-compliance. The operational part—the technical requirements of Annex I, vulnerability notification deadlines, the CE marking technical file, alignment with NIS2 and ISO 27001, and the preparation roadmap—is covered in How to comply with the Cyber Resilience Act.

Updated August 2026

The CRA has been in force since 10 December 2024, and its application is phased. Two milestones have already been met: Commission Implementing Regulation (EU) 2025/2392, in force since 29 November 2025, sets out the precise technical descriptions of the 28 categories of important and critical products; and since 11 June 2026, the provisions on notified bodies and notifying authorities have been operational.

The next milestone is imminent: on 11 September 2026, the notification obligations for actively exploited vulnerabilities and severe incidents enter into force—also for products already placed on the market—together with the single reporting platform managed by ENISA. The remaining obligations will be enforceable on 11 December 2027.

In parallel, on 27 July 2026 the Commission published its official guidance on the scope of the Regulation, and has proposed delaying by two months the deadlines for the standardisation request: horizontal vulnerability management standards are expected towards the end of October 2026, and product-specific vertical standards throughout December 2026. It is advisable to review the status of harmonised standards before finalising any compliance plan.

Who does the Cyber Resilience Act apply to?

The CRA assigns obligations across the entire digital supply chain, with different levels of intensity depending on each actor’s role:

Primary responsibility

Manufacturers

They design and develop the product. They assume the bulk of the obligations: essential requirements in Annex I, cybersecurity risk assessment, technical documentation, conformity assessment, CE marking, vulnerability management during the support period, and notification to the authorities.

Verification

Importers

They may only place on the EU market products that comply with the Regulation. They must verify that the manufacturer has carried out the conformity assessment, that technical documentation exists, and that the product bears the CE marking and instructions for use.

Due diligence

Distributors

They must act with due diligence: check for the CE marking and documentation, and not make available a product that they know or should suspect is non-compliant. If they detect a risk, they inform the manufacturer and the authorities.

Lighter regime

Open-source software stewards

Foundations and entities that sustain open-source software (open-source stewards) have a specific, lighter regime focused on security policies and cooperation, and are not subject to fines for infringements of the Regulation.

Pay attention to a critical point: an importer or distributor that places a product on the market under its own brand, or substantially modifies it, is considered a manufacturer for all purposes and assumes all of the manufacturer’s obligations. This is the most common scoping mistake in early internal assessments, and it should be resolved before anything else: your role determines the entire volume of work ahead of you.

What is a “product with digital elements”, and what is excluded?

The Regulation defines a product with digital elements as any software or hardware product—and its associated remote data processing solutions—whose intended or reasonably foreseeable use includes a logical or physical connection, directly or indirectly, to a device or a network. In practice, that definition covers almost all connected hardware and virtually all software placed on the market in the EU.

The exclusions are limited and follow two criteria: the existence of equivalent sectoral legislation or the absence of a commercial purpose. The following are excluded from the CRA:

  • Medical devices covered by Regulations (EU) 2017/745 and 2017/746.
  • Motor vehicles subject to Regulation (EU) 2019/2144 and the cybersecurity requirements of type approval.
  • Civil aviation under Regulation (EU) 2018/1139 and marine equipment.
  • Free and open-source software not supplied in the course of a commercial activity.
  • Products developed exclusively for national security, defence, or the processing of classified information.
  • Spare parts intended to replace identical components in products already placed on the market.

Everything else—including software distributed as SaaS when it forms part of a product’s remote data processing solution—falls within scope. The Commission’s guidance on scope, published on 27 July 2026, is the reference to consult in borderline cases.

CRA timeline: what is already enforceable and what lies ahead

The CRA does not apply all at once. Its phased rollout provides time to prepare, but it requires a precise distinction between what has already fallen due and what is still to come. As of August 2026, the picture is as follows:

10 December 2024

Entry into force of the Regulation

Regulation (EU) 2024/2847 enters into force. The transitional period begins: no substantive obligation is yet enforceable.

Completed
29 November 2025

Technical descriptions of the 28 categories

Commission Implementing Regulation (EU) 2025/2392 replaces the generic categories in Annex III with precise technical descriptions. It is now the mandatory reference for classifying a product.

Completed
11 June 2026

Notified bodies operational

The provisions on notifying authorities and conformity assessment bodies apply: they can now be designated and notified.

Completed
11 September 2026

Vulnerability and incident notification obligations

Manufacturers must notify actively exploited vulnerabilities and severe incidents to the coordinating CSIRT and to ENISA, via the single reporting platform. It applies also to products already placed on the market, with no transitional period.

Next milestone · weeks away
11 December 2027

Full application of the Regulation

The essential requirements in Annex I, conformity assessment, technical documentation, the EU declaration of conformity, and the CE marking become enforceable. From that date, a non-compliant product cannot be placed on the market in the EU.

Pending
The date many manufacturers are overlooking is September 2026: the 24-hour notification obligation also applies to products already on the market, with no transitional period and no exception based on the product’s age.

In other words: even though full application arrives at the end of 2027, a block of obligations starts counting in weeks and affects the entire portfolio sold to date. The specific deadlines—24 hours, 72 hours, 14 days—and how to set up the process are detailed in the second part of this guide.

Product classification: default, important, and critical

The CRA calibrates requirements according to product risk, with four levels. This classification determines the conformity assessment procedure: the higher the risk, the less room there is for self-assessment.

LevelProduct examplesConformity route
Default
(~90% of the market)
Mobile apps, video games, external hard drives, connected speakers, general management software. Self-assessment Internal control (Module A).
Important
Class I

(Annex III, 19 categories)
Password managers, browsers, antimalware, VPN, SIEM, identity and access management systems, operating systems, routers and switches, PKI, boot managers, home virtual assistants, smart locks and cameras, connected toys, health wearables. Self-assessment only if harmonised standards or a certification scheme are applied; otherwise, third-party assessment.
Important
Class II

(Annex III)
Hypervisors and container engines, firewalls, intrusion detection and prevention systems (IDS/IPS), tamper-resistant microprocessors and microcontrollers, critical industrial control systems for NIS2 entities. Mandatory third party EU type examination (B+C) or full quality assurance (H).
Critical
(Annex IV, 3 categories)
Hardware devices with secure boxes (HSM), smart meter gateways and secure cryptoprocessing devices, smart cards and secure elements. Certification European cybersecurity certification (EUCC) at least at “substantial” level when required by the Commission.

Correctly classifying the product is the first structural decision in the compliance project: cost, timelines, and whether you need to engage a notified body depend on it. Commission Implementing Regulation (EU) 2025/2392 is now the mandatory reference for doing so, because it replaces the generic categories in Annex III with precise technical descriptions.

And it has a practical consequence with its own timeline: if any product in your portfolio falls under important class II or critical, you need a third party. Notified bodies have been operational since June 2026, but their capacity is limited and demand will concentrate as December 2027 approaches.

Not sure which CRA category your products fall into? We will show you how to inventory them, classify them, and map their requirements on the platform.

Request a demo

Penalties for non-compliance with the Cyber Resilience Act

The CRA penalty regime is structured in three tiers, following the usual approach in EU law: the higher of a fixed amount and a percentage of the previous financial year’s worldwide annual turnover.

Type of non-complianceMaximum penalty
Non-compliance with the essential requirements of Annex I—the product’s cybersecurity properties and vulnerability management—and with the obligations in Articles 13 and 14 (manufacturer obligations and notification). €15 million or 2.5% of worldwide annual turnover.
Non-compliance with any other obligation under the Regulation (importers, distributors, authorised representatives, notified bodies). €10 million or 2% of worldwide annual turnover.
Providing incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities. €5 million or 1% of worldwide annual turnover.

Beyond the fine, market surveillance authorities may require the product to be withdrawn, prohibit it from being placed on the market, or restrict its availability. For a manufacturer, that commercial risk often weighs more than the financial penalty. A relevant nuance for smaller companies: micro and small enterprises do not face fines specifically for missing the 24-hour early warning deadline, although they still remain subject to the other obligations.

Translated into priorities: most of the financial risk is concentrated in the top tier—Annex I requirements and notification obligations—which is precisely the workstream we address in the second part of this guide.

How can GRC software help with CRA scoping?

At GlobalSuite Solutions, we approach the CRA for what it really is: a governance, risk, and compliance problem with fixed legal deadlines, not a spreadsheet of technical requirements. And it all starts with the scoping we have covered in this article. Our GlobalSuite® platform makes it possible to build the inventory of products with digital elements and their components, record the organisation’s role for each one—manufacturer, importer, or distributor, including the own-brand effect—classify them under Annexes III and IV and Implementing Regulation 2025/2392, and derive from that classification the conformity route and the enforceable dates for each product. On that same basis, it manages traceability from each legal requirement to a control, an owner, and evidence, tracking of the action plan with due-date alerts, and multi-standard mapping with NIS2, ISO 27001, IEC 62443, DORA, or the ENS, so that one piece of evidence can serve multiple frameworks. The result is a single dashboard of compliance status and residual risk, ready for an audit or an inspection by the market surveillance authority.

Frequently asked questions about the Cyber Resilience Act

When does the Cyber Resilience Act enter into force?

Regulation (EU) 2024/2847 has been in force since 10 December 2024, but its application is phased. The provisions on notified bodies apply from 11 June 2026, the vulnerability and incident notification obligations from 11 September 2026, and the remaining obligations—essential requirements, conformity assessment, and CE marking—from 11 December 2027.

Which products does the CRA apply to?

It applies to all products with digital elements placed on the market in the EU whose intended use includes a connection, directly or indirectly, to a device or a network: connected hardware, software, applications, operating systems, and the associated remote data processing solutions. Excluded are medical devices, motor vehicles, civil aviation, marine equipment, free and open-source software without a commercial activity, and defence or national security products.

Does the CRA affect products that are already on the market?

Yes, in one specific area and with an immediate date: the notification obligations for actively exploited vulnerabilities and severe incidents, enforceable from 11 September 2026, also apply to products already placed on the market, with no transitional period and no exception based on age. The essential requirements of Annex I and the CE marking, by contrast, apply to products placed on the market from 11 December 2027 onwards.

What happens if I sell under my own brand a product manufactured by someone else?

You stop being an importer or distributor and become a manufacturer for all purposes under the Regulation. The same applies if you substantially modify a product already placed on the market. That means taking on the full package of obligations: Annex I requirements, risk analysis, technical documentation, conformity assessment, CE marking, vulnerability management, and notification. It is the first point to verify in any internal assessment, because it determines the project’s true scope.

Do I need a notified body to certify my product?

It depends on the classification. Default products are self-assessed through internal control. Important class I products can be self-assessed only if harmonised standards or a European certification scheme are applied; otherwise they need a third party. Important class II products always require assessment by a notified body, and critical products in Annex IV may require European cybersecurity certification.

What penalties does the CRA provide for?

Up to €15 million or 2.5% of worldwide annual turnover for non-compliance with the essential requirements of Annex I and the obligations in Articles 13 and 14; up to €10 million or 2% for the remaining obligations; and up to €5 million or 1% for providing incorrect or misleading information to the authorities. The higher amount always applies, and this may be combined with withdrawal of the product from the market.

In summary

The Cyber Resilience Act makes cybersecurity a condition for access to the European market for any connected product, with the CE marking as proof and penalties of up to €15 million or 2.5% of worldwide turnover. It applies to manufacturers, importers, and distributors—and anyone selling under their own brand counts as a manufacturer—with exclusions limited to sectors that already have equivalent legislation.

The timeline leaves little room: three milestones already met, 11 September 2026 for notification obligations—also for products already placed on the market—and 11 December 2027 for the rest. The two decisions that organise everything else are determining your role and classifying the portfolio under Annexes III and IV: from there come the cost, timelines, and the need for a notified body.

With the scoping resolved, the next step is the technical and documentary work: How to comply with the Cyber Resilience Act: Annex I requirements, notification, and roadmap.

Inventory and classify your product portfolio on a single platform

Inventory of products with digital elements and components, role recording per product, classification under Annexes III and IV, enforceable dates per product, and multi-standard mapping with NIS2 and ISO 27001. We will show you with a real case.

Request a demo

Tabla de contenidos