Reviewed 17 August 2026
What is the Cyber Resilience Act?
An EU regulation that sets cybersecurity requirements for products with digital elements sold in the EU — and, for the first time, puts a clock on reporting actively exploited vulnerabilities and severe incidents.
Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools
The short version
The Cyber Resilience Act (Regulation (EU) 2024/2847) applies to products with digital elements — hardware and software placed on the EU market whose intended use includes a data connection. It covers the whole life of the product: secure design, a documented vulnerability handling process, security updates during a defined support period, technical documentation, and reporting duties when something goes wrong.
Most teams meet it in one of three ways: a customer questionnaire asks whether you are CRA-ready, a distributor asks for documentation, or someone realises the reporting obligations start before the rest of the regulation does.
Who has obligations
| Role | Typical situation | What it means in practice |
|---|---|---|
| Manufacturer | You develop or have developed a product with digital elements and place it on the EU market under your own name or trademark. | The heaviest duties: secure development, vulnerability handling, support period, technical documentation, conformity assessment and the reporting obligations. |
| Importer | You place a third-country product on the EU market. | Verify that the manufacturer did what was required, keep documentation, and act when you learn a product is non-conforming. |
| Distributor | You make a product available on the EU market without changing it. | Due care: check that the required marking and documentation are present, and stop distribution when you learn of a risk. |
| Open-source steward | You provide sustained support for open-source software used commercially. | A lighter, tailored regime — not the full manufacturer set of duties. |
Substantially modifying a product, or putting your own brand on someone else's, can move you into the manufacturer role. If that describes your business model, treat yourself as a manufacturer until you have written evidence to the contrary.
The dates that matter
The regulation entered into force in December 2024 and applies in stages. The reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. The regulation applies in full, including conformity assessment and CE marking for products with digital elements, from 11 December 2027.
That gap is the reason this site exists. Reporting arrives first, it is time-bound in hours, and it is the one obligation you cannot pass by writing a document the week before an audit.
What the reporting duty actually asks for
When a manufacturer becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting the security of the product, three things follow: an early warning within 24 hours, a fuller notification within 72 hours, and a final report once the picture is complete. Reports go to the CSIRT designated as coordinator and to ENISA through a single reporting platform.
The hard part is rarely the form. It is knowing who is allowed to press send at 02:00, what "aware" means in your organisation, and whether anyone has the product version list to hand. See the deadline breakdown for the clocks and the Article 14 checklist for the fields.
How to work out whether you are in scope
- Does the product have digital elements and a direct or indirect data connection?
- Is it placed on or made available on the EU market, whether or not you are in the EU?
- Do you make it, rebrand it, substantially modify it, import it or distribute it?
- Does a sectoral exclusion apply — for example certain medical devices, motor vehicles, aviation or products covered by equivalent EU rules?
If the first three are yes and no exclusion applies, plan on being in scope and start with the reporting flow, because it starts first.
What this site does not claim
This is a preparation aid, not legal advice, an audit, a certification or an official reporting channel. Nothing here replaces the legal text or your own counsel. Never paste live incident data into a public tool, including this one.
Reviewed 17 August 2026 · assessment version 1.0.0