๐Ÿ”ด CRITICAL: ENISA 24-hour vulnerability reporting goes live September 11, 2026. Non-compliance carries fines up to โ‚ฌ15,000,000 or 2.5% of global turnover. Check your exposure โ†’
EU Regulation 2024/2847 ยท Now in Force

Are You Ready for a โ‚ฌ15 Million Non-Compliance Fine?

If you ship software or hardware in the EU, unaddressed CRA obligations or late exploit reporting can trigger instant product bans across all 27 member states.

๐Ÿ‡ช๐Ÿ‡บ EU Regulation 2024/2847
๐Ÿ“‹ ENISA Guidelines
๐Ÿ”’ Free to use
// CRA KEY DEADLINES
CRA Enters into Force
Regulation officially active
DEC 2024 โœ“
Vulnerability Reporting
24h ENISA reporting begins
SEP 2026
Full CRA Compliance
All products must conform
DEC 2027
Self-Assessment (Default)
90% of all digital products
DEC 2027
โฑ Time to Sept 2026 Deadline
--
days
:
--
hrs
:
--
min
:
--
sec

What is the Cyber Resilience Act?

The EU CRA (Regulation 2024/2847) is a landmark law setting mandatory cybersecurity requirements for all products with digital elements sold in the EU โ€” from mobile apps to industrial IoT devices.

๐ŸŽฏ

Scope: Products with Digital Elements

Any hardware or software product connected directly or indirectly to a network, sold in the EU. This includes mobile apps, IoT devices, operating systems, firmware, and open-source software with commercial use.

Mobile AppsIoT DevicesSaaSOSS (commercial)Firmware
๐Ÿ›๏ธ

Three Product Categories

Default (90% of products) โ€” self-assessment by manufacturer. Class I Important โ€” third-party audit or strict self-assessment. Class II Critical โ€” mandatory third-party certification by accredited body.

Default โ†’ Self-assessClass I โ†’ AuditClass II โ†’ Certified
๐Ÿ“‹

Essential Requirements (21 Total)

Products must be designed with security by default, include no known exploitable vulnerabilities, receive security updates throughout their lifecycle, and carry a Declaration of Conformity plus CE marking.

Secure by designCE markingSBOM required5yr support min
๐Ÿ””

Reporting Obligations (from Sept 2026)

Actively exploited vulnerabilities must be reported to ENISA within 24 hours. A full notification within 72 hours. A final report within 14 days. All through the ENISA Single Reporting Platform (SRP).

24h early warning72h notification14d final reportvia ENISA SRP

Who Does the CRA Affect?

If you sell, distribute, or import any digital product into the EU market โ€” the CRA applies to you. Here are the key segments and their obligations.

02
๐Ÿข

SMEs & Startups

Companies with under 50 employees get some relief on the 24h early warning timing, but must still report. ENISA is specifically mandated to provide dedicated helpdesk support for microenterprises.

Limited exemptions
03
๐Ÿ“ฆ

Open Source Maintainers

Pure hobbyist OSS is exempt. OSS with commercial support or funding falls under the "open source steward" role. OSS bundled into a commercial product โ€” full manufacturer rules apply.

Complex rules apply
04
๐ŸŒ

Non-EU Businesses

Any company outside the EU selling digital products to EU customers must comply. You must appoint an EU-based authorised representative and submit via the CSIRT of their country.

Full compliance required
05
๐Ÿ”Œ

IoT & Hardware Makers

Smart home devices, industrial systems, and connected hardware are in scope. Many fall into Class I or Class II, requiring third-party conformity assessment โ€” not just self-declaration.

Higher risk category
06
๐Ÿšข

Importers & Distributors

If a manufacturer outside the EU doesn't comply, the importer or distributor becomes legally responsible. Supply chain due diligence is now a legal obligation, not a best practice.

New liability exposure

CRA Compliance Timeline

The CRA is being phased in over a 36-month window. Here are the dates that matter for any business shipping a digital product into the EU.

  1. 10 Dec 2024 Done

    CRA Enters Into Force

    EU Regulation 2024/2847 officially published in the Official Journal. The 36-month main transition window starts.

  2. 11 Sep 2026 In ~5 months

    Vulnerability Reporting Begins

    From this date, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. The 24h / 72h / 14d timeline applies.

  3. 11 Dec 2027 ~20 months

    Full CRA Compliance Deadline

    All products with digital elements placed on the EU market must conform with the CRA, carry CE marking, and have a Declaration of Conformity.

  4. 2027 onwards Enforcement era

    Market Surveillance

    National authorities begin enforcement. Non-conforming products can be banned from the EU market. Fines up to โ‚ฌ15M or 2.5% of global turnover.

Is Your Product CRA Ready?

Get a free personalised CRA compliance briefing for your specific product type, delivered to your inbox. No spam, no sales calls.

  • โ˜… Understand your exact product category (default, Class I, or Class II)
  • โ˜… Get a checklist of your specific obligations and deadlines
  • โ˜… Receive guidance on SBOM, vulnerability management, and reporting
  • โ˜… Early access to our CRA Compliance Manager tool (launching 2026)
  • โ˜… Weekly CRA news digest: ENISA updates, regulatory guidance

Get Your Free CRA Brief

Takes 60 seconds ยท Completely free

๐Ÿ”’ No spam. Unsubscribe anytime. See our privacy policy.

Guides, Checklists, and Tools

Everything we publish is free and SEO-optimised so you can find what you need fast. Bookmark this page โ€” it's updated as ENISA publishes new guidance.

Everything you need to ship CRA-compliant software.

We build the tools we wished existed when we first read Regulation 2024/2847. They're optional โ€” every guide on this site is free and complete.

Launching 2026

CRA Compliance Manager

A self-service workspace to classify your product, generate your SBOM, draft your Declaration of Conformity, and track your essential-requirement gap analysis.

  • โ˜…Auto-classification (Default / Class I / Class II)
  • โ˜…CycloneDX & SPDX SBOM generation
  • โ˜…Declaration of Conformity templates
  • โ˜…Audit-ready evidence vault
Join the waitlist โ†’
Beta ยท 2026

CRA Incident Reporter

Pre-formatted forms for the ENISA Single Reporting Platform with built-in timers for the 24h / 72h / 14d deadlines, plus templated language for early warnings and final reports.

  • โ˜…ENISA SRP-aligned schemas
  • โ˜…24h / 72h / 14d deadline timers
  • โ˜…Multi-CSIRT routing
  • โ˜…Audit log + immutable archive
Get early access โ†’