40 questions answered
CRA Frequently Asked Questions
Curated from the regulation text, ENISA guidance, and recurring questions from the developers and compliance teams we work with. Search Ctrl+F — every answer is on this page.
General CRA questions
What is the EU Cyber Resilience Act? +
When did the CRA enter into force? +
When do the reporting obligations start? +
When does full compliance kick in? +
Does the CRA replace existing cybersecurity laws? +
Who enforces the CRA? +
What are the maximum fines? +
Does the CRA apply to free apps and free software? +
Mobile app developer questions
Are mobile apps in scope of the CRA? +
Which category do most mobile apps fall into? +
How do I "CE mark" a mobile app? +
Do I need an SBOM for my mobile app? +
Does the CRA apply to apps distributed only outside the EU? +
What if my app uses third-party SDKs that aren't CRA-compliant? +
Open source questions
Is open-source software exempt from the CRA? +
What is an "open source steward"? +
Do hobbyist contributors have any CRA duties? +
What if my OSS project is bundled into a paid product? +
Do I need an SBOM for my OSS project? +
Where can I read the OSS-specific CRA text? +
SME and startup questions
Are there CRA exemptions for small businesses? +
Does my pre-revenue startup have to comply? +
What is the cheapest way to get to compliance? +
Are there grants for CRA compliance? +
Can I outsource compliance? +
ENISA SRP and reporting questions
What is the ENISA Single Reporting Platform? +
What triggers the 24-hour clock? +
Does every vulnerability need to be reported? +
What information goes in the 24-hour early warning? +
What goes in the 72-hour notification? +
What goes in the 14-day final report? +
Can I be fined for failing to report? +
How do non-EU manufacturers submit reports? +
Timeline and deadline questions
Why are the dates 11 September 2026 and 11 December 2027? +
Can the deadlines slip? +
What if my product is already on the market on 11 December 2027? +
What counts as a "substantial modification"? +
Will harmonised standards be ready by Dec 2027? +
What should I do today (April 2026)? +
Where can I find the official text? +
Free Compliance Assessment
Is Your Product CRA Ready?
Get a free personalised CRA compliance briefing for your specific product type, delivered to your inbox. No spam, no sales calls.
- ★ Understand your exact product category (default, Class I, or Class II)
- ★ Get a checklist of your specific obligations and deadlines
- ★ Receive guidance on SBOM, vulnerability management, and reporting
- ★ Early access to our CRA Compliance Manager tool (launching 2026)
- ★ Weekly CRA news digest: ENISA updates, regulatory guidance
Get Your Free CRA Brief
Takes 60 seconds · Completely free
Request received
You're on the list
We've got your details. Your personalised CRA brief is prepared by hand, so give us a working day or two and watch your inbox.
Meanwhile, check your product class →🔒 No spam. Unsubscribe anytime. See our privacy policy.