The Cyber Resilience Act, explained simply
Cybersecurity requirements for almost every digital product sold in the EU. The essentials, without reading 200 pages.
- Text
- Règlement (UE) 2024/2847
- In force since
- Dec 2024
- Penalties
- up to €15M / 2.5% of turnover
What exactly is the CRA?
The Cyber Resilience Act is the first EU regulation imposing cybersecurity requirements across the whole lifecycle of 'products with digital elements' — almost any software or connected hardware sold in the EU.
Its goal: products reach the market more secure and stay that way, through updates and vulnerability handling. No more never-patched connected devices.
In practice: if you sell (or commercially provide) software or a device in the EU, you become responsible for its security — documentation, vulnerability handling, reporting.
Who is affected?
Downloadable software, apps, firmware / IoT, commercial open-source. ~90% of scope.
SMEs and micro-enterprises: reduced requirements, but NOT exempt.
Non-commercial open-source. Pure SaaS (falls under NIS2 instead).
The risk categories
The more sensitive your product, the higher the requirements.
Default (~90%)
The vast majority of products. Self-assessment of conformity by the manufacturer.
Important (Class I & II)
Sensitive products: password managers, VPNs, browsers, antivirus, microcontrollers… Harmonised standards or third-party assessment.
Critical
The most sensitive products (HSMs, smart cards, smart meters…). European certification possible.
The timeline
Regulation (EU) 2024/2847 enters into force.
Reporting obligations: report actively exploited vulnerabilities to ENISA (24h / 72h / 14d).
Full application of ALL obligations. No CE marking without conformity.
The 5 key obligations
Software bill of materials (SBOM)
An up-to-date component inventory, CycloneDX or SPDX format.
Vulnerability disclosure policy
A coordinated reporting channel (SECURITY.md), Art. 13.
Technical documentation
The Annex VII file, ready for a notified body.
EU declaration of conformity + CE marking
The official document + the marking on the product.
ENISA reporting
Actively exploited vulnerabilities: 24h alert, 72h notification, 14d report.
CRAcheck covers these 5 pillars, automatically from your repo.
Frequently asked
Is SaaS affected?
Generally no: pure SaaS falls under NIS2. But as soon as you distribute a downloadable or installable component, the CRA applies.
What about open-source?
Non-commercial open-source is exempt. Once a company commercialises it or integrates it into a sold product, obligations apply (lighter for 'stewards').
I'm a small team, really affected?
Yes — but SMEs get lighter requirements. You're not exempt though.
What if I do nothing?
Beyond fines (up to €15M), you won't be able to affix CE marking or legally sell your product in the EU.
Don't get caught out
Up to €15M or 2.5% of worldwide annual turnover for the most serious breaches. Check your situation in 1 minute.
Check if I'm affected →