Skip to content
AuCRA PlatformLog in

Regulation (EU) 2024/2847

The Cyber Resilience Act is already running.

Two of its three dates have passed. Reporting duties start 11 September 2026.

Small or medium sized business? The self-check is free.

  1. done10 Dec 2024In force
  2. done11 Jun 2026Notified bodies
  3. next11 Sep 2026Reporting duties
  4. ahead11 Dec 2027Full application

ReferenceCRA Article 71(2)

Scope

If it has software in it, start from yes.

Not a list of gadgets. A component sold on its own counts by itself, and so does the cloud service your device needs to work.

Product with digital elements

Toggle a part.

What these words mean
Product with digital elements
The law's name for a software or hardware product together with the remote data processing it needs to work. A component placed on the market on its own counts as one too.

ReferenceCRA Article 3(1)

Classification

Your tier decides who signs off.

26 categories are named. Everything else is default.

In plain words

Most products sit in the default tier, where you assess your own product. The named categories are treated more strictly, and the strictest always need an independent third party.

Everything not named

Default

You assess it yourself

You check the product yourself, under internal control (module A).

Drag, or use the arrow keys.

What these words mean
Harmonised standard
A standard whose reference the EU has published in its Official Journal. Follow one and you are presumed to meet the requirements it covers.
Third party
An independent body that assesses the product instead of you assessing it yourself. The CRA calls these notified bodies.

ReferenceCRA Annexes III and IV; Implementing Regulation (EU) 2025/2392

What applies when

Two dates down, two to go.

Reporting arrives well before the rest.

In plain words

The rules switch on in stages, not all at once. The next stage is the duty to report, on 11 September 2026.

  1. 10 Dec 2024

    The law enters into force

  2. 11 Jun 2026

    Rules for notified bodies, Articles 35 to 51

  3. 11 Sep 2026

    Reporting duties begin, Article 14

  4. 11 Dec 2027

    The whole Regulation applies

ReferenceCRA Article 71(2)

Annex I

The part you actually have to build.

Thirteen properties the product must have, and eight things you never stop doing.

In plain words

Annex I is where the Regulation says what your product must do, and what you must keep doing about vulnerabilities while you support it.

These apply on the basis of your own cybersecurity risk assessment, and only where applicable. Annex I is not thirteen boxes every product ticks.

Part I: what the product must do

As shipped

No known exploitable vulnerabilities

At the point it is made available on the market.

Cycling. Pick one to take over.

Part II: what you keep doing after it ships

  1. 1Identify and document components

    A software bill of materials (SBOM) in a machine-readable format, covering at the very least the top-level dependencies.

  2. 2Fix vulnerabilities without delay

    Security fixes go out separately from functionality updates, where that is technically feasible.

  3. 3Test and review regularly

    Effective and regular security tests of the product.

  4. 4Disclose what you fixed

    Once the update is out, with enough detail for users to act.

  5. 5Run a disclosure policy

    A coordinated vulnerability disclosure policy, put in place and enforced.

  6. 6Publish a reporting contact

    An address for vulnerabilities found in the product or its components.

  7. 7Distribute updates securely

    Automatically as well, where applicable for security updates.

  8. 8Free of charge, unless otherwise agreed

    Updates carry advisory messages. The exception is a business user agreeing otherwise on a tailor-made product.

Open any step for the detail.

at least 5 yr

How long Part II binds

The support period, and a floor rather than an answer: longer where the product is expected to be in use for longer.

2.5 % or EUR 15 M

Getting Annex I wrong

Of total worldwide annual turnover, whichever is higher.

What these words mean
SBOM
A software bill of materials: a machine-readable list of the components a product is built from. The CRA asks for the top-level dependencies at the very least, not every nested one.
Support period
The time for which you must keep handling vulnerabilities in the product. At least five years, and longer where the product is expected to be in use for longer.

ReferenceCRA Annex I Parts I and II; Articles 13(8) and 64

The standard, in draft

The standard everyone is waiting for is not finished.

The CRA says what to achieve. The draft EN 40000 series will say how to show it.

In plain words

EN 40000 is the standard being written for the CRA. It is still a draft, so following it does not yet give you the presumption that you comply.

  • Principles for cyber resilience

    30 Aug 2026

    draft
  • Vulnerability Handling

    30 Aug 2026

    draft
  • Generic Security Requirements

    30 Oct 2027

    draft

Official Journal

Empty

What these words mean
Presumption of conformity
Follow a harmonised standard the EU has cited in the Official Journal, and you are presumed to meet the requirements that standard covers.
Official Journal
The EU's official gazette. A standard only carries presumption of conformity once its reference is published there.

ReferenceCRA Article 27(1); CEN, CENELEC and ETSI work programme M/606

AuCRA Platform

Somewhere to put the evidence.

A workspace laid out to follow the draft EN 40000 sections.

Cycling. Pick one to take over.

Already have a workspace?

Log in to the platform
Product context

Product name

Intended purpose

Users

Operating environment

saved

Auditable documentation. Not a CE mark, not a certificate, not legal advice.

ReferenceAuCRA Platform

Next step

Talk to the lab that tests this.

Auray is Asia's first O-RAN Alliance-authorised third-party testing laboratory, with EN 18031 security testing and ISO 27001 consulting.

Talk to Auray

Small or medium sized business? Start free with our self-check tool

Checked against

  • Regulation (EU) 2024/2847 (CRA)
  • Implementing Reg. (EU) 2025/2392
  • ENISA SME Cyber Resilience Maturity Model
  • BSI TR-03183 Parts 1-3
  • EN 40000 series (draft)
  • Commission CRA Guidance & FAQ
  • Blue Guide 2022