Skip to content
Auray CRA PlatformLog in

Regulation (EU) 2024/2847

The Cyber Resilience Act is already running.

Two of its three dates have passed. Reporting duties start 11 September 2026.

Talk to Auray

Small or medium sized business? Start free with our self-check tool

  1. done10 Dec 2024In force
  2. done11 Jun 2026Notified bodies
  3. next11 Sep 2026Reporting duties
  4. ahead11 Dec 2027Full application

ReferenceCRA Article 71(2)

Scope

If it has software in it, start from yes.

Not a list of gadgets. Components sold separately are in scope on their own, and so is the cloud service your device needs to work.

Product with digital elements

Toggle a part.

ReferenceCRA Article 3(1)

Classification

Your tier decides who signs off.

26 categories are named. Everything else is default.

Everything not named

Default

You self-assess

Internal control, module A.

Drag, or use the arrow keys.

ReferenceCRA Annexes III and IV; Implementing Regulation (EU) 2025/2392

What applies when

Two dates down, two to go.

Reporting arrives well before the rest.

  1. 10 Dec 2024

    Entry into force

  2. 11 Jun 2026

    Notified bodies, Articles 35 to 51

  3. 11 Sep 2026

    Reporting duties, Article 14

  4. 11 Dec 2027

    Applies in full

ReferenceCRA Article 71(2)

Annex I

The part you actually have to build.

Thirteen properties the product must have, and eight things you never stop doing.

On the basis of your own cybersecurity risk assessment, and where applicable. Annex I is not thirteen boxes every product ticks.

Part I, the product

As shipped

No known exploitable vulnerabilities

At the point it is made available on the market.

Cycling. Pick one to take over.

Part II, and it never stops

at least 5 yr

How long Part II binds

The support period. A floor, not the answer: longer if the product is expected to last longer.

2.5 % or EUR 15 M

Getting Annex I wrong

Of total worldwide annual turnover, whichever is higher.

ReferenceCRA Annex I Parts I and II; Articles 13(8) and 64

The standard, in draft

The standard everyone is waiting for is not finished.

The CRA says what to achieve. EN 40000 will say how to evidence it. It is still being written.

  • Principles for cyber resilience

    30 Aug 2026

    draft
  • Vulnerability Handling

    30 Aug 2026

    draft
  • Generic Security Requirements

    30 Oct 2027

    draft

Official Journal

Empty

ReferenceCRA Article 27(1); CEN, CENELEC and ETSI work programme M/606

Auray CRA Platform

Somewhere to put the evidence.

A workspace shaped like the EN 40000 draft sections.

Cycling. Pick one to take over.

Already have a workspace?

Log in to the platform
Product context

Product name

Intended purpose

Users

Operating environment

saved

Auditable documentation. Not a CE mark, not a certificate, not legal advice.

ReferenceAuray CRA Platform

Next step

Talk to the lab that tests this.

Auray is Asia's first O-RAN Alliance-authorised third-party testing laboratory, with EN 18031 security testing and ISO 27001 consulting.

Talk to Auray

Small or medium sized business? Start free with our self-check tool

Checked against

  • Regulation (EU) 2024/2847 (CRA)
  • Implementing Reg. (EU) 2025/2392
  • ENISA SME Cyber Resilience Maturity Model
  • BSI TR-03183 Parts 1-3
  • EN 40000 series (draft)
  • Commission CRA Guidance & FAQ
  • Blue Guide 2022