Regulation (EU) 2024/2847
The Cyber Resilience Act is already running.
Two of its three dates have passed. Reporting duties start 11 September 2026.
Small or medium sized business? Start free with our self-check tool
- done10 Dec 2024In force
- done11 Jun 2026Notified bodies
- next11 Sep 2026Reporting duties
- ahead11 Dec 2027Full application
ReferenceCRA Article 71(2)
Scope
If it has software in it, start from yes.
Not a list of gadgets. Components sold separately are in scope on their own, and so is the cloud service your device needs to work.
Toggle a part.
ReferenceCRA Article 3(1)
Classification
Your tier decides who signs off.
26 categories are named. Everything else is default.
Everything not named
Default
You self-assess
Internal control, module A.
Drag, or use the arrow keys.
ReferenceCRA Annexes III and IV; Implementing Regulation (EU) 2025/2392
What applies when
Two dates down, two to go.
Reporting arrives well before the rest.
10 Dec 2024
Entry into force
11 Jun 2026
Notified bodies, Articles 35 to 51
11 Sep 2026
Reporting duties, Article 14
11 Dec 2027
Applies in full
ReferenceCRA Article 71(2)
Annex I
The part you actually have to build.
Thirteen properties the product must have, and eight things you never stop doing.
On the basis of your own cybersecurity risk assessment, and where applicable. Annex I is not thirteen boxes every product ticks.
Part I, the product
No known exploitable vulnerabilities
At the point it is made available on the market.
Cycling. Pick one to take over.
Part II, and it never stops
at least 5 yr
How long Part II binds
The support period. A floor, not the answer: longer if the product is expected to last longer.
2.5 % or EUR 15 M
Getting Annex I wrong
Of total worldwide annual turnover, whichever is higher.
ReferenceCRA Annex I Parts I and II; Articles 13(8) and 64
The standard, in draft
The standard everyone is waiting for is not finished.
The CRA says what to achieve. EN 40000 will say how to evidence it. It is still being written.
- draft
Principles for cyber resilience
30 Aug 2026
- draft
Vulnerability Handling
30 Aug 2026
- draft
Generic Security Requirements
30 Oct 2027
Official Journal
Empty
ReferenceCRA Article 27(1); CEN, CENELEC and ETSI work programme M/606
Auray CRA Platform
Somewhere to put the evidence.
A workspace shaped like the EN 40000 draft sections.
Product name
Intended purpose
Users
Operating environment
Auditable documentation. Not a CE mark, not a certificate, not legal advice.
ReferenceAuray CRA Platform
Next step
Talk to the lab that tests this.
Auray is Asia's first O-RAN Alliance-authorised third-party testing laboratory, with EN 18031 security testing and ISO 27001 consulting.
Small or medium sized business? Start free with our self-check tool
Checked against
- Regulation (EU) 2024/2847 (CRA)
- Implementing Reg. (EU) 2025/2392
- ENISA SME Cyber Resilience Maturity Model
- BSI TR-03183 Parts 1-3
- EN 40000 series (draft)
- Commission CRA Guidance & FAQ
- Blue Guide 2022