Cyber Resilience Act FAQ

Long-form answers to the questions EU manufacturers actually ask about Regulation (EU) 2024/2847. Every claim carries a pinpoint citation, and every source is marked as binding law or as interpretive guidance.

10 questions107 cited sources4 categories

Scope and applicability

Conformity and CE marking

Obligations in practice

What do I actually have to do to comply with the Cyber Resilience Act?Compliance runs as an ordered sequence where each step feeds the next. Confirm the product is in scope and that you are its manufacturer, then classify it as default, Annex III important class I or II, or Annex IV critical. Run the Article 13(2) risk assessment, which determines which Annex I Part I requirements apply. Build to those, meet the Part II vulnerability handling requirements, compile Article 31 technical documentation, complete the Article 32 conformity assessment, draw up the EU declaration of conformity, affix the CE marking, and report under Article 14.18 sources · reviewed 2026-07-27What documents and reports does the Cyber Resilience Act require me to produce?The Cyber Resilience Act requires six artefacts. Technical documentation under Article 31 and Annex VII, which contains the risk assessment. An EU declaration of conformity under Article 28 and Annex V. A software bill of materials and a coordinated vulnerability disclosure policy, both under Annex I Part II. Information and instructions to the user under Annex II. Then the Article 14 filings once reporting begins. Technical documentation and the declaration are kept available to market surveillance authorities for at least 10 years or the support period, whichever is longer.12 sources · reviewed 2026-07-27What does the Cyber Resilience Act require in a cybersecurity risk assessment?Article 13(2) of the Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers to assess the cybersecurity risks of a product with digital elements and to carry the outcome through the planning, design, development, production, delivery and maintenance phases. Article 13(3) requires that assessment to be documented, kept updated across the support period, and to state which Annex I Part I point 2 requirements apply and how they are met. It forms part of the technical documentation under Article 31 and Annex VII, and the duty applies from 11 December 2027.14 sources · reviewed 2026-07-27

Reporting and vulnerability handling

Do I have to report the same incident under the CRA, NIS2 and GDPR?One event can trigger all three, and none of them excuses the others. CRA Article 14 binds the manufacturer when a vulnerability in its product is actively exploited or a severe incident affects product security, filed to a coordinating CSIRT and ENISA. NIS2 Article 23 binds essential and important entities when a significant incident disrupts their own services. GDPR Article 33 binds the controller within 72 hours of a personal data breach. The triggers, the subjects and the recipients differ, so the filings run in parallel.11 sources · reviewed 2026-07-27When does the CRA reporting clock start?The clock starts when you become aware, and Commission guidance now defines that moment. On detecting a suspicious event or receiving a report from a researcher, customer or authority, assess it immediately. You become aware once that initial assessment gives you a reasonable degree of certainty that a vulnerability in your product is being actively exploited, or that a severe incident has compromised your product's security. Receiving a report does not by itself start the clock, and neither does a vague suspicion you have not yet examined.6 sources · reviewed 2026-07-27Which CSIRT do I report to under the CRA, and how does the ENISA single reporting platform work?Article 14(7) of the Cyber Resilience Act routes every notification to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment in the Union, meaning where decisions about the cybersecurity of its products are predominantly taken. A manufacturer with no establishment in the Union follows a four-step fallback based on authorised representative, importer, distributor, then users. One submission through the ENISA single reporting platform reaches that CSIRT and ENISA simultaneously, and the deadlines run from 11 September 2026.11 sources · reviewed 2026-07-27

Looking for help with the product?

These answers cover the regulation. Product documentation, setup guides and the API reference live at docs.cvdportal.com. For provision-by-provision explanation, see the CRA article guide.