Cyber Resilience Act FAQ
Long-form answers to the questions EU manufacturers actually ask about Regulation (EU) 2024/2847. Every claim carries a pinpoint citation, and every source is marked as binding law or as interpretive guidance.
10 questions107 cited sources4 categories
Scope and applicability
Does the CRA cover my web application?Generally no. Commission guidance confirms that software which executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. A web application reached exclusively through a browser therefore falls outside the CRA, as does a website that only presents information. Two things pull you back in. Shipping a client that users install and run locally is in scope, even where it is built with web technologies. And your backend enters scope where it supports a function of some other product.6 sources · reviewed 2026-07-27Does the EU Cyber Resilience Act apply to open source software?The Cyber Resilience Act (Regulation (EU) 2024/2847) covers free and open source software only where it is supplied for distribution or use in the course of a commercial activity. Software its manufacturer does not monetise stays outside the scope. A paid or enterprise edition is placed on the market and carries the full manufacturer obligations. Legal persons who sustain a project intended for commercial use fall under the lighter steward regime in Article 24, which carries no CE marking and no administrative fines.13 sources · reviewed 2026-07-27
Conformity and CE marking
Do I have to wait for the EN 40000 standards before I can comply with the CRA?Waiting is the wrong plan. No part of the EN 40000 series has been cited in the Official Journal, so the Article 27 presumption of conformity is unavailable, and Article 32(2) escalates a Class I important product to third-party assessment precisely where a manufacturer has not applied a harmonised standard or where none exists. Compliance is owed from 11 December 2027 whatever the standards do. The series is drafted under Commission standardisation request M/606, with parts 1-1, 1-2 and 1-3 past public enquiry and awaiting approval.11 sources · reviewed 2026-07-27Is my software update a substantial modification under the CRA?Ask four questions from Commission guidance point 110. Does the update introduce new threat vectors, enable new attack scenarios, change the likelihood of previously identified attack scenarios, or change their impact? Where all four are negative and the assumptions in your risk assessment still hold, the update is unlikely to be substantial. Any single yes makes it substantial, as does a change to the intended purpose the product was assessed against. The size of the change is irrelevant.5 sources · reviewed 2026-07-27
Obligations in practice
What do I actually have to do to comply with the Cyber Resilience Act?Compliance runs as an ordered sequence where each step feeds the next. Confirm the product is in scope and that you are its manufacturer, then classify it as default, Annex III important class I or II, or Annex IV critical. Run the Article 13(2) risk assessment, which determines which Annex I Part I requirements apply. Build to those, meet the Part II vulnerability handling requirements, compile Article 31 technical documentation, complete the Article 32 conformity assessment, draw up the EU declaration of conformity, affix the CE marking, and report under Article 14.18 sources · reviewed 2026-07-27What documents and reports does the Cyber Resilience Act require me to produce?The Cyber Resilience Act requires six artefacts. Technical documentation under Article 31 and Annex VII, which contains the risk assessment. An EU declaration of conformity under Article 28 and Annex V. A software bill of materials and a coordinated vulnerability disclosure policy, both under Annex I Part II. Information and instructions to the user under Annex II. Then the Article 14 filings once reporting begins. Technical documentation and the declaration are kept available to market surveillance authorities for at least 10 years or the support period, whichever is longer.12 sources · reviewed 2026-07-27What does the Cyber Resilience Act require in a cybersecurity risk assessment?Article 13(2) of the Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers to assess the cybersecurity risks of a product with digital elements and to carry the outcome through the planning, design, development, production, delivery and maintenance phases. Article 13(3) requires that assessment to be documented, kept updated across the support period, and to state which Annex I Part I point 2 requirements apply and how they are met. It forms part of the technical documentation under Article 31 and Annex VII, and the duty applies from 11 December 2027.14 sources · reviewed 2026-07-27
Reporting and vulnerability handling
Do I have to report the same incident under the CRA, NIS2 and GDPR?One event can trigger all three, and none of them excuses the others. CRA Article 14 binds the manufacturer when a vulnerability in its product is actively exploited or a severe incident affects product security, filed to a coordinating CSIRT and ENISA. NIS2 Article 23 binds essential and important entities when a significant incident disrupts their own services. GDPR Article 33 binds the controller within 72 hours of a personal data breach. The triggers, the subjects and the recipients differ, so the filings run in parallel.11 sources · reviewed 2026-07-27When does the CRA reporting clock start?The clock starts when you become aware, and Commission guidance now defines that moment. On detecting a suspicious event or receiving a report from a researcher, customer or authority, assess it immediately. You become aware once that initial assessment gives you a reasonable degree of certainty that a vulnerability in your product is being actively exploited, or that a severe incident has compromised your product's security. Receiving a report does not by itself start the clock, and neither does a vague suspicion you have not yet examined.6 sources · reviewed 2026-07-27Which CSIRT do I report to under the CRA, and how does the ENISA single reporting platform work?Article 14(7) of the Cyber Resilience Act routes every notification to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment in the Union, meaning where decisions about the cybersecurity of its products are predominantly taken. A manufacturer with no establishment in the Union follows a four-step fallback based on authorised representative, importer, distributor, then users. One submission through the ENISA single reporting platform reaches that CSIRT and ENISA simultaneously, and the deadlines run from 11 September 2026.11 sources · reviewed 2026-07-27
Looking for help with the product?
These answers cover the regulation. Product documentation, setup guides and the API reference live at docs.cvdportal.com. For provision-by-provision explanation, see the CRA article guide.