What do I actually have to do to comply with the Cyber Resilience Act?
Also asked
- What are the CRA manufacturer obligations in order?
- Where do I start with CRA compliance?
- What documents does the CRA require me to produce?
- Do I need CE marking for every product with digital elements?
- How long do I have to support a product under the CRA?
Compliance runs as an ordered sequence where each step feeds the next. Confirm the product is in scope and that you are its manufacturer, then classify it as default, Annex III important class I or II, or Annex IV critical. Run the Article 13(2) risk assessment, which determines which Annex I Part I requirements apply. Build to those, meet the Part II vulnerability handling requirements, compile Article 31 technical documentation, complete the Article 32 conformity assessment, draw up the EU declaration of conformity, affix the CE marking, and report under Article 14.
The order matters. The risk assessment sets the scope of everything downstream, and the conformity assessment route depends on the classification settled before it.
At a glance
- Gateway condition
- Article 6, Annex I Part I for the product and Part II for your processes
- What sets the scope
- The Article 13(2) risk assessment
- Where the evidence lives
- Technical documentation, Article 31 and Annex VII
- Support period
- At least five years, or expected use time if shorter (Article 13(8))
- Reporting starts
- 11 September 2026 (Article 14)
- Everything else starts
- 11 December 2027
Last reviewed 27 July 2026
Verified against The final text of Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026
The conformity assessment route for Annex III class I products turns on harmonised standards that are not yet cited in the Official Journal. The Commission guidance on these obligations was adopted on 27 July 2026 as C(2026) 5252 final.
Step 1. Confirm you are in scope, and in which role
Article 6 states the gateway condition. Products with digital elements may be made available on the market only where they meet the Annex I Part I essential cybersecurity requirements, provided they are properly installed, maintained and used for their intended purpose or under reasonably foreseeable conditions, and where the processes put in place by the manufacturer comply with Annex I Part II.[1]
Two checks come before anything else.
Is the product excluded? Article 2 carves out products already covered by sectoral Union law, including medical devices under Regulations (EU) 2017/745 and 2017/746, motor vehicles under Regulation (EU) 2019/2144, civil aviation under Regulation (EU) 2018/1139 and marine equipment under Directive 2014/90/EU.[2]
Are you the manufacturer? The obligations in this answer are Article 13 manufacturer obligations. Importers carry Article 19 duties and distributors Article 20 duties, which are verification rather than construction obligations. Article 21 pulls an importer or distributor into the manufacturer's shoes where they place a product on the market under their own name or trademark, and Article 22 does the same in other cases including substantial modification.[7]
Free and open source software supplied outside a commercial activity sits outside scope, and open-source software stewards fall under the lighter Article 24 regime instead of Article 13.
Step 2. Classify the product
Classification decides the conformity assessment route later, so it is settled early even though nothing is produced at this stage.
There are four tiers.
- Default. Any product with digital elements not listed elsewhere. Self-assessment is available.
- Important, Annex III class I, under Article 7.
- Important, Annex III class II, under Article 7.
- Critical, Annex IV, under Article 8, where the Commission is empowered to require a European cybersecurity certification scheme.[3][4]
The practical effect appears at Article 32. A class I product may use self-assessment only where harmonised standards, common specifications or a certification scheme have been fully applied. Otherwise it escalates to third-party assessment. A class II product goes to third-party assessment regardless.[12]
Since no CRA harmonised standard has been cited in the Official Journal, the escalation limb currently bites for class I products. The EN 40000 timing question covers what that means for budget and scheduling.
An implementing act adopted on 28 November 2025 sets out technical descriptions of the Annex III and Annex IV categories. That is the document to read when a product sits near a boundary.[18]
Step 3. Run the risk assessment, because it scopes everything after it
Article 13(2) requires an assessment of the cybersecurity risks associated with the product, whose outcome is taken into account during planning, design, development, production, delivery and maintenance.[5]
This is the pivot of the whole sequence. Annex I Part I point (2) opens with the words "On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable", so the security requirements listed there are conditional, and the assessment is what establishes which apply.[16] Article 13(4) then requires a clear justification in the technical documentation for every essential requirement treated as not applicable.[5]
Article 13(3) sets the minimum content and requires the assessment to be documented and updated as appropriate across the support period. It also has to indicate how the manufacturer applies Annex I Part I point (1) and the Part II vulnerability handling requirements.[5]
Running this step late is the most expensive sequencing error available, because a requirement discovered as applicable after design is frozen is a redesign rather than a document change. The full risk assessment requirements go through it provision by provision.
Step 4. Build to Annex I, both parts
Annex I has two halves and they are commonly treated as one.
Part I is about the product. Point (1) requires products to be designed, developed and produced so as to ensure an appropriate level of cybersecurity based on the risks. Point (2) lists the specific security properties, applicable on the basis of the risk assessment, running from (a) to (m) and covering release without known exploitable vulnerabilities, secure by default configuration, security updates, access protection, confidentiality and integrity of data, data minimisation, availability, attack surface reduction, exploitation mitigation, logging and monitoring, and secure removal of data.[16]
Part II is about your processes, and it applies whatever the risk assessment says. It requires identifying and documenting vulnerabilities and components including an SBOM covering at least top-level dependencies, remediating without delay through security updates, applying effective and regular testing, publicly disclosing fixed vulnerabilities with descriptions and remediation information, putting a coordinated vulnerability disclosure policy in place, providing a contact address for reporting, and distributing security updates without delay and free of charge.[16]
Part II is where a coordinated vulnerability disclosure capability stops being good practice and becomes a legal requirement, and it is the part with the longest lead time to build.
Step 5. Compile the technical documentation
Article 31 requires technical documentation containing all relevant data and details of the means used to demonstrate conformity with the essential requirements, drawn up before the product is placed on the market and kept up to date. Its elements are set out in Annex VII.[11]
Article 13(4) requires the cybersecurity risk assessment to be included in it, along with a clear justification wherever an essential requirement is treated as not applicable.[5]
Annex II is separate and often confused with it. That is the information and instructions supplied to the user, and it includes the manufacturer's contact details, the single point of contact for vulnerability reports and where the CVD policy can be found, the intended purpose and security properties, any known or foreseeable circumstance related to intended use or reasonably foreseeable misuse that may lead to significant cybersecurity risks, the technical security support offered, and the end date of the support period.[17]
Microenterprises and small enterprises get relief on form rather than substance. Article 33(5) allows them to provide all Annex VII elements using a simplified format specified by the Commission, and notified bodies must accept it.[13]
Step 6. Conformity assessment, declaration, CE marking
Article 32(1) offers four routes: internal control based on module A, EU-type examination based on module B followed by conformity to type based on module C, full quality assurance based on module H, or a European cybersecurity certification scheme under Article 27(9) where available and applicable. Which are open to you was decided by the classification in step 2.[12]
Article 28 then requires the manufacturer to draw up the EU declaration of conformity, stating that fulfilment of the applicable Annex I essential requirements has been demonstrated. It follows the model structure in Annex V, contains the elements specified in the relevant Annex VIII procedure, and is updated as appropriate.[8]
CE marking comes last. Article 29 applies the general principles of the CE marking, and Article 30 sets the rules and conditions for affixing it.[9][10]
The order is load-bearing. The CE marking asserts that the preceding steps happened, so affixing it before the documentation and the declaration exist is the failure mode market surveillance authorities are equipped to detect.
Step 7. The obligations that begin when you ship
Compliance is not discharged at placing on the market. Three duties run afterwards.
The support period. Article 13(8) requires the manufacturer to determine it so that it reflects how long the product is expected to be in use, taking into account reasonable user expectations, the nature and intended purpose of the product, and relevant Union law. It carries a floor: the support period shall be at least five years, and where the product is expected to be in use for less than five years, it corresponds to the expected use time.[5]
Vulnerability handling. The Annex I Part II process obligations run across that whole period, including remediation through security updates and public disclosure of fixed vulnerabilities.[16]
Reporting. Article 14 requires notification of actively exploited vulnerabilities and severe incidents to a coordinating CSIRT and ENISA through the single reporting platform, on a 24 hour, 72 hour and final report cadence, plus a separate duty under Article 14(8) to inform impacted users.[6] The CSIRT routing and platform mechanics work through the operational side.
What is due when
Article 71(2) splits the calendar three ways. Chapter IV, Articles 35 to 51 on notifying conformity assessment bodies, applies from 11 June 2026. Article 14 reporting applies from 11 September 2026. Everything else applies from 11 December 2027.[15]
The sequencing consequence is that reporting arrives first, roughly 15 months ahead of the design and conformity obligations, and it reaches further. Article 69(2) generally exempts products placed on the market before 11 December 2027 unless they are substantially modified, and Article 69(3) derogates from that specifically for Article 14.[14]
So an existing product line needs a working reporting capability well before it needs a technical file. Building steps 1 to 6 in order remains right for anything new, and step 7's reporting duty is the one with the nearest deadline.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 6, points (a) and (b) · CELEX:32024R2847 · OJ L, 20.11.2024
“Products with digital elements shall be made available on the market only where they meet the essential cybersecurity requirements”
Accessed 2026-07-27
- [2]
Publications Office of the European Union · Article 2(2) to (7) · CELEX:32024R2847
Accessed 2026-07-27
- [3]
Publications Office of the European Union · Article 7, with Annex III · CELEX:32024R2847
Accessed 2026-07-27
- [4]
Publications Office of the European Union · Article 8, with Annex IV · CELEX:32024R2847
Accessed 2026-07-27
- [5]
Publications Office of the European Union · Article 13(2), (3), (4) and (8) · CELEX:32024R2847
“Without prejudice to the second subparagraph, the support period shall be at least five years”
Accessed 2026-07-27
- [6]
Publications Office of the European Union · Article 14(1) to (8) · CELEX:32024R2847
Accessed 2026-07-27
- [7]
Publications Office of the European Union · Articles 19, 20, 21 and 22 · CELEX:32024R2847
Accessed 2026-07-27
- [8]
Publications Office of the European Union · Article 28(1) and (2), with Annex V · CELEX:32024R2847
“state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated”
Accessed 2026-07-27
- [9]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 29 (General principles of the CE marking)Binding
Publications Office of the European Union · Article 29 · CELEX:32024R2847
Accessed 2026-07-27
- [10]
Publications Office of the European Union · Article 30 · CELEX:32024R2847
Accessed 2026-07-27
- [11]
Publications Office of the European Union · Article 31, with Annex VII · CELEX:32024R2847
Accessed 2026-07-27
- [12]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 32 (Conformity assessment procedures)Binding
Publications Office of the European Union · Article 32(1), (2) and (3) · CELEX:32024R2847
Accessed 2026-07-27
- [13]
Publications Office of the European Union · Article 33(5) · CELEX:32024R2847
Accessed 2026-07-27
- [14]
Publications Office of the European Union · Article 69(2) and (3) · CELEX:32024R2847
Accessed 2026-07-27
- [15]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71 (Entry into force and application)Binding
Publications Office of the European Union · Article 71(2) · CELEX:32024R2847
“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026”
Accessed 2026-07-27
- [16]Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I (Essential cybersecurity requirements)Binding
Publications Office of the European Union · Annex I, Parts I and II · CELEX:32024R2847
“On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall”
Accessed 2026-07-27
- [17]
Publications Office of the European Union · Annex II, points 1 to 7 · CELEX:32024R2847
Accessed 2026-07-27
- [18]
European Commission · Technical descriptions of Annex III and Annex IV categories · Implementing Regulation (EU) 2025/2392
Accessed 2026-07-27
Follow-up questions
Does every product with digital elements need CE marking under the CRA?+
Every product within scope that is placed on the market does, since the CE marking indicates conformity with the Regulation under Articles 29 and 30. What differs by classification is the route to it. A default product can reach it by self-assessment, while an Annex III class II product requires third-party assessment.
Can I self-assess, or do I need a notified body?+
Default products can use internal control based on module A. Annex III class I products can too, but only where harmonised standards, common specifications or a certification scheme have been fully applied. Since none is cited in the Official Journal yet, class I products currently escalate to third-party assessment under Article 32(2). Class II products always require it.
What is the minimum support period?+
Article 13(8) sets a floor of five years, unless the product is expected to be in use for less than five years, in which case the support period matches the expected use time. Where a product is reasonably expected to be in use longer, the determination has to reflect that, so five years is a floor rather than a default.
Do I need an SBOM?+
Yes, for products within scope. Annex I Part II requires manufacturers to identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used machine-readable format covering at the very least the top-level dependencies of the product.
We only assemble and rebrand someone else's product. Are we the manufacturer?+
Very likely yes. Article 21 applies the manufacturer's obligations to an importer or distributor that places a product on the market under its own name or trademark. Article 22 extends them in other cases, including where a substantial modification is made to a product already on the market.
The provisions behind this answer
Terms used in this answer
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.