User Tools

Site Tools


kb:cs:cra:overview

00 Overview

The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for hardware and software products made available on the EU market.

For details about the regulation itself, see Regulation (EU) 2024/2847.

1. What is the CRA?

The CRA is a regulation of the European Union that requires manufacturers to ensure that products with digital elements are:

Compliant products generally require an EU Declaration of Conformity and CE marking.

The CRA also establishes reporting obligations for actively exploited vulnerabilities and severe incidents having an impact on product security.


2. Which products does it apply to?

The CRA generally applies to hardware and software products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect logical or physical connection to a device or network. (CRA Article 2(1); Article 3(1), (8)–(10), (23) and (24))

Certain product categories governed by specific EU legislation are excluded or subject to special treatment, including some medical devices, motor vehicles, aviation products and marine equipment. (CRA Article 2(2) and (4)–(8))

Non-monetised free and open-source software is generally not considered placed on the market. A legal person that publishes and systematically supports such software intended for commercial use may nevertheless qualify as an open-source software steward and be subject to Article 24. (CRA Article 2(3); Article 3(48); Recitals 18 and 19)

In plain words

The CRA covers software that is intended to communicate digitally with something else - not only software that connects to the internet.

A “connection” may be:

  • Physical: USB, Ethernet, serial bus, Bluetooth radio, etc.
  • Logical: communication through a software interface, API, IPC mechanism, protocol, driver or similar interface.
  • Direct: the product communicates directly with another device or network.
  • Indirect: communication occurs through another component or as part of a larger connected system.

“Intended purpose or reasonably foreseeable use” prevents manufacturers from avoiding the CRA merely by claiming that connectivity was not the primary purpose. Foreseeable real-world use also counts.

The important word missing from many summaries is data: the CRA concerns a logical or physical data connection. The Commission explains that digitally encoded information must be transmitted and interpreted. A simple electrical on/off signal is not a data connection if it merely triggers or powers a function and does not convey digitally encoded information.

Publishing a non-monetised open-source library does not normally make you its manufacturer. A company that maintains it systematically for downstream commercial use may nevertheless be its open-source software steward.


3. Making a product available on the EU market

A product is made available on the market when it is supplied for distribution or use on the EU market in the course of a commercial activity, whether in return for payment or free of charge. (CRA Article 3(22))

Placing on the market means making an individual product with digital elements available on the EU market for the first time. (CRA Article 3(21))

Depending on the circumstances, making a product available may include:

Software developed and used exclusively within one organisation is generally not made available on the market because it is not supplied to another party for distribution or use. (derived from CRA Article 3(22); see also Recital 15)

In plain words

A product is made available when it is supplied for distribution or use in the EU in a commercial context, whether paid or free. This includes delivering software, a custom application or a complete system to a customer. Internal use within the same legal entity is generally not a supply on the market.

The first such supply is its placing on the market. For standalone software, a completed version is generally placed on the market when first offered; later downloads of the unchanged version retain that placement date.

A one-off or customer-specific product can also be placed on the market. The CRA is not limited to standard products, mass-produced software or products sold through a public catalogue.

Software developed and used entirely within the same legal organisation is generally not made available on the market merely through that internal use. However, supplying it to a customer, another legal entity or as part of a commercially delivered system can bring it within the CRA.

Whether money is charged directly for the product is therefore not decisive. The relevant question is whether the product is supplied in the course of a commercial activity.


4. Which companies does it apply to?

The CRA assigns obligations according to the organisation's role as an economic operator. (CRA Article 3(12); Chapter II)

  • Manufacturers develop, manufacture or have products developed or manufactured and market them under their own name or trademark, whether for payment, monetisation or free of charge. (CRA Article 3(13); Article 13)
  • Importers place products bearing the name or trademark of a manufacturer established outside the EU on the EU market. (CRA Article 3(16); Article 19)
  • Distributors make products available within the supply chain without affecting their properties. (CRA Article 3(17); Article 20)

An importer or distributor becomes subject to the obligations of a manufacturer if it markets a product under its own name or trademark or carries out a substantial modification of a product already placed on the market. (CRA Article 21)

Other persons may also become manufacturers if they substantially modify a product and subsequently make it available on the market. (CRA Article 22)

A system integrator delivering a complete system under its own name can therefore become the manufacturer of that system. (derived from CRA Article 3(13); Article 21; Article 22)

The CRA is not limited to large companies. Microenterprises and SMEs receive specific support measures, but there is no general exemption from the CRA’s product and manufacturer obligations. (CRA Article 3(19); Article 26; Article 33; Article 67)

In plain words

The CRA does not apply only to traditional product manufacturers or large companies. It assigns responsibilities according to the role an organisation has for a particular product.

You are generally the manufacturer if you develop a product - or have it developed - and make it available under your own company name or trademark. This can include:

  • a software company selling or licensing its own software;
  • a consulting company delivering a custom application under its own name;
  • a system integrator delivering a complete machine, test system or other system under its own name; or
  • a company that substantially modifies an existing product and supplies the modified product.

You are an importer if you introduce a product from a manufacturer established outside the EU into the EU market.

You are a distributor if you supply a product from another manufacturer within the EU without changing it substantially - for example, as a reseller.

The role must be determined separately for each product. The same company may therefore be the manufacturer of one product, the distributor of another and the system integrator of a third.

Putting your own name or trademark on somebody else’s product, or substantially modifying it, can make you responsible as its manufacturer.

Company size does not create a general exemption. Microenterprises and SMEs may receive support or simplified measures in specific areas, but they remain subject to the CRA when they act as manufacturers, importers or distributors.


5. Sources of information

The following source hierarchy is recommended:

  1. Legal text: The authoritative and legally binding source.
  2. European Commission guidance: Official implementation guidance and explanations. The Commission is required to issue guidance covering specified CRA topics. (CRA Article 26)
  3. Harmonised standards and common specifications: These can provide a presumption of conformity with the CRA requirements they cover. (CRA Article 27; Article 28)
  4. National market-surveillance authorities: These authorities are responsible for market surveillance and enforcement. (CRA Article 52; Chapter V)
  5. ENISA and national CSIRTs: These bodies are involved in vulnerability and incident reporting and in operating the CRA single reporting platform. (CRA Article 14; Article 15; Article 16; Article 17)

6. Timeline

Date Milestone Legal basis
10 December 2024 The CRA entered into force. CRA Article 71(1)
11 June 2026 Provisions concerning the notification of conformity-assessment bodies started to apply. CRA Article 71(2); Chapter IV
11 September 2026 Reporting obligations for actively exploited vulnerabilities and severe security incidents start to apply. CRA Article 71(2); Article 14
11 December 2027 The remaining CRA obligations become applicable, including product requirements, conformity assessment, technical documentation and CE marking. CRA Article 71(2)

Products placed on the market before 11 December 2027 are generally subject to the remaining CRA requirements only if they undergo a substantial modification from that date. (CRA Article 69(2); definition in Article 3(30))

The reporting obligations in Article 14 also apply to products within the CRA’s scope that were placed on the market before 11 December 2027. (CRA Article 69(3))

Next deadline: 11 September 2026

Manufacturers must be able to report actively exploited vulnerabilities and severe incidents having an impact on product security through the CRA single reporting platform. (CRA Article 14; Article 16; application date in Article 71(2))

kb/cs/cra/overview.txt · Last modified: 2026/07/29 14:38 by joerg.hampel