Resources · CRA

CYBER RESILIENCE ACT

The Cyber Resilience Act, Regulation (EU) 2024/2847, is in force since 10 Dec 2024. Vulnerability reporting starts 11 Sep 2026, the rest from 11 Dec 2027.

Step 1

Find out whether the CRA makes you a manufacturer

Most arguments about the CRA are not about technology but about roles. The guide explains who the regulation turns into a manufacturer and what follows from that, the FAQ answers specific situations, and the DevSecOps piece shows how those requirements are met in practice.

Guide · 18 min read

What DevSecOps is and why the CRA requires it

The regulation does not ask for documents, it asks for repeatable processes. What SCA, SAST, DAST, secrets scanning and image or IaC scanning actually find, what threat modelling is good for, how an SBOM and VEX come about, what to block in CI/CD and what to merely report. Including how KEV and EPSS feed the decision to report under Article 14.

Open the guide →
Guide · 15 min read

Guide to the CRA

Staggered dates under Article 71 and the difference between entry into force and application. Who is a manufacturer, what is a product with digital elements, the requirements of Annex I, SBOM, support period, reporting under Article 14 and the state of harmonised standards. Every topic links to the text on EUR-Lex.

Open the guide →
FAQ · common questions

FAQ on the Cyber Resilience Act

Custom-built software, SaaS, open source, hardware with third-party firmware, integration work. What has to be reported from 11 Sep 2026 and what does not, how long the support period must run, whether you can wait for standards and who will enforce the CRA in the Czech Republic.

Open the FAQ →

Step 2

Check a specific product

Scope and product category decide whether you can run the conformity assessment yourself or need a notified body. Start with the scope calculator.

Calculator

Does the CRA apply to your product?

A handful of questions about data connection, how the product is supplied and your role in the supply chain. The result tells you whether you are a manufacturer, importer, distributor or open-source software steward, and whether the product falls within scope at all.

Run the calculator →
Classification

Default, important or critical product?

Classification by the core functionality of the product into the categories of Annex III (class I and II) and Annex IV, with the technical descriptions from Implementing Regulation (EU) 2025/2392. Plus what that means for the conformity assessment procedure under Article 32.

Open the classification →
Self-check

How far you are from Annex I

A questionnaire against the requirements of Annex I — product properties (Part I) as well as vulnerability handling processes (Part II). The output is a score, the largest gaps and the order in which to close them before the product goes on the market.

Run the check →

Step 3

Legal texts and reporting materials

The binding text is the one published in the Official Journal. Our materials add orientation and practical notes; they do not reproduce it.

Regulation

Regulation (EU) 2024/2847 interactive

A structured walk through the articles and annexes with notes for practice, search and an anchored table of contents. Including the follow-up Implementing Regulation 2025/2392 and Delegated Regulation 2026/881.

Open the regulation →
Procedure

Reporting under Article 14 step by step

How to decide whether you are dealing with an actively exploited vulnerability or a severe incident, the 24 h / 72 h / 14 day and 1 month deadlines, what goes into each report and how to prepare for the ENISA single reporting platform.

Open the procedure →
Cheatsheet

Manufacturer obligations in brief

A condensed overview of the obligations under Articles 13 and 14, the contents of the technical documentation under Annex VII and the deadlines. Ready to print to PDF straight from the browser.

Open and download the PDF →
Content valid as of 8 August 2026

Building a product the CRA applies to?

Annex I requirements go
into development,
not into documents.

Product threat modelling, secure development reviews, vulnerability management and the inputs for the technical documentation under Annex VII. Write to us — tell us how far you are and what is pressing.