Resources · CRA
The Cyber Resilience Act, Regulation (EU) 2024/2847, is in force since 10 Dec 2024. Vulnerability reporting starts 11 Sep 2026, the rest from 11 Dec 2027.
Step 1
Most arguments about the CRA are not about technology but about roles. The guide explains who the regulation turns into a manufacturer and what follows from that, the FAQ answers specific situations, and the DevSecOps piece shows how those requirements are met in practice.
The regulation does not ask for documents, it asks for repeatable processes. What SCA, SAST, DAST, secrets scanning and image or IaC scanning actually find, what threat modelling is good for, how an SBOM and VEX come about, what to block in CI/CD and what to merely report. Including how KEV and EPSS feed the decision to report under Article 14.
Open the guide → Guide · 15 min readStaggered dates under Article 71 and the difference between entry into force and application. Who is a manufacturer, what is a product with digital elements, the requirements of Annex I, SBOM, support period, reporting under Article 14 and the state of harmonised standards. Every topic links to the text on EUR-Lex.
Open the guide → FAQ · common questionsCustom-built software, SaaS, open source, hardware with third-party firmware, integration work. What has to be reported from 11 Sep 2026 and what does not, how long the support period must run, whether you can wait for standards and who will enforce the CRA in the Czech Republic.
Open the FAQ →Step 2
Scope and product category decide whether you can run the conformity assessment yourself or need a notified body. Start with the scope calculator.
A handful of questions about data connection, how the product is supplied and your role in the supply chain. The result tells you whether you are a manufacturer, importer, distributor or open-source software steward, and whether the product falls within scope at all.
Run the calculator → ClassificationClassification by the core functionality of the product into the categories of Annex III (class I and II) and Annex IV, with the technical descriptions from Implementing Regulation (EU) 2025/2392. Plus what that means for the conformity assessment procedure under Article 32.
Open the classification → Self-checkA questionnaire against the requirements of Annex I — product properties (Part I) as well as vulnerability handling processes (Part II). The output is a score, the largest gaps and the order in which to close them before the product goes on the market.
Run the check →Step 3
The binding text is the one published in the Official Journal. Our materials add orientation and practical notes; they do not reproduce it.
A structured walk through the articles and annexes with notes for practice, search and an anchored table of contents. Including the follow-up Implementing Regulation 2025/2392 and Delegated Regulation 2026/881.
Open the regulation → ProcedureHow to decide whether you are dealing with an actively exploited vulnerability or a severe incident, the 24 h / 72 h / 14 day and 1 month deadlines, what goes into each report and how to prepare for the ENISA single reporting platform.
Open the procedure → CheatsheetA condensed overview of the obligations under Articles 13 and 14, the contents of the technical documentation under Annex VII and the deadlines. Ready to print to PDF straight from the browser.
Open and download the PDF →Building a product the CRA applies to?
Product threat modelling, secure development reviews, vulnerability management and the inputs for the technical documentation under Annex VII. Write to us — tell us how far you are and what is pressing.