Summary · cheatsheet · manufacturer obligations

MANUFACTURER OBLIGATIONS

Regulation (EU) 2024/2847 · Articles 13 and 14, Annexes I and VII · reporting from 11 Sep 2026, the rest from 11 Dec 2027 · ready to print as PDF

← Back to the CRA guide
Summary · cheatsheet · manufacturer obligations
Regulation (EU) 2024/2847 · Articles 13 and 14, Annexes I and VII · reporting from 11 Sep 2026, the rest from 11 Dec 2027 · ready to print as PDF
Orientation document This document is a simplified, informative overview of the manufacturer obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA), as of 8 August 2026. It is not a binding legal opinion or a complete interpretation of the regulation — the binding text is the one published in the Official Journal, linked in the sources below. CypherOn is a cybersecurity consultancy, not a law firm; for a legal opinion, turn to an attorney registered with the Czech Bar Association.
Role: manufacturer Regulation (EU) 2024/2847 · Articles 13 and 14, Annexes I and VII · reporting from 11 Sep 2026, the rest from 11 Dec 2027 · ready to print as PDF

What the Cyber Resilience Act (CRA) requires of the manufacturer of a product with digital elements. A quick reference for management, product and engineering — not a legal opinion. Every point carries an article or annex number so you can look the binding wording up on EUR-Lex.

Who it applies to

Manufacturer = anyone who develops or manufactures a product, and equally anyone who has it developed for them and offers it under their own name or trade mark, whether for payment or free of charge (Article 3(13)) — so white labelling counts too. An importer or distributor becomes a manufacturer the moment they place the product on the market under their own name or substantially modify it (Article 21; definition in Article 3(30)). Scope: hardware and software whose intended or reasonably foreseeable use includes a data connection (Article 2(1)), including the remote data processing part without which the product would not perform one of its functions (Article 3(2)). Out of scope: pure SaaS, PaaS and IaaS (recital 12 — those fall under NIS2, in the Czech Republic under Act No. 264/2025 Coll.), free and open-source software supplied outside a commercial activity (recital 18) and products covered by sectoral legislation, among them medical devices, vehicles, aviation and defence (Article 2(2) to (7)).

What the manufacturer has to deliver (6 pillars)

1. Security by design — Annex I, Part I

Products go on the market with no known exploitable vulnerabilities and with a secure default configuration that can be restored. Point 2 of Part I holds 13 requirements, (a) to (m): fixability through updates, access and identity control, confidentiality and integrity of data, data minimisation, availability of essential functions, reduced attack surface, security logging, secure deletion and portability of data. Above them sits point 1 — a level of security appropriate to the risks. The binding list is the one in Annex I.

2. Risk assessment — Article 13(2) to (4)

It is produced during planning, design, development, production and maintenance, not retrospectively. It is documented, kept up to date throughout the support period, and it has to show whether and how each requirement of Annex I, Part I, point 2 applies to the product and how it has been implemented (paragraph 3). Where a requirement does not apply, the documentation must carry a justification (paragraph 4).

3. SBOM and vulnerability handling — Annex I, Part II

A machine-readable SBOM covering at the very least the top-level dependencies (point 1). Remediate without delay, ship security updates separately from functionality updates where technically feasible (point 2). Test regularly (point 3), publish information about the vulnerability once the fix is out (point 4). A coordinated vulnerability disclosure policy (point 5), a contact address for reporting (point 6), secure distribution of updates (point 7), disseminated without delay and free of charge (point 8). For third-party components including open source, exercise due diligence and report vulnerabilities to the person maintaining them (Article 13(5) and (6)).

4. Support period — Article 13(8), (9) and (19)

The manufacturer sets it, but it has to reflect how long the product is expected to be in use. Five years is the floor; shorter only where the product is expected to be in use for less. Separately: security updates already issued must remain available for at least 10 years after their release, or for the remainder of the support period if that is longer. The month and year the support ends must be stated clearly at the time of purchase — which makes it a decision to take before the product goes on the market.

5. Category and conformity assessment — Articles 7, 8 and 32

What decides is the core functionality of the product as a whole (Article 7(1)). Default category — internal control, module A. Important, Annex III class I — module A only where harmonised standards, common specifications or a certification at assurance level "substantial" have been applied in full; otherwise module B + C or H, meaning a notified body. Class II — a third party in every case. Critical, Annex IV — the class II regime until the Commission requires a European cybersecurity certificate (Article 8(1), Article 32(4)). Category descriptions: Implementing Regulation (EU) 2025/2392. As of 8 August 2026 no harmonised standard has been cited → the presumption of conformity (Article 27(1)) is not available and class I leads through a notified body.

6. Reporting — Article 14, applicable from 11 Sep 2026

What gets reported is an actively exploited vulnerability in the product (paragraph 1; Article 3(42) — reliable evidence of exploitation, not every CVE you find) and a severe incident having an impact on the security of the product (paragraph 3, criteria in paragraph 5). Addressee: the CSIRT designated as coordinator and ENISA simultaneously, through the single reporting platform under Article 16; which CSIRT is yours follows from your main establishment in the Union (paragraph 7). Deadlines: 24 h early warning from the moment the manufacturer becomes aware (point (a)); 72 h notification describing the product, the nature of the matter and the measures taken (point (b)); a final report within 14 days of a corrective measure becoming available for a vulnerability, within 1 month of the notification for an incident (point (c)). Users are informed by the manufacturer itself (paragraph 8).

How compliance is evidenced — technical documentation (Article 31, Annex VII)

Fines (Article 64)

Three tiers, and in each of them the higher of the two figures applies; turnover means total worldwide annual turnover for the preceding financial year. EUR 15 000 000 or 2.5 % — the essential requirements of Annex I and the obligations under Articles 13 and 14 (paragraph 2). EUR 10 000 000 or 2 % — supply chain roles, the EU declaration of conformity, CE marking, technical documentation, conformity assessment, notified bodies (paragraph 3). EUR 5 000 000 or 1 % — incorrect or misleading information supplied to notified bodies and market surveillance authorities (paragraph 4). Two exemptions (paragraph 10): microenterprises and small enterprises are not fined for a missed 24 h early warning — this does not extend to the 72 h deadline or the final report; open-source software stewards are not fined at all. Market surveillance authorities are designated by the member state (Article 52); the Czech implementing act is, as of 8 August 2026, only a draft from the Ministry of Industry and Trade dated 3 July 2026.

Timeline: what applies from when (Articles 71 and 69)

11 Jun 2026
Chapter IV applies (Articles 35 to 51) — member states designate notifying authorities and notify conformity assessment bodies. Notified body capacity is still being built up.
11 Sep 2026
Article 14 applies. Reporting within 24 h / 72 h, final report within 14 days (vulnerability) or one month (incident). It applies to products already on the market today (Article 69(3)) — so to the whole portfolio, not only to new releases.
11 Dec 2027
The regulation applies in full — conformity assessment, EU declaration of conformity, CE marking, technical documentation under Annex VII. Products placed on the market earlier are subject to the essential requirements only if they are substantially modified after that date (Article 69(2)).
11 Jun 2028
EU type-examination certificates and approval decisions issued for cybersecurity requirements under other Union harmonisation legislation cease to be valid (Article 69(1)).
Ready by 9/2026
An inventory of everything you have on the Union market, with versions, components and an owner — without it you cannot tell within 24 h which products a vulnerability affects. Written criteria for "actively exploited" and "severe incident". A role that holds the deadline outside office hours. Access to the ENISA platform.
Ready by 12/2027
A reasoned, dated classification of the product and the procedure under Article 32 (for classes I and II expect a queue at the notified bodies). A running risk assessment, an SBOM produced by the build, a disclosure policy, the support period and the documentation under Annex VII.

From the overview to a specific product

Role and category first,
documentation after.

Most of the work under the CRA is not writing documents but processes in development and in responding to vulnerabilities. Wondering whether you are a manufacturer, which category your product falls into or how to hold a 24-hour deadline? Write to us and we will go through it on your product.