Summary · cheatsheet · manufacturer obligations
Regulation (EU) 2024/2847 · Articles 13 and 14, Annexes I and VII · reporting from 11 Sep 2026, the rest from 11 Dec 2027 · ready to print as PDF
Manufacturer obligations under the CRA
What the Cyber Resilience Act (CRA) requires of the manufacturer of a product with digital elements. A quick reference for management, product and engineering — not a legal opinion. Every point carries an article or annex number so you can look the binding wording up on EUR-Lex.
Manufacturer = anyone who develops or manufactures a product, and equally anyone who has it developed for them and offers it under their own name or trade mark, whether for payment or free of charge (Article 3(13)) — so white labelling counts too. An importer or distributor becomes a manufacturer the moment they place the product on the market under their own name or substantially modify it (Article 21; definition in Article 3(30)). Scope: hardware and software whose intended or reasonably foreseeable use includes a data connection (Article 2(1)), including the remote data processing part without which the product would not perform one of its functions (Article 3(2)). Out of scope: pure SaaS, PaaS and IaaS (recital 12 — those fall under NIS2, in the Czech Republic under Act No. 264/2025 Coll.), free and open-source software supplied outside a commercial activity (recital 18) and products covered by sectoral legislation, among them medical devices, vehicles, aviation and defence (Article 2(2) to (7)).
Products go on the market with no known exploitable vulnerabilities and with a secure default configuration that can be restored. Point 2 of Part I holds 13 requirements, (a) to (m): fixability through updates, access and identity control, confidentiality and integrity of data, data minimisation, availability of essential functions, reduced attack surface, security logging, secure deletion and portability of data. Above them sits point 1 — a level of security appropriate to the risks. The binding list is the one in Annex I.
It is produced during planning, design, development, production and maintenance, not retrospectively. It is documented, kept up to date throughout the support period, and it has to show whether and how each requirement of Annex I, Part I, point 2 applies to the product and how it has been implemented (paragraph 3). Where a requirement does not apply, the documentation must carry a justification (paragraph 4).
A machine-readable SBOM covering at the very least the top-level dependencies (point 1). Remediate without delay, ship security updates separately from functionality updates where technically feasible (point 2). Test regularly (point 3), publish information about the vulnerability once the fix is out (point 4). A coordinated vulnerability disclosure policy (point 5), a contact address for reporting (point 6), secure distribution of updates (point 7), disseminated without delay and free of charge (point 8). For third-party components including open source, exercise due diligence and report vulnerabilities to the person maintaining them (Article 13(5) and (6)).
The manufacturer sets it, but it has to reflect how long the product is expected to be in use. Five years is the floor; shorter only where the product is expected to be in use for less. Separately: security updates already issued must remain available for at least 10 years after their release, or for the remainder of the support period if that is longer. The month and year the support ends must be stated clearly at the time of purchase — which makes it a decision to take before the product goes on the market.
What decides is the core functionality of the product as a whole (Article 7(1)). Default category — internal control, module A. Important, Annex III class I — module A only where harmonised standards, common specifications or a certification at assurance level "substantial" have been applied in full; otherwise module B + C or H, meaning a notified body. Class II — a third party in every case. Critical, Annex IV — the class II regime until the Commission requires a European cybersecurity certificate (Article 8(1), Article 32(4)). Category descriptions: Implementing Regulation (EU) 2025/2392. As of 8 August 2026 no harmonised standard has been cited → the presumption of conformity (Article 27(1)) is not available and class I leads through a notified body.
What gets reported is an actively exploited vulnerability in the product (paragraph 1; Article 3(42) — reliable evidence of exploitation, not every CVE you find) and a severe incident having an impact on the security of the product (paragraph 3, criteria in paragraph 5). Addressee: the CSIRT designated as coordinator and ENISA simultaneously, through the single reporting platform under Article 16; which CSIRT is yours follows from your main establishment in the Union (paragraph 7). Deadlines: 24 h early warning from the moment the manufacturer becomes aware (point (a)); 72 h notification describing the product, the nature of the matter and the measures taken (point (b)); a final report within 14 days of a corrective measure becoming available for a vulnerability, within 1 month of the notification for an incident (point (c)). Users are informed by the manufacturer itself (paragraph 8).
Three tiers, and in each of them the higher of the two figures applies; turnover means total worldwide annual turnover for the preceding financial year. EUR 15 000 000 or 2.5 % — the essential requirements of Annex I and the obligations under Articles 13 and 14 (paragraph 2). EUR 10 000 000 or 2 % — supply chain roles, the EU declaration of conformity, CE marking, technical documentation, conformity assessment, notified bodies (paragraph 3). EUR 5 000 000 or 1 % — incorrect or misleading information supplied to notified bodies and market surveillance authorities (paragraph 4). Two exemptions (paragraph 10): microenterprises and small enterprises are not fined for a missed 24 h early warning — this does not extend to the 72 h deadline or the final report; open-source software stewards are not fined at all. Market surveillance authorities are designated by the member state (Article 52); the Czech implementing act is, as of 8 August 2026, only a draft from the Ministry of Industry and Trade dated 3 July 2026.
From the overview to a specific product
Most of the work under the CRA is not writing documents but processes in development and in responding to vulnerabilities. Wondering whether you are a manufacturer, which category your product falls into or how to hold a 24-hour deadline? Write to us and we will go through it on your product.