Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the EU Cyber Resilience Act and when does it apply?
Updated
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is a regulation setting cybersecurity requirements for products with digital elements on the Union market. Article 14 applies from 11 September 2026; full application is 11 December 2027. This page is not legal advice and does not start a clock.
CRA overview, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 1–3, 7–8, 13, 14, 28, 30, 32, 64, 69 and 71, Annexes III and IV, the European Commission's CRA pages (last updated 7 September 2026) and 27 July 2026 guidance (guidance, not the regulation), and ENISA product-security / Single Reporting Platform materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, and not a substitute for counsel.
This is the CRA, not YOUR product class
Audience: a CTO, founder, product, or compliance lead at an organisation that might make products with digital elements available on the Union market. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, or that you must file.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. It is a regulation, directly applicable. It is not NIS2, not DORA, and not GDPR. The NIS2, DORA, GDPR, and CRA Article 14 help pages on this site are different instruments. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 1–3, 7–8, 13, 14, 28, 30, 32, 64, 69 and 71, and Annexes III and IV, are legal requirements only if they apply. Commission CRA pages and the 27 July 2026 Commission guidance are Commission materials — guidance, not the regulation. ENISA product-security and Single Reporting Platform materials are agency guidance, not the regulation. This page quotes which kind of text it is relying on.
- The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope, SaaS-scope, penalties, and readiness-checklist guide is not on this site yet. Naming them is not a link.
- The live Article 14 reporting guide on this site is the CRA Article 14 page under breach reporting. That page is not an unpublished HC4 sibling.
What the CRA is — Articles 1, 2 and 3
Article 1: this Regulation lays down rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products; essential cybersecurity requirements for design, development and production; essential cybersecurity requirements for manufacturers' vulnerability-handling processes; and rules on market surveillance and enforcement. That is the legal requirement.
Article 2(1): this Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network. Articles 2(2)–(7) set exclusions (including certain medical, vehicle, aviation, marine, spare-part, and national-security products). This page does not run those exclusions for YOU.
Article 3 definitions, quoted as the regulation uses them. This page does not apply them to YOU. Last verified 8 September 2026. Not legal advice.
| Term | What Article 3 says | Kind of text | Last verified |
|---|---|---|---|
| Product with digital elements — Article 3(1) | A software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. | Legal requirement — Article 3(1). | 8 September 2026 |
| Remote data processing — Article 3(2) | Data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions. | Legal requirement — Article 3(2). This page does not find that YOUR cloud path is in or out. | 8 September 2026 |
| Manufacturer — Article 3(13) | A natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark. | Legal requirement — Article 3(13). This page does not find that YOU are a manufacturer. | 8 September 2026 |
| Making available on the market — Article 3(22) | The supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity. | Legal requirement — Article 3(22). This page does not find that YOUR supply is that activity. | 8 September 2026 |
| Placing on the market — Article 3(21) | The first making available of a product with digital elements on the Union market. | Legal requirement — Article 3(21). | 8 September 2026 |
| Open-source software steward — Article 3(14) | A legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as open-source software and intended for commercial activities, and that ensures the viability of those products. | Legal requirement — Article 3(14). This page does not classify YOU as a steward. | 8 September 2026 |
| CE marking — Article 3(31) | A marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing. | Legal requirement — Article 3(31). Readiness in this product is not CE marking. | 8 September 2026 |
Phased timeline — Article 71, not YOUR dates
Last verified 8 September 2026 against Article 71 on EUR-Lex. Article 71(1): this Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. Publication was 20 November 2024, so entry into force is 10 December 2024. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Those four dates are not one number. This page does not move them.
Article 69(3): by way of derogation from Article 69(2), the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027. Article 14 reporting is not delayed until full application in December 2027.
As of last verification on 8 September 2026, Article 14's application date is in three days (11 September 2026). Chapter IV notifying-bodies provisions have applied since 11 June 2026. Full essential-requirements / CE / market-surveillance application remains 11 December 2027. This table is not YOUR dates. Not legal advice.
| Date in the regulation | What applies | Kind of text | Last verified |
|---|---|---|---|
| 10 December 2024 | Entry into force — twentieth day following publication in the Official Journal (OJ L 2024/2847, 20.11.2024). | Article 71(1). Legal requirement. | 8 September 2026 |
| 11 June 2026 | Chapter IV — notification of conformity assessment bodies (Articles 35 to 51). | Article 71(2), second subparagraph. Not the Article 14 reporting ladder. | 8 September 2026 |
| 11 September 2026 | Article 14 reporting obligations of manufacturers. | Article 71(2), second subparagraph. Legal requirement. This page does not start that clock. | 8 September 2026 |
| 11 December 2027 | The rest of the Regulation, including essential cybersecurity requirements, CE marking, and market surveillance. | Article 71(2), first subparagraph. | 8 September 2026 |
Product classes — default, important I, important II, critical
The CRA is risk-based. Default products with digital elements, important products in class I and class II (Annex III), and critical products (Annex IV) take different conformity-assessment paths under Article 32. This page does not classify YOUR product. Last verified 8 September 2026. Not legal advice.
- Article 7(1) second sentence: integrating a product that has Annex III core functionality does not in itself render the product in which it is integrated subject to Article 32(2) and (3). This page does not run that integration test for YOU.
- Commission Implementing Regulation (EU) 2025/2392 specifies technical descriptions of important and critical categories. That implementing act is not this overview. This page does not apply it to YOU.
| Class | What the regulation says | What this page does not do | Kind of text |
|---|---|---|---|
| Default products with digital elements | Products in scope that do not have the core functionality of an Annex III or Annex IV category. Article 32(1) lets the manufacturer demonstrate conformity by internal control (module A), EU-type examination, full quality assurance, or, where available and applicable, a European cybersecurity certification scheme. | Does not find that YOUR product is a default product. | Articles 2 and 32(1). Legal requirement only if the CRA applies. |
| Important — class I (Annex III) | Article 7(1): products which have the core functionality of a product category set out in Annex III. Class I examples include identity-management and privileged-access software and hardware, standalone and embedded browsers, password managers, operating systems, routers and switches, and smart-home products with security functionalities. Article 32(2) tightens the path when harmonised standards, common specifications, or a certification scheme at assurance level at least 'substantial' have not been applied. | Does not place YOUR product in class I. Does not treat an example as YOUR product. | Article 7; Annex III class I; Article 32(2). Legal requirement. |
| Important — class II (Annex III) | Annex III class II: hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments; firewalls, intrusion detection and prevention systems; tamper-resistant microprocessors; tamper-resistant microcontrollers. Article 32(3): EU-type examination, full quality assurance, or a certification scheme at assurance level at least 'substantial'. | Does not place YOUR product in class II. | Article 7; Annex III class II; Article 32(3). Legal requirement. |
| Critical (Annex IV) | Article 8 and Annex IV: hardware devices with security boxes; smart-meter gateways and other devices for advanced security purposes, including for secure cryptoprocessing; smartcards or similar devices, including secure elements. Article 32(4): a European cybersecurity certification scheme in accordance with Article 8(1), or, where those conditions are not met, the class II procedures. | Does not place YOUR product in Annex IV. | Article 8; Annex IV; Article 32(4). Legal requirement. |
CE marking — Union harmonisation legislation, not a product score
The CRA is Union harmonisation legislation. Article 28(1): the EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated. Article 28(4): by drawing up the EU declaration of conformity, the manufacturer shall assume responsibility for the compliance of the product with digital elements.
Article 30(1): the CE marking shall be affixed visibly, legibly and indelibly to the product with digital elements. Where that is not possible or not warranted on account of the nature of the product, it shall be affixed to the packaging and to the EU declaration of conformity. For software, the CE marking shall be affixed either to the EU declaration of conformity or on the website accompanying the software product. Article 30(3): the CE marking shall be affixed before the product with digital elements is placed on the market.
Readiness tracking in this product is not CE marking, not an EU declaration of conformity, and not a market-surveillance determination. This product does not affix a CE mark. Last verified 8 September 2026. Not legal advice.
Article 14 — pointer only; this page does not start that clock
Article 14 sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on the actively-exploited track, to the CSIRT designated as coordinator and to ENISA via the single reporting platform. Those three marks are not one number. Article 14 applies from 11 September 2026 (Article 71(2)). Article 69(3) applies those duties to in-scope products placed on the market before 11 December 2027.
This overview does not start that clock. It does not duplicate the live Article 14 reporting guide on this site. That live page is the ladder: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track, and the severe-incident one-month final report. Open it for the stages. This page does not file with a CSIRT or ENISA.
Penalties — Article 64 maxima, not typical fines
Article 64(1): Member States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties provided for shall be effective, proportionate and dissuasive. Article 64(2): non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Article 64(3) sets a lower ceiling (up to EUR 10 000 000 or 2 % of that turnover) for other listed obligations. Article 64(4) sets a further ceiling (up to EUR 5 000 000 or 1 % of that turnover) for incorrect, incomplete or misleading information supplied to notified bodies and market surveillance authorities. Those figures are statutory maxima, not typical fines, and not a prediction. This product does not issue fines. Last verified 8 September 2026. Not legal advice.
Open-source software and SaaS — named, not decided here
Open-source software stewards are a different Article 3(14) class. Article 24 sets a distinct set of duties. This page does not classify YOU as a steward. Commission guidance of 27 July 2026 (guidance, not the regulation) addresses remote data processing and open-source software. It is not a rewrite of Article 71's dates.
This overview does not decide that standalone browser-only SaaS is in or out of the CRA. A dedicated SaaS-scope guide is not on this site yet. Naming it is not a link. Recital 12 discusses cloud services designed and developed outside the responsibility of a manufacturer, and points to NIS2 for in-scope cloud computing services. Recital 12 is a recital, not an operative article.
The in-repo CRA control-set comment says standalone browser-only SaaS is generally out of CRA scope. That sentence is this product's own illustrative readiness mapping, not a legal determination. Counsel applies Articles 2 and 3 to YOUR facts.
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 8 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 1–3, 7–8, 13, 14, 28, 30, 32, 64, 69, 71 and Annexes III–IV | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| European Commission CRA policy page (updated 7 September 2026) and CRA summary page | Commission materials. Guidance, not the regulation. | Does not treat a Commission summary as a substitute for Article 71. |
| Commission guidance of 27 July 2026 (C(2026) 5252) on CRA application | Commission guidance, not the regulation. The Commission page itself calls it non-binding. It addresses remote data processing, substantial modification, support periods, and reporting. | Does not treat that guidance as rewriting 11 September 2026 or 11 December 2027. |
| ENISA product-security pages and Single Reporting Platform materials | Agency guidance on product security and the Article 16 platform. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock. |
How this differs from NIS2, DORA, and GDPR
Do not paste one instrument onto another. The NIS2 incident-reporting guide on this site is Directive (EU) 2022/2555 Article 23. The DORA incident-reporting guide on this site is Regulation (EU) 2022/2554 Articles 18–19. The GDPR breach-notification guide on this site is Articles 33–34. The CRA is Regulation (EU) 2024/2847. Last verified 8 September 2026. Not legal advice.
- NIS2 is a directive on essential and important entities. The CRA is a regulation on products with digital elements made available on the Union market. Filing a NIS2 Article 23 report does not discharge CRA Article 14.
- DORA is a regulation on ICT risk for financial entities. It is not the CRA. Filing a DORA Article 19 notification does not discharge CRA Article 14.
- GDPR is a regulation on personal data. A GDPR Article 33 notice is not a CRA Article 14 notification.
What to do now
As of last verification on 8 September 2026, Article 14 applies from 11 September 2026 — three days from that verification date. Full essential-requirements application remains 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking CRA in an obligation map is not that determination.
- Ask counsel which class, if any, YOUR product has under Annex III or Annex IV. This page does not classify it.
- If counsel says Article 14 may apply, open the live Article 14 reporting guide on this site for the 24-hour / 72-hour / 14-day ladder. This overview does not start that clock.
- Do not treat Commission or ENISA guidance as the regulation. Do not treat this product's CRA control-set as a conformity-assessment file.
- The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope, SaaS-scope, penalties, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The live Article 14 reporting guide on this site is the ladder. The reporting-deadlines page on this site is the statute table of clocks.
- Does the CRA apply? Product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test.
- Which class, if any — default, important class I, important class II, or critical? Annexes III and IV. This page does not place YOUR product.
- Article 14 from 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track. This page does not start that clock.
- Full application from 11 December 2027: essential requirements, EU declaration of conformity, CE marking. Readiness in this product is not CE marking.
- Article 64 maxima are not typical fines. This product does not issue fines.
- Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not compliance, not CE marking, and not a market-surveillance determination. Article 14 rows in that set are the control-side home of the CRA reporting-clock model.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. Marking cra in-scope is not a determination that you are a manufacturer or that a product with digital elements has been made available on the Union market. The cyber risk register lives under Security. It is not an Article 14 file.
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 1–3, 7–8, 13, 14, 28, 30, 32, 64, 69 and 71 and Annexes III and IV, is a legal requirement only if it applies. Entry into force 10 December 2024 (Article 71(1)). Article 14 applies from 11 September 2026; Chapter IV from 11 June 2026; the rest from 11 December 2027 (Article 71(2)). The European Commission's CRA policy page (updated 7 September 2026), CRA summary page, and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. ENISA's product-security pages and Single Reporting Platform materials are agency guidance, not the regulation. Directive (EU) 2022/2555 Article 23 is a different instrument; the NIS2 incident-reporting guide is on this site. Regulation (EU) 2022/2554 Articles 18–19 are a different instrument; the DORA incident-reporting guide is on this site. These are not a complete world list. Not legal advice.
The CRA Article 14 reporting guide on this site is the live ladder. The reporting-deadlines page on this site is the statute table of clocks. The NIS2 incident-reporting guide on this site is Article 23. The DORA incident-reporting guide on this site is Articles 18–19. The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope, SaaS-scope, penalties, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a pillar overview distilled from Regulation (EU) 2024/2847, with Commission and ENISA materials labelled as guidance, not the regulation. Whether the CRA applies to YOUR product is a legal question for counsel on your facts. This page does not start a clock.
Does ShipReady file Article 14 reports?
No. The signed-in app does not file with a CSIRT or ENISA, does not start an Article 14 clock, and does not decide that the CRA applies or that you are a manufacturer. Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. A named human still submits.
Does marking CRA in-scope mean the CRA applies to us?
No. Marking the bundled framework key cra in-scope on the obligation map is not a determination that you are a manufacturer or that a product with digital elements has been made available on the Union market. Counsel applies Articles 2 and 3 to YOUR facts.
Is Article 14 already applicable?
Article 14 applies from 11 September 2026 (Article 71(2)). Last verified 8 September 2026 — three days before that date. This page does not start that clock. The live Article 14 reporting guide on this site is the ladder page.
Does NIS2 discharge the CRA?
No. NIS2 (Directive (EU) 2022/2555) and the CRA (Regulation (EU) 2024/2847) are different instruments. A NIS2 Article 23 filing is not an Article 14 notification. Filing one does not discharge the other.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.