EU Cyber Resilience Act: Reporting Starts in September
Written and edited by Kaamel Labs
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, is the EU’s horizontal regulatory framework for hardware and software products made available on the market. These “products with digital elements” include finished products as well as components placed on the market separately.
The CRA stresses that users should be able to consider cybersecurity when purchasing and using these products and that providers of products with digital elements should give users sufficient information. It is intended to create the conditions for secure hardware and software development in the EU, strengthen the EU’s cybersecurity strategy, and improve the functioning of the internal market.
The CRA entered into force on 10 December 2024 and will become fully applicable on 11 December 2027. Some provisions apply in 2026: Chapter IV on the notification of conformity assessment bodies applies from 11 June 2026, while the Article 14 reporting obligations apply from 11 September 2026.
01 Key terms
Product with digital elements
A product with digital elements is a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. Its intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
The category is broad. Examples include smart cameras, robot vacuum cleaners, industrial PLC controllers, and commercial software products placed on the market separately. Software does not need to be bundled with a physical device to be covered, but SaaS, PaaS, IaaS offered solely online and ordinary websites are not automatically subject to the CRA. Each case must still be assessed against the specific product form and the definition of a remote data processing solution.
Remote data processing
This means remote data processing designed and developed by the manufacturer, or under its responsibility, where the product would be unable to perform one of its functions without that processing.
The key issue is the relationship between the remote processing and a product function. Not every cloud service that merely makes a product less convenient when disconnected falls within scope. For example, if a smart speaker’s speech recognition model runs entirely in a cloud environment for which the manufacturer is responsible, and the speaker cannot conduct a voice interaction without it, the cloud recognition service may be a remote data processing solution that must be assessed together with the product under the CRA.
Economic operator
This is the collective term for parties with obligations under the CRA, including manufacturers, authorised representatives, importers, and distributors.
Manufacturer
An entity that develops or manufactures a product and markets it under its own name or trademark, whether or not the product is supplied for payment.
Authorised representative
A natural or legal person established in the EU that has received a written mandate from a manufacturer to perform specified tasks on its behalf.
Importer
An entity established in the EU that places on the EU market a product with digital elements manufactured in a third country.
Distributor
An entity in the supply chain, other than the manufacturer or importer, that makes a product available on the EU market.
Consider a smart wristband manufactured in China and sold in Germany:
- The entity that designs and produces the wristband and sells it under its own logo is the manufacturer. It carries the most extensive compliance obligations.
- If the manufacturer is not established in the EU, it may appoint a natural or legal person established in the EU as its authorised representative through a written mandate. The representative may cooperate with EU regulators within the scope of that mandate. Simply opening an office in Berlin or engaging a general compliance service provider does not automatically create an authorised-representative relationship under the CRA.
- A German trading company that buys the wristbands from the manufacturer and first introduces them to the EU market may be the importer and must perform the corresponding checks.
- A local German electronics retailer that buys the products from the importer and sells them to consumers may be a distributor. It must verify matters such as the CE marking, manufacturer and importer details, user instructions, and the support period.
All of these parties may be economic operators under the CRA. Their precise status depends on the actual supply-chain arrangements.
Open-source software steward
This is an important new CRA concept. It means a legal person, other than a manufacturer, that provides sustained and systematic support for the development of specific free and open-source software products and ensures their viability.
A foundation or other legal person that systematically provides infrastructure, maintains repositories, and supports a particular open-source product may meet this definition, but status cannot be inferred from the organisation’s name alone. The CRA requires open-source software stewards to establish a cybersecurity policy and imposes certain reporting, corrective-action, and regulatory cooperation duties.
Notified body
A notified body is an independent organisation designated by a Member State and notified to the European Commission and the other Member States to perform third-party conformity assessment tasks.
Whether an organisation has obtained notified-body status under the CRA should be checked against the European Commission’s NANDO database and formal Member State notifications. It should not be predicted merely from the brand or existing business of a testing and certification organisation.
Conformity assessment
The process of verifying whether a product satisfies the essential cybersecurity requirements in Annex I.
For example, a firewall classified as an important Class II product must, in principle, undergo third-party conformity assessment under the CRA or use an applicable European cybersecurity certification scheme. Only after completing the applicable procedure, compiling the technical documentation, and signing the EU declaration of conformity may the manufacturer affix the CE marking as required. Medical devices and in vitro diagnostic medical devices governed respectively by Regulation (EU) 2017/745 or Regulation (EU) 2017/746 are generally expressly excluded under Article 2 of the CRA and should not be used as generic examples of Class II products.
Placing on the market
The first making available of a product on the EU market.
Making available on the market
Supplying a product for distribution or use in the course of a commercial activity, whether in return for payment or free of charge.
Harmonised standard
A technical standard developed by a European standardisation organisation in response to a standardisation request from the European Commission, with its reference published in the Official Journal of the European Union. Compliance with an applicable harmonised standard can create a presumption of conformity with the CRA requirements it covers.
02 Regulatory enforcement and legal liability
The CRA allows market surveillance authorities to conduct coordinated control actions, or sweeps, on specific products with digital elements or product categories to check compliance and identify infringements. These actions may include inspecting products acquired under a cover identity.
When a Member State market surveillance authority identifies any of the following formal non-compliance issues, it must require the relevant manufacturer to end the non-compliance:
- The CE marking has been affixed in breach of Articles 29 and 30.
- The CE marking has not been affixed.
- The EU declaration of conformity has not been drawn up.
- The EU declaration of conformity has not been drawn up correctly.
- Where applicable, the identification number of the notified body involved in the conformity assessment procedure has not been affixed.
- The technical documentation is unavailable or incomplete.
If the non-compliance continues, the Member State must take appropriate measures to restrict or prohibit the product from being made available on the market or to ensure that it is withdrawn or recalled.
Non-compliance with the essential cybersecurity requirements or the manufacturer obligations in Articles 13 and 14 may result in an administrative fine of up to EUR 15 million or, for an undertaking, 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Non-compliance with the obligations in Articles 18 to 23 concerning authorised representatives, importers, and distributors; Article 28 on the EU declaration of conformity; Article 30(1) to (4) on the CE marking; Article 31(1) to (4) on technical documentation; Article 32(1), (2), and (3) on conformity assessment procedures; Article 33(5) on simplified technical documentation; and Articles 39, 41, 47, 49, and 53 may result in a fine of up to EUR 10 million or, for an undertaking, 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Providing incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities in response to a request may result in a fine of up to EUR 5 million or, for an undertaking, 1% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
03 Main provisions of the Act
Chapter I: General provisions (Articles 1–12)
Chapter I sets out the scope of the Regulation, defines key terms and concepts, and explains how the CRA interacts with other EU legislation.
The CRA framework applies to economic operators placing or making products with digital elements available on the EU market. It establishes essential cybersecurity requirements that manufacturers must satisfy during the design, development, and production of products with digital elements and throughout the period for which the product is expected to be in use.
When a product with digital elements is made available on the market and its intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, it is generally within the CRA’s scope. The exclusions and limitations in Article 2 must still be checked.
Chapter II: Obligations of economic operators and provisions concerning free and open-source software (Articles 13–26)
Manufacturer obligations
The CRA’s main obligations apply to manufacturers. They include the following:
- When designing, developing, and producing a product with digital elements, the manufacturer must ensure that it meets the essential cybersecurity requirements. A cybersecurity risk assessment must guide the measures implemented during product planning, design, development, production, delivery, and maintenance.
- When third-party components are integrated, the manufacturer must exercise due diligence to ensure that they do not compromise the product’s cybersecurity.
- The cybersecurity risk assessment and the standards or other technical measures used to implement the essential requirements must be included in the technical documentation and retained for the statutory period so that market surveillance authorities can inspect them during enforcement activities.
- Before placing a product on the market, the manufacturer must complete the applicable conformity assessment procedure, draw up the EU declaration of conformity, and affix the CE marking.
- The manufacturer must determine a support period during which vulnerabilities in the product and its components are handled effectively. The end date must be stated at least by month and year and disclosed to users clearly and intelligibly at the time of purchase.
- After the product is placed on the market, the manufacturer must report known actively exploited vulnerabilities and severe incidents affecting product security through the Single Reporting Platform. The platform makes the notification available simultaneously to the designated coordinating CSIRT and ENISA. The manufacturer must also comply with the applicable 24-hour early warning, 72-hour notification, and final-report deadlines.
Authorised representative obligations
A manufacturer may appoint an authorised representative by written mandate to perform certain tasks, including retaining the EU declaration of conformity and technical documentation and cooperating with market surveillance authorities within the mandate. Core manufacturer obligations such as product design and risk assessment cannot be transferred wholesale to the authorised representative.
Importer obligations
Importers must ensure that the product complies with the CRA, including by verifying that the manufacturer:
- has complied with the applicable essential cybersecurity requirements and has processes to meet vulnerability-handling obligations;
- has completed the appropriate conformity assessment procedure;
- has prepared the technical documentation;
- has signed the EU declaration of conformity and affixed the CE marking; and
- has provided the required manufacturer details, user information, and instructions.
If an importer considers or has reason to believe that a product with digital elements does not comply with the CRA, it must not place the product on the market until conformity has been restored. If it identifies a vulnerability, it must inform the manufacturer and cooperate with market surveillance authorities to eliminate cybersecurity risks caused by products it has placed on the market.
Distributor obligations
Distributors must verify that a product with digital elements bears the CE marking and that the manufacturer and importer have fulfilled relevant duties, including adding contact details, supplying user information and instructions, and stating the support period.
If a distributor considers or has reason to believe that a product does not comply with the CRA, it must inform the manufacturer and, where applicable, the importer. The distributor must not make the product available until conformity has been restored. It must also report identified vulnerabilities to the manufacturer and cooperate with market surveillance authorities to address the relevant cybersecurity risks.
Open-source software stewards
Open-source software stewards must:
- establish and document in a verifiable manner a cybersecurity policy that promotes secure product development and effective vulnerability handling;
- cooperate with market surveillance authorities and take appropriate corrective action where the CRA is not met; and
- report actively exploited vulnerabilities, severe incidents, and incidents affecting the network and information systems they use for developing free and open-source software products.
The CRA’s administrative-fine rules do not apply to open-source software stewards, but their substantive and regulatory cooperation obligations remain.
Chapter III: Conformity of products with digital elements (Articles 27–34)
Chapter III covers harmonised standards, presumptions of conformity, the EU declaration of conformity, the CE marking, technical documentation, and conformity assessment procedures.
In general, manufacturers may use a self-assessment procedure, known as internal control based on Module A, a third-party conformity assessment procedure involving a notified body, or an applicable European cybersecurity certification scheme.
For an important Class I product, the manufacturer may use self-assessment only when it has fully applied the relevant harmonised standards, common specifications where available, or an applicable European cybersecurity certification scheme. Otherwise, third-party assessment is required.
Important Class II products must, in principle, undergo third-party assessment or use an applicable European cybersecurity certification scheme where feasible. Critical products are also subject to stricter assessment routes. Manufacturers of important Class I or Class II products that qualify as free and open-source software may use the internal control procedure, but they must make the relevant technical documentation publicly available.
Chapter IV: Notification of conformity assessment bodies (Articles 35–51)
To perform conformity assessment procedures under the CRA, Member States must notify the European Commission and the other Member States of the bodies authorised to carry out those assessments.
A conformity assessment body seeking notified-body status must meet the applicable requirements. It must, for example, be established under Member State law and have legal personality, remain independent and impartial in relation to the products it assesses, and employ staff with the necessary technical competence.
By 11 June 2026, Member States must designate the authorities responsible for establishing and carrying out the assessment, designation, and notification procedures for conformity assessment bodies. A Member State may use a national accreditation body to assess an applicant’s competence. Only bodies that meet the applicable requirements may be notified.
After a notification is submitted under Article 43 and no objection is raised, the conformity assessment body may perform third-party assessment tasks within the notified scope. A notified body must apply proportionality, take the size of the undertaking into account, and avoid imposing unnecessary burdens on economic operators.
Chapter V: Market surveillance and enforcement (Articles 52–60)
Each Member State must designate one or more market surveillance authorities responsible for effective enforcement of the CRA.
With support from the European Commission and, where appropriate, CSIRTs and ENISA, market surveillance authorities may provide guidance and advice on CRA implementation to economic operators, including manufacturers. They may also require information, evaluate products, and order corrective action. Where necessary, they may restrict or prohibit sales or require a product to be withdrawn or recalled.
Chapter VI: Delegated powers and committee procedure (Articles 61–62)
Chapter VI authorises the European Commission to supplement the CRA through delegated or implementing acts or to establish uniform conditions for its application.
The Commission has adopted two relevant acts:
- Commission Delegated Regulation (EU) 2025/1535 excludes certain L-category vehicles within the scope of Regulation (EU) No 168/2013 from the CRA. The exclusion does not apply to the specified L1e pedal cycles.
- Commission Implementing Regulation (EU) 2025/2392 provides the technical descriptions for the categories of important and critical products with digital elements listed in Annexes III and IV.
Chapter VII: Confidentiality and penalties (Articles 63–65)
Chapter VII sets out confidentiality rules for parties involved in applying the CRA and the penalties for infringements. Member States establish the specific penalty regimes, subject to the maximum fine tiers and the assessment factors set out in the CRA.
A manufacturer that qualifies as a microenterprise or small enterprise is not subject to CRA administrative fines solely for failing to submit the 24-hour early warning for an actively exploited vulnerability or severe incident on time. This is not an exemption from the 72-hour notification, final report, user notification, or other substantive obligations. The CRA’s administrative-fine rules also do not apply to infringements by open-source software stewards.
Chapter VIII: Transitional and final provisions (Articles 66–71)
The CRA entered into force on 10 December 2024. Its main provisions apply from 11 December 2027. Chapter IV on the notification of conformity assessment bodies applies from 11 June 2026, while the Article 14 reporting obligations apply from 11 September 2026.
Products with digital elements placed on the market before 11 December 2027 are generally subject to the other main CRA obligations only if they undergo a substantial modification from that date. However, Article 14 applies to all in-scope products made available on the EU market, including products placed on the market before 11 December 2027.
Annex I: Essential cybersecurity requirements
Annex I divides the essential cybersecurity requirements into two parts.
Part I concerns the properties of products with digital elements. When placing a product on the market, the manufacturer must ensure that its design, development, and production meet the applicable requirements. These include making the product available with a risk-appropriate level of security, avoiding known exploitable vulnerabilities, using appropriate access controls and data-protection measures, reducing the attack surface, and providing security updates.
Part II concerns vulnerability-handling requirements. After the product is placed on the market and throughout the support period, the manufacturer must ensure that vulnerabilities in the product and its components are handled effectively. This includes identifying and documenting vulnerabilities, performing testing, providing security updates promptly, establishing a coordinated vulnerability disclosure policy, and distributing updates securely.
Annex II: Information and instructions to users
The manufacturer must ensure that the product is accompanied by the legally required information and instructions in a language that users and market surveillance authorities can understand. The material must be clear, intelligible, and legible and must enable the product to be installed, operated, and used securely.
Annexes III and IV: Important and critical products with digital elements
Class I products include identity management systems and privileged access management software and hardware; standalone and embedded browsers; password managers; software that searches for, removes, or quarantines malicious software; products with virtual private network (VPN) functionality; smart-home products with security functionality, including smart locks, surveillance cameras, baby-monitoring systems, and alarm systems; and personal wearable products meeting the specified conditions.
Class II products include hypervisors and container runtime systems that support the virtualised execution of operating systems and similar environments, firewalls, and intrusion detection and prevention systems.
Critical products include hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices, including secure elements. Classification must be based on the product’s core functionality and the technical descriptions in Commission Implementing Regulation (EU) 2025/2392. Integrating a component from one of these categories does not automatically place the entire product in the same category.
Annexes V and VI: EU declaration of conformity and simplified declaration
If the applicable conformity assessment procedure demonstrates that the product complies with the essential cybersecurity requirements, the manufacturer must draw up an EU declaration of conformity. Annexes V and VI specify the required structure for the full and simplified declarations.
Annex VII: Content of the technical documentation
Before placing a product with digital elements on the market, the manufacturer must compile technical documentation and retain it for the required period so it can be inspected by market surveillance authorities. The documentation must cover the product description, design and development, risk assessment, vulnerability-handling processes, applicable standards, testing, and conformity assessment.
Annex VIII: Conformity assessment procedures
Before placing a product with digital elements on the market, the manufacturer must conduct, or have a relevant body conduct, the conformity assessment required by Article 32.
Annex VIII sets out the procedures that may be available under Article 32. They include internal control based on Module A, EU-type examination based on Module B followed by conformity to type based on internal production control under Module C, and conformity assessment based on full quality assurance under Module H.
Kaamel’s approach
Kaamel operates at the forefront of privacy protection and digital compliance. We use technology to help businesses identify and address privacy, security, and product-compliance risks.
The Kaamel AI detection engine draws on major regulatory frameworks and enforcement practice to help businesses identify compliance risks quickly and comprehensively. Kaamel also provides broad privacy and digital compliance solutions that help businesses respond more effectively to regulatory and user requirements in international operations, reduce compliance risks and gaps, and build trust in global markets.

