European Union
CRA
The Cyber Resilience Act sets essential cybersecurity requirements for products with digital elements sold in the EU, covering secure design and development, vulnerability handling (including a software bill of materials), technical documentation, and mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA.
8 articles
Subject matter
This Regulation lays down rules for making available products with digital elements, essential cybersecurity requirements for their design/development/production and for manufacturers' vulnerability handling processes, and rules on market surveillance and enforcement.
Scope
This Regulation applies to products with digital elements whose intended or reasonably foreseeable use includes a data connection to a device or network, with carve-outs for medical devices, vehicles, aviation-certified products, maritime equipment, spare parts, and national security/defence products.
Definitions
Key definitions including product with digital elements, manufacturer, software bill of materials, vulnerability, actively exploited vulnerability, incident, conformity assessment, and CE marking.
Requirements for products with digital elements
Products with digital elements may only be made available on the market where they meet the essential cybersecurity requirements in Annex I Part I (properly installed/maintained/used as intended, with necessary security updates) and the manufacturer's processes meet Annex I Part II.
Obligations of manufacturers
Manufacturers must design/develop/produce products in accordance with Annex I Part I; conduct and document a cybersecurity risk assessment; exercise due diligence integrating third-party/open-source components; report and remediate vulnerabilities in integrated components; maintain vulnerability handling (incl. SBOM per Part II point 1) for at least a 5-year support period; draw up technical documentation and carry out conformity assessment before placing on the market; and keep records, a single point of contact, and user instructions for at least 10 years.
Software bill of materials (Art. 13(8)/(24), Annex I Part II point 1)
Manufacturers must maintain a software bill of materials covering at least the top-level dependencies of the product, as part of the vulnerability-handling requirements for the support period.
Reporting obligations of manufacturers
Manufacturers must notify any actively exploited vulnerability and any severe incident affecting product security to the CSIRT designated as coordinator and ENISA, via the single reporting platform, within 24 hours (early warning), 72 hours (notification), and a final report within 14 days (vulnerability) or one month (incident).
Technical documentation
The technical documentation must contain all relevant data/details (at least the elements in Annex VII) showing the product and manufacturer's processes comply with the essential cybersecurity requirements. It must be drawn up before the product is placed on the market and kept continuously updated during the support period.
Turn CRA into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial