New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

European Union

CRA

The Cyber Resilience Act sets essential cybersecurity requirements for products with digital elements sold in the EU, covering secure design and development, vulnerability handling (including a software bill of materials), technical documentation, and mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA.

8 articles

Article 1

Subject matter

This Regulation lays down rules for making available products with digital elements, essential cybersecurity requirements for their design/development/production and for manufacturers' vulnerability handling processes, and rules on market surveillance and enforcement.

Article 2

Scope

This Regulation applies to products with digital elements whose intended or reasonably foreseeable use includes a data connection to a device or network, with carve-outs for medical devices, vehicles, aviation-certified products, maritime equipment, spare parts, and national security/defence products.

Article 3

Definitions

Key definitions including product with digital elements, manufacturer, software bill of materials, vulnerability, actively exploited vulnerability, incident, conformity assessment, and CE marking.

Article 6

Requirements for products with digital elements

Products with digital elements may only be made available on the market where they meet the essential cybersecurity requirements in Annex I Part I (properly installed/maintained/used as intended, with necessary security updates) and the manufacturer's processes meet Annex I Part II.

Article 13

Obligations of manufacturers

Manufacturers must design/develop/produce products in accordance with Annex I Part I; conduct and document a cybersecurity risk assessment; exercise due diligence integrating third-party/open-source components; report and remediate vulnerabilities in integrated components; maintain vulnerability handling (incl. SBOM per Part II point 1) for at least a 5-year support period; draw up technical documentation and carry out conformity assessment before placing on the market; and keep records, a single point of contact, and user instructions for at least 10 years.

Article 13

Software bill of materials (Art. 13(8)/(24), Annex I Part II point 1)

Manufacturers must maintain a software bill of materials covering at least the top-level dependencies of the product, as part of the vulnerability-handling requirements for the support period.

Article 14

Reporting obligations of manufacturers

Manufacturers must notify any actively exploited vulnerability and any severe incident affecting product security to the CSIRT designated as coordinator and ENISA, via the single reporting platform, within 24 hours (early warning), 72 hours (notification), and a final report within 14 days (vulnerability) or one month (incident).

Article 31

Technical documentation

The technical documentation must contain all relevant data/details (at least the elements in Annex VII) showing the product and manufacturer's processes comply with the essential cybersecurity requirements. It must be drawn up before the product is placed on the market and kept continuously updated during the support period.

Turn CRA into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial