Built to Last

Understanding the European Cyber Resilience Act (CRA)

The Cyber Resilience Act is law. Regulation (EU) 2024/2847 took effect December 10, 2024, applying directly across all EU member states and covering nearly every hardware and software product sold into the EU market. If you make, import, distribute, or buy digital products, obligations are already in motion.

Three key deadlines: conformity assessment body notifications began June 2026; 24-hour vulnerability reporting to national CSIRTs and ENISA starts September 2026 (covering products already on the market); and full enforcement with mandatory CE marking begins December 2027.

This guide answers the ten questions practitioners, legal teams, and buyers are actually asking — each chapter stands on its own.

Read Guide