The practical guide to navigating the CRA for engineering, legal, and product teams
Author: Sal Kimmich, Policy Manager at OpenUK & Member of the Global Cyber Policy Working Group
What Is the European Cyber Resilience Act (CRA)?
The Cyber Resilience Act (Regulation EU 2024/2847) is an EU law enforcing mandatory cybersecurity, vulnerability handling, and CE marking for hardware and software sold in the EU. It shifts legal responsibility for software security back to product manufacturers.
Key CRA Deadlines & Legal Articles
- September 11, 2026 (Article 14): Mandatory reporting for actively exploited vulnerabilities to ENISA & national CSIRTs. Under Article 69(3), this obligation applies retroactively to existing products already on the market.
- December 11, 2027: Full CRA enforcement & mandatory CE marking.
Who Must Comply with the CRA?
- Software & Hardware Manufacturers: Companies creating products with digital elements (PDEs) sold in the EU.
- Authorized representatives, Importers & Distributors: Organizations supplying third-party digital products in the EU market.
- Open Source Stewards & Foundations supporting open source projects.
What You Will Learn in This eBook
- Product Classification: Determine if your product is Default, Important (Class I/II), or Critical.
- Conformity Assessments: Navigate CE marking, self-assessments, and Notified Body audits.
- Open Source Rules: Navigate commercial activity tests, maintainer impacts, and open source steward obligations.
- Security by Design: Implement Annex I security rules, secure defaults, and Software Bill of Materials (SBOM) requirements.
- Vulnerability Disclosure: Build internal engineering workflows for Article 14’s reporting obligations.
- Small Team Framework: A Minimum Viable Documentation strategy for startups operating without internal legal counsel.