REGULATION (EU) 2024/2847
From 11 December 2027, a product with digital elements that does not meet the CRA cannot be sold in the EU.
The CRA is the EU's horizontal, mandatory cybersecurity regulation for products with digital elements. It covers design, development, production, vulnerability handling, updates and market surveillance. This page turns the legal text into what a manufacturer actually has to do, with the article reference for every statement.
Regulation (EU) 2024/2847 — the Cyber Resilience Act, the EU's first horizontal, mandatory product cybersecurity regulation.
It applies to all products with digital elements — any software or hardware product whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Sector does not matter; the digital element does. (Art. 2(1), Art. 3(1))
One test before shipping is not enough. Secure design, risk assessment, SBOM and security testing come first; vulnerability handling, security updates, reporting and end of life follow after the product is on the market. (Art. 13, Annex I Part II)
The manufacturer carries the heaviest load (Art. 13, 14); importers and distributors have verification duties; a manufacturer outside the EU must appoint an authorised representative inside the EU (Art. 18).
Pass conformity assessment, hold the technical documentation (Annex VII) and sign the EU declaration of conformity (Annex V) before affixing the CE marking. (Art. 28-32)
The cap is the higher of a fixed amount or a percentage of total worldwide annual turnover.
| Non-compliance with the Annex I essential requirements or the Art. 13 / Art. 14 manufacturer obligations | EUR 15,000,000 or 2.5% of worldwide annual turnover | Art. 64(2) |
| Non-compliance with other obligations (authorised representative, importer, distributor, DoC, CE marking, technical documentation, assessment procedures) | EUR 10,000,000 or 2% of worldwide annual turnover | Art. 64(3) |
| Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities | EUR 5,000,000 or 1% of worldwide annual turnover | Art. 64(4) |
Member States set the actual amount, taking into account the nature, gravity and duration of the infringement (Art. 64(5)).
Statutory dates come from Art. 71(2). Items marked “planned” are expected standardisation milestones, not legal dates.
Signed by the European Parliament and the Council in Strasbourg.
Published in the Official Journal of the European Union.
The twentieth day following publication.
Chapter IV (Art. 35-51) applies. Member States may designate notified bodies and manufacturers can start applying.
Article 14 applies early: actively exploited vulnerabilities and severe incidents must be notified to the CSIRT and ENISA.
The EN 40000 horizontal series and the ETSI EN 304-6xx vertical standards are mostly mature drafts and are expected to be finalised by the end of 2026.
All manufacturer, importer and distributor obligations apply. Products placed on the market after this date must comply.
Radio products are covered by the RED cybersecurity requirements today; the CRA takes over on 11 December 2027.
Delegated Regulation (EU) 2022/30 is repealed by Delegated Regulation (EU) 2026/339 with effect from 11 December 2027, dovetailing with full CRA application. Radio equipment placed on the market between 1 Aug 2025 and 10 Dec 2027 remains subject to RED 3.3(d)(e)(f) market surveillance, so keep the records.
Scope and exclusions are all in Article 2; Article 3 contains the definitions.
| Product category | In scope? | Legal basis | Notes |
|---|---|---|---|
| Products with digital elements | In scope | Art. 2(1) | Any hardware or software product whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network — IoT devices, smartphones, computer systems, applications, embedded software. |
| Medical devices | Out of scope | Art. 2(2)(a) | Covered by Regulation (EU) 2017/745. |
| In vitro diagnostic medical devices | Out of scope | Art. 2(2)(b) | Covered by Regulation (EU) 2017/746. |
| Motor vehicles and type-approved systems | Out of scope | Art. 2(2)(c) | Covered by Regulation (EU) 2019/2144 — ADAS, in-vehicle communication systems. |
| Aviation products | Out of scope | Art. 2(3) | Certified in accordance with Regulation (EU) 2018/1139 (EASA). |
| Marine equipment | Out of scope | Art. 2(4) | Within the scope of Directive 2014/90/EU — shipborne navigation and safety communication equipment. |
| Products under other sectoral EU law | May be limited or excluded | Art. 2(5) | Where other Union rules address all or some of the Annex I risks at the same or a higher level of protection, the Commission may limit or exclude application by delegated act. |
| Spare parts | Out of scope | Art. 2(6) | Placed on the market to replace identical components and manufactured to the same specifications. |
| Defence and classified-information products | Out of scope | Art. 2(7) | Developed or modified exclusively for national security or defence, or specifically designed to process classified information. |
| National security information | Cannot be required | Art. 2(8) | Obligations under the Regulation shall not entail supplying information whose disclosure would be contrary to essential national security, public security or defence interests. |
Being out of CRA scope rarely means no cybersecurity duty — it usually means another sectoral regulation applies instead.
The class determines the conformity route: the higher the class, the deeper third-party involvement goes. The lists are in Annex III and Annex IV; the technical description is in Commission Implementing Regulation (EU) 2025/2392.
Anything not listed in Annex III or Annex IV — where the large majority of products land.
Self-assessment (Module A) allowed
Higher risk, but self-assessment remains possible under conditions.
Self-assessment only if harmonised standards are fully applied
Higher risk again; a notified body is always involved.
Module B+C or H, or European cybersecurity certification
Highest risk; a European cybersecurity certification scheme takes priority.
European cybersecurity certification scheme (Art. 8(1))
Classification follows product function, not industry. Two products from the same company can fall into different classes — assess model by model.
The procedures are in Art. 32; the modules themselves are in Annex VIII (Part I = Module A, Part II = B, Part III = C, Part IV = H).
| Product class | Available procedure | Module | Notes |
|---|---|---|---|
| Default | Internal control (self-assessment) | Module A | The manufacturer verifies conformity with Annex I and keeps the technical documentation. No notified body. Art. 32(1)(a) |
| EU-type examination + conformity to type | Module B + C | A notified body examines the sample and the documentation. Art. 32(1)(b) | |
| Full quality assurance | Module H | For manufacturers with a quality management system; approved by a notified body. Art. 32(1)(c) | |
| European cybersecurity certification scheme | EU certification | Where available and applicable, it can replace the modules above. Art. 32(1)(d), Art. 27(9) | |
| Important — Class I | Harmonised standards fully applied → self-assessment | Module A | Where harmonised standards, common specifications or an EU certification scheme at assurance level at least substantial are fully applied. Art. 32(2) |
| Not applied, only partly applied, or no standards exist | Module B + C or H | A notified body procedure becomes mandatory for those essential requirements. Art. 32(2)(a)(b) | |
| Important — Class II | EU-type examination + conformity to type | Module B + C | A notified body is always required. Art. 32(3)(a) |
| Full quality assurance | Module H | Quality system approved by a notified body. Art. 32(3)(b) | |
| European cybersecurity certification (at least substantial) | EU certification | Assurance level per Regulation (EU) 2019/881. Art. 32(3)(c) | |
| Critical | European cybersecurity certification scheme | Art. 8(1) | Takes priority; the Commission may require certification by delegated act. Art. 32(4)(a) |
| Where Art. 8(1) conditions are not met → Class II routes | Module B + C or H | Fallback when no scheme is available. Art. 32(4)(b) | |
| Free and open-source software | Any of the Default procedures | Module A / B+C / H | FOSS manufacturers of products in the Annex III categories may use the Art. 32(1) procedures provided the documentation conditions are met. Art. 32(5) |
The CRA spreads security work across every phase of the product life, instead of concentrating it in one pre-shipment test.
Applies from 11 September 2026. Notifications go simultaneously to the designated coordinator CSIRT and to ENISA, via the single reporting platform established under Art. 16.
An incident is severe where it negatively affects, or is capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or where it has led or is capable of leading to the introduction or execution of malicious code in the product or in the user's network and information systems (Art. 14(5)).
Applying a harmonised standard gives presumption of conformity with Annex I (Art. 27). Horizontal standards set generic requirements; vertical standards refine them per product category. Most of the standards below are still drafts — check the official publication for final numbering and content.
Developed by CEN/CENELEC JTC 13 WG9; applies to all product categories.
prEN 40000-1-2 is the horizontal harmonised standard for Annex I and covers the whole product lifecycle. Its core principles are security by design, defence in depth, use of memory-safe languages, no security by obscurity, user-centred design and lifecycle management, together with a risk management framework running from product context to risk assessment, treatment, monitoring and communication.
Developed by ETSI TC CYBER WG EUSR for the Annex III categories; mostly mature drafts today.
Documentation is not paperwork on the side — it is exactly what a market surveillance authority asks for.
The technical documentation and the EU DoC are kept for at least 10 years after the individual product is placed on the market, or for the declared support period, whichever is longer (Art. 13(13)).
Work backwards from 11 December 2027. Starting early is what keeps you out of the notified body queue.
⚠ Article 14 reporting already applies from 11 September 2026 — the reporting mechanism cannot wait until 2027.
Sporton Cybersecurity Lab covers CRA scoping, Annex I gap analysis, product security testing, SBOM and vulnerability management, and technical documentation and conformity assessment preparation.
Related services:EU CRA consulting · EU CRA product security testing
This page summarises Regulation (EU) 2024/2847 and related EU legislation for general information only and does not constitute legal advice. Standard numbers and development status may change; always confirm against the Official Journal (EUR-Lex) and the standards bodies' official publications.