content_copy

Request information at
—your chance to get started right away

Download Materials

Understanding the European Cyber Resilience Act (
) and How to Respond to It

Manufacturers selling products with digital components in the EU market will be subject to new obligations.The European Cyber Resilience Act (CRA) is a regulation that requires manufacturers not only to bring products to market in a secure state but also to maintain a system for continuously identifying, addressing, and reporting vulnerabilities after the products have been sold. The obligation to report vulnerabilities that are actively being exploited and serious incidents to EU authorities will take effect on September 11, 2026, and the main obligations will become fully applicable on December 11, 2027.

In this document, we organize the overall framework of the CRA into two categories: “Measures to Ensure Product Compliance (A)” and “Post-Market Vulnerability and Incident Response (B).” We explain everything from how to determine whether your company’s products are subject to the CRA to the required outputs for each product category, reporting standards and deadlines for the EU, and the development of response schedules and organizational structures.

What You'll Learn from This Document

  • Purpose and Scope of the CRA, and the Structure of the Regulations (Relationship Between the Main Text and the Annexes)

  • Procedure for Determining Whether a Company's Product Is Subject to CRA or Falls Under Annex III/IV

  • Seven Post-Sale Obligations and the Thresholds and Deadlines for Reporting to the EU

  • Schedule for 2026–2027 and the Approach to Allocating Roles Internally and Externally

Recommended for people like this

  • Business managers, quality assurance professionals, and legal affairs staff at manufacturers that market hardware and software products to the EU

  • For those who want to get a big-picture view of where to start with CRA compliance

  • For those considering establishing a system for vulnerability response and incident reporting