All frameworks
    Product conformityEuropean Union; conformity assessment and CE marking, with notified bodies for critical products

    CRA

    CRA: Cyber Resilience Act (Regulation (EU) 2024/2847)

    The EU Cyber Resilience Act sets cybersecurity requirements for products with digital elements sold in the EU, backed by CE marking. Main obligations apply from 2027.

    Last verified Jul 17, 2026

    Q&A

    What is CRA?

    The EU Cyber Resilience Act sets cybersecurity requirements for products with digital elements sold in the EU, backed by CE marking. Main obligations apply from 2027.

    Who needs CRA?

    Manufacturers, importers, and distributors of products with digital elements sold in the EU: connected devices, software products, and components, as well as their supply chains, which will be expected to support conformity.

    How long does CRA take?

    Obligations phase in through 2026 and 2027. Manufacturers should be building conformity, vulnerability-handling, and update processes now, ahead of reporting duties in 2026 and the main requirements in 2027.

    How much does a CRA audit cost?

    Cost depends on product risk class and whether a notified body is required. Default-class products rely on self-assessment; important and critical classes involve more rigorous, and more costly, conformity assessment.

    What does a CRA audit cover?

    Conformity assessment against the CRA's essential cybersecurity requirements, culminating in CE marking. The route ranges from manufacturer self-assessment for default products to notified-body involvement for critical classes.

    What it is

    The Cyber Resilience Act introduces mandatory cybersecurity requirements for "products with digital elements", hardware and software, placed on the EU market. It entered into force in December 2024 and phases in over the following years, with core obligations applying from December 2027 and vulnerability- and incident-reporting duties applying earlier, from September 2026.

    Manufacturers must meet essential cybersecurity requirements, handle vulnerabilities across the product lifecycle, provide security updates, and demonstrate conformity, carrying the CE marking. How conformity is assessed depends on the product's risk class: most products can self-assess, while important and critical classes require greater rigor, up to involvement of a notified body.

    The CRA effectively extends product-safety-style conformity assessment to cybersecurity, making it a manufacturer and supply-chain obligation rather than a service-level audit.

    Who needs it

    Manufacturers, importers, and distributors of products with digital elements sold in the EU: connected devices, software products, and components, as well as their supply chains, which will be expected to support conformity.

    What's audited

    Conformity assessment against the CRA's essential cybersecurity requirements, culminating in CE marking. The route ranges from manufacturer self-assessment for default products to notified-body involvement for critical classes.

    Typical timeline

    Obligations phase in through 2026 and 2027. Manufacturers should be building conformity, vulnerability-handling, and update processes now, ahead of reporting duties in 2026 and the main requirements in 2027.

    Typical cost

    Cost depends on product risk class and whether a notified body is required. Default-class products rely on self-assessment; important and critical classes involve more rigorous, and more costly, conformity assessment.

    What to verify on an auditor

    For products requiring third-party assessment, use a notified body designated under the CRA for the relevant product class. Verify the body's designation scope; for self-assessed products, ensure your internal conformity evidence and technical documentation are robust.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • CRA readiness work (SBOM, VDP, SDLC, technical docs)
      Available
    • Manufacturer self-assessment (default class)
      Applies to the large majority of products with digital elements. Manufacturer signs an EU Declaration of Conformity and applies CE marking.
      Available
    • Notified body conformity assessment (important / critical classes)
      As of mid-2026, no CRA-designated notified bodies exist in the EU's official NANDO registry, so third-party CRA conformity assessment is not yet operational regardless of demand.
      Not yet operational