Framework hub

Cyber Resilience Act

The CRA is the EU horizontal cybersecurity framework for products with digital elements, including many commercial software and connected hardware products made available on the EU market.

EU baseline

If you are established in the EU, operate in the EU, or place this product or service on the EU market, treat this as a first-order compliance check. Non-EU reach language means outsiders can also be covered, not that EU companies are outside scope.

Review scope

Focus 1

Builder trigger

Check CRA when you ship commercial software, hardware, components, or remote data-processing features that connect directly or indirectly to a device or network.

Focus 2

Common carve-outs

Pure SaaS and non-commercial open-source software are not the default target, but remote data processing tied to a product, commercial open-source stewardship, import, and distribution can change the analysis.

Focus 3

Core duties

The key operating themes are secure design, vulnerability handling, support-period disclosure, technical documentation, conformity assessment, EU declaration of conformity, and CE marking.

Focus 4

Reporting timeline

The CRA entered into force on 10 December 2024. Conformity body rules apply from 11 June 2026, Article 14 reporting applies from 11 September 2026, and full application starts on 11 December 2027.

Open related page

Focus 5

Official legal text

The controlling source is Regulation (EU) 2024/2847 in the Official Journal. Secondary explainers are useful, but product decisions should trace back to the legal text.

Open related page

Focus 6

Why vibe-coded apps matter

Fast generated builds often miss secure defaults, update processes, dependency hygiene, vulnerability intake, and user-facing support-period information, which are exactly the product-security habits CRA pushes into the lifecycle.

Open related page

Source updates

URGENTESMA2026-07-02

Moody’s Germany fined EUR 2,145,000 for misreporting to ESMA

The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has fined Moody’s Deutschland GmbH (Moody’s Germany) a total of EUR 2,145,000, for...

DORAMiCACyber Resilience ActFTC Safeguards
MEDIUMOWASP2026-06-09

OWASP Dependency-Track 5.0 Is Now Generally Available

The largest redesign in the project’s history brings horizontal scaling, fault tolerance, and software supply chain integrity verification to the widely used open source platform....

OWASP Top 10LLM Top 10Cyber Resilience ActDORA