Focus 1
Builder trigger
Check CRA when you ship commercial software, hardware, components, or remote data-processing features that connect directly or indirectly to a device or network.
The CRA is the EU horizontal cybersecurity framework for products with digital elements, including many commercial software and connected hardware products made available on the EU market.
EU baseline
If you are established in the EU, operate in the EU, or place this product or service on the EU market, treat this as a first-order compliance check. Non-EU reach language means outsiders can also be covered, not that EU companies are outside scope.
Review scopeFocus 1
Check CRA when you ship commercial software, hardware, components, or remote data-processing features that connect directly or indirectly to a device or network.
Focus 2
Pure SaaS and non-commercial open-source software are not the default target, but remote data processing tied to a product, commercial open-source stewardship, import, and distribution can change the analysis.
Focus 3
The key operating themes are secure design, vulnerability handling, support-period disclosure, technical documentation, conformity assessment, EU declaration of conformity, and CE marking.
Focus 4
The CRA entered into force on 10 December 2024. Conformity body rules apply from 11 June 2026, Article 14 reporting applies from 11 September 2026, and full application starts on 11 December 2027.
Open related pageFocus 5
The controlling source is Regulation (EU) 2024/2847 in the Official Journal. Secondary explainers are useful, but product decisions should trace back to the legal text.
Open related pageFocus 6
Fast generated builds often miss secure defaults, update processes, dependency hygiene, vulnerability intake, and user-facing support-period information, which are exactly the product-security habits CRA pushes into the lifecycle.
Open related pageThe Food and Drug Administration (FDA or Agency) is announcing an opportunity for public comment on the proposed collection of certain information by the Agency.
The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has fined Moody’s Deutschland GmbH (Moody’s Germany) a total of EUR 2,145,000, for...
The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has fined Moody’s Deutschland GmbH (Moody’s Germany) a total of EUR 2,145,000, for...
The U.S.
The largest redesign in the project’s history brings horizontal scaling, fault tolerance, and software supply chain integrity verification to the widely used open source platform....
OpenEoX and CLE are two emerging standards that work together to solve a critical gap in how organizations track whether the software and hardware they depend on is still supported, and...
OWASP has forged a coalition between the global security community and formal standardization bodies on AI.