Framework hub

Cyber Resilience Act

The CRA is the EU horizontal cybersecurity framework for products with digital elements, including many commercial software and connected hardware products made available on the EU market.

EU baseline

If you are established in the EU, operate in the EU, or place this product or service on the EU market, treat this as a first-order compliance check. Non-EU reach language means outsiders can also be covered, not that EU companies are outside scope.

Review scope

Focus 1

Builder trigger

Check CRA when you ship commercial software, hardware, components, or remote data-processing features that connect directly or indirectly to a device or network.

Focus 2

Common carve-outs

Pure SaaS and non-commercial open-source software are not the default target, but remote data processing tied to a product, commercial open-source stewardship, import, and distribution can change the analysis.

Focus 3

Core duties

The key operating themes are secure design, vulnerability handling, support-period disclosure, technical documentation, conformity assessment, EU declaration of conformity, and CE marking.

Focus 4

Reporting timeline

The CRA entered into force on 10 December 2024. Conformity body rules apply from 11 June 2026, Article 14 reporting applies from 11 September 2026, and full application starts on 11 December 2027.

Open related page

Focus 5

Official legal text

The controlling source is Regulation (EU) 2024/2847 in the Official Journal. Secondary explainers are useful, but product decisions should trace back to the legal text.

Open related page

Focus 6

Why vibe-coded apps matter

Fast generated builds often miss secure defaults, update processes, dependency hygiene, vulnerability intake, and user-facing support-period information, which are exactly the product-security habits CRA pushes into the lifecycle.

Open related page

Source updates

HIGHEuropean Commission2026-06-07

Cyber Resilience Act application timeline

The CRA entered into force on 10 December 2024, with reporting duties from 11 September 2026 and full application from 11 December 2027.

Cyber Resilience Act