Regulation (EU) 2024/2847 (Cyber Resilience Act)

Cyber Resilience Act (CRA) β€” Implementation Guide for Connected Products

Structured readiness for products with digital elements: obligations under Art. 13 & Annex I, reporting processes under Art. 14, Software Bills of Materials (SBOM), and conformity assessment routes.

Pre-Launch Informational Portal

The interactive assessment engine for the Cyber Resilience Act (Regulation (EU) 2024/2847) is currently under development by SKOPION Intelligence on the shared Steps Core platform. This portal serves as a manufacturer knowledge base.

CRASteps is an independent informational and scoping portal by SKOPION Intelligence. Not legal advice under national legal counseling acts. CE conformity requires individualized assessment.

CRASteps is the specialized guidance portal for the SKOPION service CRA Readiness & CE Cybersecurity

What is the Cyber Resilience Act?

Regulation (EU) 2024/2847 establishes the first EU-wide mandatory horizontal cybersecurity requirements for all products with digital elements.

Who is covered?

Economic operators in the EU single market: manufacturers of connected hardware and software, authorised representatives, importers, and distributors (Articles 13–19). Pure non-commercial open-source software developed outside commercial activity is excluded; open-source software stewards are subject to Article 24. Manufacturers integrating open-source components remain responsible for the cybersecurity of the finished product.

What does it require?

Security by design and default (Art. 13 & Annex I Part I), attack surface reduction, vulnerability handling, and a machine-readable SBOM covering at least top-level dependencies (Annex I Part II point 1). Support period determination under Art. 13(8), user information under Art. 13(19) & Annex II, and free security updates under Annex I Part II point 8.

Reporting Obligations Active

Mandatory reporting under Article 14 applies from 11 September 2026: actively exploited vulnerabilities and severe security incidents must be reported within 24 hours (early warning) and 72 hours to competent CSIRTs and ENISA.

CE Marking & Conformity

Prior to market placement (mandatory from 11 December 2027), a conformity assessment pursuant to Art. 32 & Annex VIII must be completed: standard products via internal production control (Module A); important products (Art. 7 & Annex III Part I / II) via Module A (if harmonised standards fully applied) or notified body; critical products (Art. 8 & Annex IV) via third-party assessment or European cybersecurity certificate. EU Declaration of Conformity under Art. 28 & Annex V/VI and technical documentation under Art. 31 & Annex VII.

Penalties

Non-compliance risks substantial regulatory sanctions: sales bans, product recalls, and fines of up to €15 million or 2.5% of worldwide annual turnover (Art. 64).

How Structured Preparation Works

1. Product & Role Scoping

Identify product type (hardware, software, component) and your role as manufacturer, importer, or distributor under Art. 2 and Art. 13–19.

2. Security Requirements Gap Analysis

Assess essential cybersecurity properties under Art. 13 & Annex I Part I (access control, cryptography, integrity, secure defaults).

3. Vulnerability Handling & SBOM

Evaluation of vulnerability handling processes (Annex I Part II), patch delivery mechanisms, and compilation of a machine-readable Software Bill of Materials (SBOM) covering at least top-level dependencies.

4. Action Plan & CE Roadmap

Prioritised overview of identified gaps, technical documentation requirements (Art. 31 & Annex VII), EU Declaration of Conformity (Art. 28 & Annex V), and applicable conformity assessment route (Art. 32 & Annex VIII).

What You Get with CRASteps

Classification & Conformity Path

Clear identification whether your product qualifies as standard, important (Class I or II under Annex III), or critical (Annex IV).

Transparent Gap Analysis

Clear identification of missing evidence in vulnerability management, documentation, SBOM, and incident notification.

Prioritized Preparation

Actionable recommendations to assemble technical files ahead of the general CE deadline on 11 December 2027.

CRA Architecture at a Glance

The forthcoming CODEX Steps Core assessment engine will systematically map the core pillars of Regulation (EU) 2024/2847:

1. Essential Cybersecurity Requirements (Art. 13 & Annex I)

Annex I Part I: Security-by-default, integrity protection, access controls, attack surface minimization, and free security updates during the support period.

2. Product Classification (Art. 6, 7 & Annexes III, IV)

Classification into standard products with digital elements, important products (Class I & II under Annex III), and critical products (Annex IV) with differentiated conformity routes.

3. Reporting Obligations under Art. 14 (Active 11 Sept 2026)

Mandatory reporting of actively exploited vulnerabilities and severe security incidents within 24 hours (early warning) and 72 hours to designated CSIRTs and ENISA.

4. Vulnerability Handling & SBOM (Annex I Part II)

Annex I Part II: Machine-readable Software Bill of Materials (SBOM), coordinated vulnerability disclosure, provision of security updates, and technical documentation (Annex VII).

Independent Methodology & Guidance

Our preparation framework aligns strictly with the final provisions of Regulation (EU) 2024/2847, European Commission guidelines, and ENISA publications. We support developers and manufacturers in early compliance readiness.

Applicable across the European Economic Area (EEA).

European Cybersecurity Framework

The Cyber Resilience Act is a cornerstone of the EU cybersecurity strategy, bridging the gap between organizational obligations and concrete product security across the digital single market.

Frequently Asked Questions about the CRA

When does the Cyber Resilience Act take effect?

Regulation (EU) 2024/2847 was published on 20 November 2024 and entered into force on 10 December 2024. Notified body provisions (Chapter IV) apply from 11 June 2026. Article 14 reporting obligations for actively exploited vulnerabilities apply from 11 September 2026. General product requirements and CE marking become mandatory on 11 December 2027.

What deadlines must manufacturers observe now?

From 11 September 2026, manufacturers must report actively exploited vulnerabilities to CSIRTs and ENISA within 24h and 72h (Art. 14). By 11 December 2027, all essential cybersecurity requirements (Art. 13 & Annex I), support period determinations (Art. 13(8)), technical documentation (Art. 31 & Annex VII), and conformity assessments (Art. 32 & Annex VIII) must be fully implemented.

Does the CRA apply to open-source software?

Free and open-source software developed or supplied outside commercial activity is outside the scope of the CRA. Open-source software stewards are subject to a tailored regime under Article 24. When a commercial manufacturer integrates open-source components, the manufacturer must ensure cybersecurity and document the SBOM; commercial integration does not make the upstream open-source developer a manufacturer.

What is a Software Bill of Materials (SBOM)?

A Software Bill of Materials (SBOM) is a machine-readable inventory of software components and dependencies. The statutory minimum requirement under Annex I Part II point (1) mandates covering at least top-level dependencies. Full transitive dependency tracking is recommended as industry technical best practice.

How does the CRA relate to the NIS2 Directive?

NIS2 regulates the cybersecurity governance and operational resilience of organisations and infrastructure operators. The CRA regulates the cybersecurity of products placed on the market. NIS2 entities will increasingly require suppliers to provide CRA-compliant products.

Early Access & Expert Consultation

Would you like to be among the first manufacturers to evaluate products against the CRA with the upcoming Steps Core engine? Contact our advisory team.

Your data is handled confidentially pursuant to our Privacy Policy.