CRA reporting obligations apply from 11 September 2026View the timeline
Practical CRA guidance

Practical Cyber Resilience Act guides

Understand CRA scope, categories, deadlines, reporting and conformity assessment. Six focused guides linked to primary sources and practical tools.

CRA essentials

Cyber Resilience Act: a practical guide

The Cyber Resilience Act establishes cybersecurity requirements for products with digital elements supplied on the EU market. Start by identifying the product and your role, then determine its category and the applicable assessment procedure.

Read the guide
Scope & economic roles

CRA scope: which products and roles are covered?

A product is likely within CRA scope when it is a product with digital elements supplied on the EU market in a commercial activity, has the relevant direct or indirect data connection, and is not covered by an exclusion.

Read the guide
Product classification

CRA product categories: Default, Class I, Class II and Critical

Compare the core functionality of the product as a whole with Annex III and Annex IV and their implementing technical descriptions. A marketing label or a single embedded component is not enough to determine the category.

Read the guide
Implementation dates

CRA deadlines and application timeline

Article 14 reporting for manufacturers applies from 11 September 2026. Most CRA requirements apply from 11 December 2027. Earlier products have transitional treatment, with reporting expressly extending to older in-scope products.

Read the guide
Article 14 reporting

CRA reporting obligations: awareness, notifications and final reports

Article 14 requires reporting without undue delay, with outer limits of 24 hours for an early warning and 72 hours for the main notification. The final-report trigger differs for an actively exploited vulnerability and a severe incident.

Read the guide
Assessment & evidence

CRA conformity assessment routes explained

The permitted CRA conformity assessment route depends on product classification and additional conditions. Default products can generally use internal control; important and critical products need a closer Article 32 analysis.

Read the guide