Skip to content
folhas.io
secure by design for connected products· Regulation (EU) 2024/2847

The Cyber Resilience Act for manufacturers

Regulation (EU) 2024/2847 imposes cybersecurity requirements on anyone placing products with digital elements on the European market. This page is the entry point: what the regulation covers, which technical decisions it forces, and when.

The common reading is that the CRA is aimed at large hardware manufacturers. It is not. The regulation applies to products with digital elements, which includes software sold as a product, companies that integrate digital components into physical products, and also importers and distributors, each with obligations of their own.

What sets it apart from earlier regimes is the time axis: the obligations do not end when the product is placed on the market. Vulnerability management, security updates and communication throughout the support period are part of the product.

CRA calendar

2024-12CRA in force
2026-07Commission guidance
2026-0924h / 72h reporting
2027-12Full application
today

456 daysuntil Full application for manufacturers (11 Dec 2027)

  1. 10 Dec 2024The Cyber Resilience Act enters into force. Manufacturer obligations only become applicable later, in phases. Regulation (EU) 2024/2847
  2. 27 Jul 2026The European Commission publishes practical guidance on applying the CRA. European Commission
  3. 11 Sep 2026The reporting obligations become applicable: an early warning within 24 hours and a notification within 72 hours for actively exploited vulnerabilities and severe incidents. Regulation (EU) 2024/2847, Article 14
  4. 11 Dec 2027The CRA becomes fully applicable. From here on, products with digital elements placed on the market must meet the essential cybersecurity requirements. Regulation (EU) 2024/2847

The full calendar, with national context

The calendar above shows the CRA milestones. This table also includes the Portuguese regulatory context, which runs in parallel and applies to entities, not to manufacturers as such.

DateMilestoneSource
10 Dec 2024CRA in force
The Cyber Resilience Act enters into force. Manufacturer obligations only become applicable later, in phases.
Regulation (EU) 2024/2847
3 Apr 2026DL 125/2025 (NIS2 PT)
Portugal's transposition of the NIS2 directive takes effect. It applies to essential and important entities, not to manufacturers as such.
Decree-Law 125/2025
23 Jun 2026National Reference Framework
CNCS Regulation 756/2026 takes effect, establishing Portugal's National Cybersecurity Reference Framework.
Regulation 756/2026 (CNCS)
27 Jul 2026Commission guidance
The European Commission publishes practical guidance on applying the CRA.
European Commission
11 Sep 202624h / 72h reporting
The reporting obligations become applicable: an early warning within 24 hours and a notification within 72 hours for actively exploited vulnerabilities and severe incidents.
Regulation (EU) 2024/2847, Article 14
11 Dec 2027Full application
The CRA becomes fully applicable. From here on, products with digital elements placed on the market must meet the essential cybersecurity requirements.
Regulation (EU) 2024/2847

The seven points that decide a project

Each of these is an in-depth article, already published. New articles come out every two to three weeks.

  1. 01

    SBOM for embedded firmware: what the CRA requires and how to generate one without lying

    The software bill of materials the CRA demands is not written by hand. For firmware, the only credible SBOM comes out of the build system, and binary scanning serves for what we did not build ourselves.

  2. 02

    The 24h and 72h reports: how the obligation arriving on 11 September works

    From 11 September 2026, a manufacturer who learns of an actively exploited vulnerability in its product has 24 hours for the first alert. What gets reported, to whom, through where, and what to prepare beforehand.

  3. 03

    Classifying the product under the CRA: the decision that sets the cost of everything else

    Default, important class I, important class II or critical. The product's category determines whether conformity is a self-assessment or a notified body, and the difference is measured in tens of thousands of euros and months of calendar.

  4. 04

    The support period: the most expensive promise the CRA makes you make

    The CRA obliges every manufacturer to declare for how long it supports the product: as a rule, at least five years. It is an engineering, contracts and supplier decision disguised as a field on a form.

  5. 05

    CRA and RED: the radio-equipped device now lives under two regimes

    Since August 2025, any radio equipment connected to the internet has had to meet the RED's cybersecurity requirements. The CRA will replace them, but until December 2027 the two regimes coexist, and work done under one does not automatically count under the other.

  6. 06

    What automotive already learnt, and the rest of industry will learn by 2027

    The automotive sector was the first forced to treat cybersecurity as a product property across the life cycle, with UNECE R155/R156 and ISO/SAE 21434. Vehicles are outside the CRA precisely because of this, and it is also why they serve as a preview.

  7. 07

    The CRA for software makers: the regulation is not only for people who solder boards

    The most common misconception about the CRA is that it addresses device manufacturers. Software sold as a product is in. Pure SaaS is out, with one exception that catches a lot of people. And 'free of charge' does not mean 'non-commercial'.

Where this turns into work

Preparing a product for the CRA is not filling in a dossier at the end. The decisions that cost real money are taken early: which third-party components go into the firmware and how they will be tracked, what update surface the device exposes, how long the company commits to supporting the product, and who receives and answers a vulnerability report arriving from outside.

What we do describes how we enter that process.

No compliance promises. No consultant can guarantee a product's conformity — the manufacturer declares it, under its own responsibility. We work on preparation and on reducing technical risk.