The Cyber Resilience Act for manufacturers
Regulation (EU) 2024/2847 imposes cybersecurity requirements on anyone placing products with digital elements on the European market. This page is the entry point: what the regulation covers, which technical decisions it forces, and when.
The common reading is that the CRA is aimed at large hardware manufacturers. It is not. The regulation applies to products with digital elements, which includes software sold as a product, companies that integrate digital components into physical products, and also importers and distributors, each with obligations of their own.
What sets it apart from earlier regimes is the time axis: the obligations do not end when the product is placed on the market. Vulnerability management, security updates and communication throughout the support period are part of the product.
CRA calendar
456 daysuntil Full application for manufacturers (11 Dec 2027)
- 10 Dec 2024The Cyber Resilience Act enters into force. Manufacturer obligations only become applicable later, in phases. Regulation (EU) 2024/2847
- 27 Jul 2026The European Commission publishes practical guidance on applying the CRA. European Commission
- 11 Sep 2026The reporting obligations become applicable: an early warning within 24 hours and a notification within 72 hours for actively exploited vulnerabilities and severe incidents. Regulation (EU) 2024/2847, Article 14
- 11 Dec 2027The CRA becomes fully applicable. From here on, products with digital elements placed on the market must meet the essential cybersecurity requirements. Regulation (EU) 2024/2847
The full calendar, with national context
The calendar above shows the CRA milestones. This table also includes the Portuguese regulatory context, which runs in parallel and applies to entities, not to manufacturers as such.
| Date | Milestone | Source |
|---|---|---|
| 10 Dec 2024 | CRA in force The Cyber Resilience Act enters into force. Manufacturer obligations only become applicable later, in phases. | Regulation (EU) 2024/2847 |
| 3 Apr 2026 | DL 125/2025 (NIS2 PT) Portugal's transposition of the NIS2 directive takes effect. It applies to essential and important entities, not to manufacturers as such. | Decree-Law 125/2025 |
| 23 Jun 2026 | National Reference Framework CNCS Regulation 756/2026 takes effect, establishing Portugal's National Cybersecurity Reference Framework. | Regulation 756/2026 (CNCS) |
| 27 Jul 2026 | Commission guidance The European Commission publishes practical guidance on applying the CRA. | European Commission |
| 11 Sep 2026 | 24h / 72h reporting The reporting obligations become applicable: an early warning within 24 hours and a notification within 72 hours for actively exploited vulnerabilities and severe incidents. | Regulation (EU) 2024/2847, Article 14 |
| 11 Dec 2027 | Full application The CRA becomes fully applicable. From here on, products with digital elements placed on the market must meet the essential cybersecurity requirements. | Regulation (EU) 2024/2847 |
The seven points that decide a project
Each of these is an in-depth article, already published. New articles come out every two to three weeks.
- 01
SBOM for embedded firmware: what the CRA requires and how to generate one without lying
The software bill of materials the CRA demands is not written by hand. For firmware, the only credible SBOM comes out of the build system, and binary scanning serves for what we did not build ourselves.
- 02
The 24h and 72h reports: how the obligation arriving on 11 September works
From 11 September 2026, a manufacturer who learns of an actively exploited vulnerability in its product has 24 hours for the first alert. What gets reported, to whom, through where, and what to prepare beforehand.
- 03
Classifying the product under the CRA: the decision that sets the cost of everything else
Default, important class I, important class II or critical. The product's category determines whether conformity is a self-assessment or a notified body, and the difference is measured in tens of thousands of euros and months of calendar.
- 04
The support period: the most expensive promise the CRA makes you make
The CRA obliges every manufacturer to declare for how long it supports the product: as a rule, at least five years. It is an engineering, contracts and supplier decision disguised as a field on a form.
- 05
CRA and RED: the radio-equipped device now lives under two regimes
Since August 2025, any radio equipment connected to the internet has had to meet the RED's cybersecurity requirements. The CRA will replace them, but until December 2027 the two regimes coexist, and work done under one does not automatically count under the other.
- 06
What automotive already learnt, and the rest of industry will learn by 2027
The automotive sector was the first forced to treat cybersecurity as a product property across the life cycle, with UNECE R155/R156 and ISO/SAE 21434. Vehicles are outside the CRA precisely because of this, and it is also why they serve as a preview.
- 07
The CRA for software makers: the regulation is not only for people who solder boards
The most common misconception about the CRA is that it addresses device manufacturers. Software sold as a product is in. Pure SaaS is out, with one exception that catches a lot of people. And 'free of charge' does not mean 'non-commercial'.
Where this turns into work
Preparing a product for the CRA is not filling in a dossier at the end. The decisions that cost real money are taken early: which third-party components go into the firmware and how they will be tracked, what update surface the device exposes, how long the company commits to supporting the product, and who receives and answers a vulnerability report arriving from outside.
What we do describes how we enter that process.
No compliance promises. No consultant can guarantee a product's conformity — the manufacturer declares it, under its own responsibility. We work on preparation and on reducing technical risk.