CRA obligations by product class
Regulation (EU) 2024/2847 by product class: the scope test, the obligations by article, the conformity route, and what starts on 11 September 2026.
Compliance4 Sept 20269 min read
On this page
What it is
The Cyber Resilience Act is Regulation (EU) 2024/2847, on horizontal cybersecurity requirements for products with digital elements, published in the Official Journal of 20 November 2024 1.
A product may be made available only where it meets the essential requirements in Part I of Annex I, and where the manufacturer's processes meet the vulnerability-handling requirements in Part II. The manufacturer is the central operator: it designs to Part I, documents a risk assessment, draws up technical documentation, assesses conformity and affixes the CE marking. The route it uses follows product class, not company size 2.
Who is in scope (decision test)
Steps 1 to 3 decide whether the Regulation reaches the product; step 4, how heavy the route is.
- Is it a product with digital elements? The term covers software and hardware products and their remote data processing solutions. The Regulation applies where intended or foreseeable use includes a direct or indirect data connection to a device or network 3.
- Which operator role? Manufacturer, importer and distributor are defined at Article 3, points (13), (16) and (17). Anyone else who substantially modifies a product and markets it becomes the manufacturer, for the affected part or the whole product 4. An open-source software steward carries a lighter set, with the Article 14 duties only so far as stated 5.
- Is it excluded? Article 2 removes products covered by the medical device, in vitro diagnostic and vehicle type-approval Regulations, and products certified under the civil aviation Regulation. It also removes marine equipment, identical spare parts, and products for national security, defence or classified information 6.
- Which class? A product whose core functionality matches an Annex III category is important, class I or class II, and takes the Article 32(2) and (3) routes. Annex III lists nineteen class I categories and four class II, among them operating systems, routers and firewalls. Annex IV names three critical categories, including smart meter gateways and smartcards 7. Everything else is a default product.
| Outcome | What it means | Next step |
|---|---|---|
| In scope | Article 13 applies in full; the class sets the route | Fix the class, then work Article 13 by paragraph |
| Out of scope | An Article 2 exclusion applies, or nothing connects | Record it with its article; re-run after changes |
| Needs legal input | The exclusion or role is arguable | Write the analysis; have counsel confirm |
Obligations by article
| Article / clause | Obligation | What it means in practice | Evidence |
|---|---|---|---|
| Art. 13(1); Annex I Part I | Design and produce to Part I, whose point (2) lists thirteen properties (a) to (m) 8 | Secure defaults; no known exploitable vulnerabilities | Decision per requirement |
| Art. 13(2) to 13(4) | Assess and document cybersecurity risk, keep it current, state which Part I requirements apply 9 | Non-application needs justifying | Dated assessment |
| Art. 13(5), 13(6) | Due diligence on third-party components; report a component vulnerability upstream and share the fix 10 | Open-source components included | Diligence and upstream logs |
| Art. 13(8), 13(9); Annex I Part II | Handle vulnerabilities to the eight Part II requirements; support-period floor five years; each update kept ten years or longer 11 | A recorded determination | Determination; update archive |
| Art. 13(12) to 13(14) | Documentation, assessment, declaration and CE marking; documentation kept ten years or the support period; series production stays conforming 12 | Four artefacts, one version | Artefacts; change record |
| Art. 13(17), 13(19), 13(21) | A single point of contact; the support end date at purchase; immediate correction or recall 13 | The trigger is belief | Contact; correction record |
| Art. 14 | Notify actively exploited vulnerabilities and severe incidents 14 | Route and clocks below | Timestamped submissions |
| Art. 19 | Importers check assessment, documentation, marking, declaration and user information 15 | A checking duty | Documents per check |
| Art. 20 | Distributors act with due care and verify marking and the named manufacturer duties 16 | Belief of non-conformity stops it | Verification record |
| Art. 22 | A substantial modifier takes Articles 13 and 14 for the affected part, or the whole product 17 | Integrators inherit the set | Modification analysis |
| Art. 32(1) to 32(4); Art. 8(1) | Module A, module B with C, module H, or a certification scheme. Class I loses module A where harmonised standards, common specifications or a scheme at assurance level at least substantial were not fully applied or do not exist. Class II takes B with C, H, or a scheme at assurance level at least substantial. Annex IV products may need a certificate 18 | Standards keep class I self-assessed | Module; standards note |
Dates (verified)
| Date | What happens | Source |
|---|---|---|
| 2024-12-10 | Entry into force, the twentieth day following publication in the Official Journal | 19 |
| 2026-06-11 | Chapter IV, Articles 35 to 51, applies; notified bodies can be appointed | 20 |
| 2026-09-11 | Article 14 applies; reporting duties start | 20 |
| 2027-12-11 | General application. Products placed earlier take the substantive requirements only if substantially modified | 21 |
The 11 September 2026 milestone
Two duties start that day, and they reach further than the rest of the Regulation. By derogation from the transitional rule, Article 14 applies to every product in scope placed on the market before 11 December 2027 22. A shipped fleet reports before its own requirements bite.
The first duty covers an actively exploited vulnerability: one for which there is reliable evidence that a malicious actor has exploited it without the system owner's permission 23. The second covers a severe incident, and severe is defined rather than judged freehand. The first test is a negative effect, actual or possible, on the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. The second is that malicious code has been, or could be, introduced or executed 24.
Both go the same way, simultaneously to the CSIRT designated as coordinator and to ENISA, through the Article 16 reporting platform. The end-point is that coordinator's, in the Member State of the manufacturer's main establishment 25.
The clocks run from awareness: an early warning within 24 hours, a fuller notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure is available for a vulnerability, and within one month of the 72-hour notification for an incident. The coordinator may ask for an intermediate report; the manufacturer tells impacted users what to apply 26.
| Readiness item | Done when |
|---|---|
| Awareness is an event | A role and timestamp record it |
| The severity call is written | Both Article 14(5) tests on the form |
| The end-point is fixed | The coordinator's address is stored |
| Platform access works | Credentials tested by someone on call |
| The user-notice path exists | A channel reaching impacted users |
| The clocks are rehearsed | One exercise times both tracks |
Mapping to ISO 27001 Annex A / NIST CSF
| Obligation | ISO/IEC 27001:2022 / 27002:2022 | NIST CSF 2.0 | Gap |
|---|---|---|---|
| Art. 13(1); Annex I Part I | Clause 8, Technological controls, at clause level | Platform Security (PR.PS) | Product properties are not management-system controls |
| Art. 13(2) to 13(4) | Clauses 6.1.2 and 8.2, risk assessment | Risk Assessment (ID.RA) | The scope is one product version |
| Art. 13(5), 13(6) | A.5.19 to A.5.22, supplier relationships | Cybersecurity Supply Chain Risk Management (GV.SC) | Reporting a fix upstream; unowned components |
| Art. 13(8), 13(9); Annex I Part II | A.5.1 Policies for information security | Asset Management (ID.AM) | No reference control asks for a bill of materials |
| Art. 13(12) to 13(21) | Clause 7.5.3 Control of documented information; clause 10.2 Nonconformity and corrective action | Improvement (ID.IM) | A retention floor; an external intake |
| Art. 14(1) to 14(8) | A.5.24 to A.5.27, incident management | Incident Response Reporting and Communication (RS.CO) | Statutory clocks, two recipients, severity test |
Control titles come from the ISO contents listings, public only to 8.1, so technological controls are cited at clause level 27. Category names are CSF Core 28.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1 | Run the scope test per line; record the class and its article | Product security lead | Class register with citations |
| 1-2 | Register on the reporting platform via the coordinator end-point | Product security lead | Tested platform access |
| 2 | Put both Article 14(5) tests on the incident form; define awareness | Incident manager | Revised form; awareness event logged |
| 3 | Exercise both tracks against the 24-hour, 72-hour and final windows | Incident manager | Exercise report, times measured |
| 4-8 | Build the machine-readable user-notification path; write the support-period determination | Release engineering | Advisory template; determination records |
| 5-12 | Produce a bill of materials per release; decide the Article 32 route per class | Product compliance role | Bill of materials; dated route decision |
References
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://publications.europa.eu/resource/celex/32024R2847 29
- NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29 28
- ISO/IEC. ISO/IEC 27002:2022, contents. ISO Online Browsing Platform. https://www.iso.org/obp/ui/#iso:std:iso-iec:27002:ed-3:v2:en 27
Sources
- 1EU Publications Office CELEX 32024R2847 OJ reference · verified 2026-09-04
- 2EU Publications Office CELEX 32024R2847 Art. 6, 13(1), 13(12) and Art. 32(1) · verified 2026-09-04
- 3EU Publications Office CELEX 32024R2847 Art. 2(1) and Art. 3(1) · verified 2026-09-04
- 4EU Publications Office CELEX 32024R2847 Art. 3(13) to 3(17) and Art. 22 · verified 2026-09-04
- 5EU Publications Office CELEX 32024R2847 Art. 3(14) and Art. 24 · verified 2026-09-04
- 6EU Publications Office CELEX 32024R2847 Art. 2(2) to 2(7) · verified 2026-09-04
- 7EU Publications Office CELEX 32024R2847 Art. 7(1), 7(2), Art. 8(1), Annex III and Annex IV · verified 2026-09-04
- 8EU Publications Office CELEX 32024R2847 Art. 13(1) and Annex I Part I · verified 2026-09-04
- 9EU Publications Office CELEX 32024R2847 Art. 13(2) to 13(4) · verified 2026-09-04
- 10EU Publications Office CELEX 32024R2847 Art. 13(5) and 13(6) · verified 2026-09-04
- 11EU Publications Office CELEX 32024R2847 Art. 13(8), 13(9) and Annex I Part II · verified 2026-09-04
- 12EU Publications Office CELEX 32024R2847 Art. 13(12) to 13(14) · verified 2026-09-04
- 13EU Publications Office CELEX 32024R2847 Art. 13(17), 13(19) and 13(21) · verified 2026-09-04
- 14EU Publications Office CELEX 32024R2847 Art. 14(1) and 14(3) · verified 2026-09-04
- 15EU Publications Office CELEX 32024R2847 Art. 19(1) and 19(2) · verified 2026-09-04
- 16EU Publications Office CELEX 32024R2847 Art. 20(1) and 20(2) · verified 2026-09-04
- 17EU Publications Office CELEX 32024R2847 Art. 22 · verified 2026-09-04
- 18EU Publications Office CELEX 32024R2847 Art. 32(1) to 32(4) and Art. 8(1) · verified 2026-09-04
- 19EU Publications Office CELEX 32024R2847 Art. 71(1) · verified 2026-09-04
- 20EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-04
- 21EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-04
- 22EU Publications Office CELEX 32024R2847 Art. 69(3) · verified 2026-09-04
- 23EU Publications Office CELEX 32024R2847 Art. 14(1) and Art. 3(42) · verified 2026-09-04
- 24EU Publications Office CELEX 32024R2847 Art. 14(3) and 14(5) · verified 2026-09-04
- 25EU Publications Office CELEX 32024R2847 Art. 14(1), 14(7) and Art. 16(1) · verified 2026-09-04
- 26EU Publications Office CELEX 32024R2847 Art. 14(2), 14(4), 14(6) and 14(8) · verified 2026-09-04
- 27ISO/IEC 27002:2022 contents, iso.org/obp · verified 2026-09-03
- 28NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-04
- 29EU Publications Office CELEX 32024R2847 · verified 2026-09-04