CRA Insights

Cyber Resilience Act

Cyber Resilience Act: what management needs to know now

Cyber Resilience Act: what management needs to know now

Last updated: 2026-10-09

The Cyber Resilience Act, formally Regulation (EU) 2024/2847, sets out the cybersecurity requirements that products with digital elements must meet before they are placed on the EU market, and how manufacturers must handle vulnerabilities while their products are in use. One obligation already applies: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of their products. The remaining obligations follow from 11 December 2027.

For the management of a manufacturer, the CRA is more than a topic for the engineering department. It affects product strategy, budget, organisation and contracts with suppliers. Below you will find what the CRA requires, which deadlines apply, which decisions rest with management and how to check where you stand.

What the Cyber Resilience Act covers and who it applies to

Under Article 2(1), the CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Under Article 3(1), a product with digital elements is a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. This can cover controllers, gateways, connected devices and machine components as well as software sold on its own.

Article 2(2) to (4) excludes, among others, products covered by the EU regulations on medical devices, in vitro diagnostics or vehicle type-approval, aviation products certified under Regulation (EU) 2018/1139, and marine equipment. Whether a particular product is in scope is a legal question that your legal department or counsel should answer for the individual case. The applicability check gives a first orientation.

Manufacturers, importers and distributors

The CRA allocates obligations by role, the economic operators (Article 3(12)):

  • Manufacturers (Article 3(13)) develop or manufacture products with digital elements, or have them designed, developed or manufactured, and market them under their own name or trademark, including free of charge. They carry the most extensive obligations (Articles 13 and 14).
  • Importers (Article 3(16)) are established in the EU and place on the market products bearing the name or trademark of a company established outside the EU. Before doing so they must check, among other things, that the manufacturer has carried out the conformity assessment and drawn up the technical documentation (Article 19(2)).
  • Distributors (Article 3(17)) make products available on the market without affecting their properties. They check, among other things, the CE marking and the manufacturer's information (Article 20(2)).

Roles can change: under Article 21, an importer or distributor is considered a manufacturer if it places a product on the market under its own name or trademark or carries out a substantial modification of a product already on the market. With traded goods, own brands and bought-in parts in the portfolio, it is worth checking which role your company has for each product. More in the overview of CRA roles and on manufacturer obligations.

The deadlines at a glance

Published in the Official Journal on 20 November 2024, the Regulation entered into force on the twentieth day after publication, 10 December 2024 (Article 71(1)). Its obligations apply in stages (Article 71(2)):

DateWhat appliesProvision
10 Dec 2024Entry into force of the RegulationArticle 71(1)
11 Jun 2026Chapter IV (Articles 35 to 51): notification of conformity assessment bodiesArticle 71(2)
11 Sep 2026Manufacturers' reporting obligations under Article 14Article 71(2)
11 Dec 2027All other obligations, including the Annex I requirements, technical documentation, conformity assessment and CE markingArticle 71(2)

Two transitional rules matter for products already on the market. Products placed on the market before 11 December 2027 are subject to the requirements of the Regulation only if they undergo a substantial modification after that date (Article 69(2)). The Article 14 reporting obligations, however, expressly apply to these products as well (Article 69(3)). A device in the field for years is thus already subject to reporting, provided it is in scope. Details on the timeline are in CRA timeline and deadlines.

What rests with management

The CRA obligations apply to the company as manufacturer, importer or distributor. Part of the implementation can be handled within the project. Some points, however, affect budget, product strategy or organisation and therefore need a decision by company management. Six areas belong here.

1. Ownership

Who is responsible for the CRA in the company, and who for each product? Who decides when something has to be reported, and who deputises for that person? Without named owners, topics such as risk assessment, documentation and supplier requirements fall between engineering, quality and purchasing. Clear allocation with a reporting line to management creates accountability.

2. Budget

The effort depends on the number of products and variants, their product class, the maturity of development and vulnerability handling, and the support period you commit to. Part of the cost is one-off, such as the technical documentation per product; part is ongoing, such as vulnerability handling and security updates. The cost drivers are explained in What does CRA compliance cost?

3. Product portfolio

Which products and variants will you still place on the market from 11 December 2027, which will be developed further and which will be phased out? Every single unit counts: a device from a series built for years must meet the requirements if it is placed on the market from that date (recital 38). For units placed on the market before, the question of substantial modifications after that date matters (Article 69(2)). The product class helps determine whether an internal conformity assessment is possible or a notified body must be involved; for important products of class I this also depends on whether harmonised standards are applied (Article 32); important and critical products are listed in Annexes III and IV (see CRA product classes).

4. Support period

Under Article 3(20), the support period is the period during which the manufacturer must ensure that vulnerabilities of the product are handled effectively. Under Article 13(8), the manufacturer determines it so that it reflects the length of time the product is expected to be in use; it is at least five years, unless the product is expected to be in use for less. The end date must be indicated at the time of purchase, at least by month and year (Article 13(19)), and security updates made available must remain available for a minimum of 10 years after being issued or for the remainder of the support period, whichever is longer (Article 13(9)). The support period thus becomes a commitment to the market that ties up staff and money for years. More in Support period and update duty.

5. Round-the-clock reporting capability

Since 11 September 2026, a manufacturer must notify any actively exploited vulnerability in its product and any severe incident having an impact on the security of the product, simultaneously to the CSIRT designated as coordinator (the competent national computer security incident response team) and to ENISA, via the single reporting platform (Article 14(1), (3) and (7)). The early warning notification is due without undue delay and in any event within 24 hours of becoming aware, the more detailed notification within 72 hours, followed by a final report (Article 14(2) and (4)). The Regulation provides no different deadline for weekends or public holidays. Meeting these deadlines depends on reports being received, assessed and passed to someone with authority to decide outside business hours as well. Organising and funding that availability is a management decision. On the process, see CRA reporting obligation since 11 September 2026 and our service reporting process and PSIRT.

6. Supply chain

Manufacturers must exercise due diligence when integrating components sourced from third parties, including open-source software, so that these do not compromise the cybersecurity of the product (Article 13(5)). If they identify a vulnerability in a component, they report it to the person or entity manufacturing or maintaining it (Article 13(6)). Supplier selection, purchasing terms and the information suppliers deliver, such as a software bill of materials (SBOM), therefore belong on management's agenda. How to draft contracts in the individual case is a matter for your legal department or counsel.

Overview "What rests with management": six areas that affect budget, product strategy or organisation and need a decision by company management. 1 Ownership: who owns the CRA, who decides when reporting, who deputises? 2 Budget: are one-off and ongoing costs per product planned? 3 Product portfolio: what will you still place on the market from 11 Dec 2027, counting every unit, and what is phased out? (Art. 69(2), recital 38, Annexes III and IV). 4 Support period: at least five years unless the expected time of use is shorter; end date shown at purchase with month and year (Art. 13(8) and (19)). 5 Round-the-clock reporting, highlighted because the obligation already applies: early warning without undue delay and in any event within 24 hours, notification within 72 hours of awareness, weekends included (Art. 14(2) and (4), applies since 11 Sep 2026). 6 Supply chain: due diligence for third-party components, supplier information such as SBOM (Art. 13(5) and (6)). Footer: source Regulation (EU) 2024/2847, as of 9 October 2026, general information, not legal advice.
Six areas for management decisions under the CRA. Source: Regulation (EU) 2024/2847, as of 9 October 2026.

Questions to ask your team

These questions can give you a first picture of the status in one meeting. Note whether the answers point to evidence or to intentions.

  1. Do we have a complete list of all products and variants with digital elements, and is it recorded for each product which role and product class we assume and why?
  2. Who would decide tonight on an early warning notification under Article 14, who deputises for that person, and do both have access to the reporting platform?
  3. Is there a documented cybersecurity risk assessment for every product under Article 13(2) and (3)?
  4. Do we produce a software bill of materials for each release, and how do we find out whether a newly disclosed vulnerability affects one of our products?
  5. Which support period do we plan for each product, on what basis, and is it reflected in the budget?
  6. Which products will we still place on the market after 11 December 2027, including from current series, and which of them need a notified body?
  7. Could we provide the market surveillance authority, on request, with the documents demonstrating conformity (Article 13(22))?

What the consequences of infringements can be

Enforcement lies with the market surveillance authorities of the Member States (Article 52). Upon a reasoned request they can require the manufacturer to provide all information and documentation needed to demonstrate conformity (Article 13(22)). Where a product presents a significant cybersecurity risk and does not meet the requirements, the authority requires corrective action within a set period; if none is taken, it takes provisional measures to prohibit or restrict the product being made available, or to withdraw or recall it (Article 54(1) and (5)).

In addition, Article 64 provides for administrative fines. For non-compliance with the Annex I requirements and the obligations in Articles 13 and 14, the range goes up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher (paragraph 2). Other obligations, including those of importers and distributors, carry up to EUR 10 million or 2% (paragraph 3), and supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request up to EUR 5 million or 1% (paragraph 4). For manufacturers that are microenterprises or small enterprises, Article 64(10)(a) contains a special rule on fines for a missed 24-hour deadline for the early warning; how far it reaches is a question of interpretation, and the reporting obligation itself remains. Setting the fine takes into account, among other things, the nature, gravity and duration of the infringement and the size of the company (paragraph 5). For more, see CRA fines and penalties.

On implementation in Germany, the Federal Government submitted a draft act implementing Regulation (EU) 2024/2847 to the Bundestag on 26 May 2026 (Bundestag printed paper 21/6134; previously Bundesrat printed paper 260/26). The draft designates the Federal Office for Information Security (BSI) as market surveillance authority and governs the procedure for fines under Article 64; the fine ranges themselves are set by the Regulation. The Bundestag held the first reading on 11 June 2026 and referred the draft to its Committee on Internal Affairs as lead committee, and the Bundesrat raised no objections on 12 June 2026 (Bundestag printed paper 21/6512). As of the date of this article, the act has been neither adopted nor promulgated in the Federal Law Gazette.

Note that fines under Article 64 are directed at the economic operator; where that is a GmbH or AG, at the company. Whether and when members of management are personally liable is governed by other provisions, such as the duties of care under section 43 of the German Limited Liability Companies Act (GmbHG) and section 93 of the German Stock Corporation Act (AktG) or the rules of German administrative offences law, and depends on the individual case. These questions are covered in CRA and management liability.

How to check where you stand: gap analysis or CRA readiness audit

The right route depends on whether a CRA programme is already running.

CRA gap analysisCRA readiness audit
Starting pointno CRA programme yetCRA programme already running, in-house or with a service provider
Aimidentify gaps and plan measuresassess the status independently
Approachtogether with your teamssamples from the evidence, independent of the project lead
Resultgap report and prioritised action plan per productreport for management with a rating per product and recommendations by urgency

The CRA gap analysis records your products, gives a technical assessment of which of them fall under the CRA and in which role you act, for review by your legal department or counsel, and measures how far each product is from the requirements. It ends with a prioritised action plan you can use to plan budget and dates.

If implementation is already under way, the CRA readiness audit answers a different question: how much of it is evidenced? Blackfort Technology reviews the programme independently of the project lead in five review areas, with samples taken from code, processes and documents. If we have contributed to the programme ourselves, we disclose this before the engagement and you decide whether we carry out the review; parts we implemented ourselves are marked in the report as not independently assessed. The audit is neither a certificate nor an attestation and does not replace the conformity assessment under Article 32; questions that have to be decided legally are flagged for your legal department or counsel. How the review runs is described in CRA audit: process and scope; which evidence to expect is covered in Checking CRA readiness.

What you can tackle now

The reporting obligation already applies, the remaining obligations from 11 December 2027. By then, products, documentation and processes must meet the requirements, including a notified body assessment where one is required. Management can now name the people responsible, have reporting availability secured, decide on the portfolio and support periods, and ask for status reports backed by evidence. For an overview of our services, see CRA consulting and implementation.

Note: This article is general information as of 9 October 2026 and does not constitute legal advice. For an assessment of your individual case, please contact your legal department or a law firm.

Frequently asked questions

What does management need to know about the Cyber Resilience Act?+
The CRA (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements and for handling their vulnerabilities. The Article 14 reporting obligation has applied since 11 September 2026, the other obligations apply from 11 December 2027 (Article 71(2)). Management mainly decides on ownership, budget, product portfolio, support period, reporting availability and supply chain requirements.
Does the CRA also apply to products already on the market?+
Partly. Products placed on the market before 11 December 2027 are subject to the requirements only if they are substantially modified after that date (Article 69(2)). The Article 14 reporting obligation, however, expressly applies to these products as well (Article 69(3)), provided they are in scope.
How quickly must a manufacturer report an actively exploited vulnerability?+
The early warning notification is due without undue delay and in any event within 24 hours of becoming aware, the vulnerability notification within 72 hours. The final report follows no later than 14 days after a corrective or mitigating measure is available (Article 14(2)). Notifications go via the single reporting platform to the CSIRT designated as coordinator and to ENISA.
How long must the support period be?+
The manufacturer determines it so that it reflects the length of time the product is expected to be in use. It is at least five years; if the product is expected to be in use for less, it matches that period (Article 13(8)). The end date must be indicated at the time of purchase, at least by month and year (Article 13(19)).
What fines does the CRA provide for?+
For non-compliance with Annex I and the obligations in Articles 13 and 14, Article 64(2) provides for fines of up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover, whichever is higher. The amount in an individual case takes into account gravity, duration and company size, among other factors (Article 64(5)). The German implementing rules exist as a government draft (Bundestag printed paper 21/6134); as of 9 October 2026 the act has not yet been adopted. For microenterprises and small enterprises, Article 64(10)(a) contains a special rule on a missed 24-hour deadline; how far it reaches is a question of interpretation.
Is management personally liable for CRA infringements?+
Article 64 links the fine to the economic operator that committed the infringement (paragraphs 2 to 5); where the manufacturer is a GmbH or AG, that is the company. Whether members of management are personally liable is governed by other provisions, such as section 43 GmbHG, section 93 AktG or German administrative offences law, and depends on the individual case. Our article on management liability gives an overview; for your case, please contact your legal department or counsel.
Is the CRA readiness audit a certification?+
No. The audit assesses the status of a running CRA programme based on samples and reports to management. It is neither a certificate nor an attestation and does not replace the conformity assessment under Article 32, which involves a notified body depending on the product class.

Sources

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).