Cyber Resilience Act (CRA): a practical guide

The EU Cyber Resilience Act (CRA) in practice: who it covers, 24-hour reporting since 11 September 2026, Annex I, fines and what to do before December 2027.

Updated

In short

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements: software, and hardware that runs software or connects to a network. It has been in force since 10 December 2024 and applies in stages.

What matters right now: the manufacturer's reporting duty has applied since 11 September 2026. An actively exploited vulnerability or a severe incident affecting a product's security needs an early warning within 24 hours. The duty also covers products placed on the market before 11 December 2027. Most other obligations, including the essential requirements and CE marking, apply from 11 December 2027.

In Finland, the Regulation is supplemented by Act 439/2026 on the cyber resilience of certain products and on cybersecurity certification (laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista), in force since 1 June 2026; its sections apply in stages.

Who the CRA applies to

The CRA covers products made available on the EU market and the economic operators who put them there. Traficom's National Cyber Security Centre gives examples such as smart speakers, hard drives, image-editing software, games, routers, browsers, smart-home products, wearables and smart toys.

The manufacturer is whoever develops or manufactures a product, or has it made, and markets it under its own name or trademark, whether it is paid for, monetised or free. Most obligations fall on the manufacturer. Importers and distributors check the CE marking and required documents and tell the manufacturer about vulnerabilities they learn of. An importer or distributor that sells a product under its own name, or substantially modifies it, takes on the manufacturer's obligations.

An open-source software steward, such as a foundation that supports the development of open source intended for commercial use on a sustained basis, has a lighter set of duties and cannot be fined. Non-commercial open source is outside the CRA.

Also outside it are products with their own sector rules, such as medical and in vitro diagnostic devices, certain vehicles, marine equipment and certified aviation equipment, and products made exclusively for national security or defence. Pure software as a service is mostly out of scope unless it is a product's remote data processing: software the manufacturer is responsible for, without which the product could not perform one of its functions. NIS2 may also apply to the service.

Key dates

Four dates matter for the CRA. For a manufacturer, the two that count are September 2026 and December 2027.

  • 10 December 2024: the Regulation entered into force
  • 11 June 2026: the rules on notified bodies started to apply
  • 11 September 2026: manufacturers' reporting of actively exploited vulnerabilities and severe incidents
  • 11 December 2027: essential requirements, conformity assessment and CE marking

Reporting: 24 hours, 72 hours, final report

The reporting duty is the manufacturer's. It starts when the manufacturer becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting the product's security. Actively exploited means there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A good-faith finding by a security researcher does not trigger a report on its own, though from 11 December 2027 the manufacturer must still handle it under its vulnerability process.

Reports are filed on ENISA's Single Reporting Platform (SRP). The early warning goes to the CSIRT acting as coordinator and to ENISA. In Finland, that CSIRT is Traficom's National Cyber Security Centre (Kyberturvallisuuskeskus).

  • Early warning within 24 hours of becoming aware
  • Notification within 72 hours, with more detail
  • Final report on a vulnerability no later than 14 days after a fix is available
  • Final report on a severe incident within one month of the notification

The essential requirements in plain language

Annex I has two parts. Part I is about the product itself: it is designed, developed and produced to a level of cybersecurity appropriate to the risks. In practice, it must not be placed on the market with a known exploitable vulnerability, it ships with a secure default configuration, it is protected against unauthorised access, and its attack surface is limited.

Part II is about handling vulnerabilities throughout the support period. From 11 December 2027 the manufacturer must, under Part II and Article 13:

  • keep a software bill of materials (SBOM) showing which components the product is made of
  • have a coordinated vulnerability disclosure (CVD) policy and a contact address for reporting vulnerabilities
  • provide security updates, as a rule free of charge
  • set a support period of at least five years, or the expected use time if that is shorter, and state it clearly to the buyer
  • keep each security update available for ten years after it is issued, or for the rest of the support period if that is longer
  • carry out the conformity assessment, draw up the technical documentation and affix the CE marking

Product classes and conformity assessment

Most products are self-assessed by the manufacturer. Important products fall into two classes. Class I products, such as password managers and VPNs, can be self-assessed only where harmonised standards are applied. Class II products, such as firewalls, need a notified body, unless they are free and open-source software whose technical documentation is public. CE marking applies per unit: units placed on the market from 11 December 2027 need it, while earlier units do not, unless they are substantially modified.

National rules, with Finland as an example

The CRA is a regulation, binding in its entirety and directly applicable in every member state (Article 71). National authorities supervise it, and national acts can supplement it, so check your own country's. In Finland, Act 439/2026 supplements the Regulation. Traficom is the market surveillance authority and checks that products on the market meet the requirements. Its National Cyber Security Centre is also the CSIRT that Finnish manufacturers' reports are routed to. The Centre offers a CRA Compass tool, in Finnish, to check whether your product is in scope.

Penalties

Article 64 sets three ceilings for administrative fines: up to €15 million or 2.5 % of worldwide annual turnover for breaching the essential requirements or the manufacturer's obligations in Articles 13 and 14; up to €10 million or 2 % for other obligations; and up to €5 million or 1 % for misleading information to authorities, whichever is higher in each case. Importers and distributors can be fined too. The Regulation's fine ceilings apply from 11 December 2027.

Micro and small enterprises cannot be fined for missing the 24-hour early-warning deadline, and open-source stewards cannot be fined at all. In Finland, administrative penalty payments for CRA breaches are set out in sections 31–36 of Act 439/2026. Beyond fines, the market surveillance authority can require a product to be withdrawn.

What to do now

Reporting is already live, and December 2027 is closer than many product cycles. Take these six steps in order.

  • Inventory your products: list every piece of software and hardware you sell or distribute, and check which are in scope
  • Determine your role for each: manufacturer, importer or distributor, and whether you modify products sold under your name
  • Define a support period per product, and make sure sales and contracts promise the same
  • Set up a coordinated vulnerability disclosure policy and publish a contact address for researchers and customers
  • Prepare the 24-hour process: who decides whether a vulnerability is actively exploited, who files on ENISA's platform, and who is on call at the weekend
  • Train your staff: support, sales and developers recognise a vulnerability report and know whom to take it to at once

Not the EU Cybersecurity Act, and not NIS2

The EU Cybersecurity Act, Regulation (EU) 2019/881, is a different law. It gave ENISA, the EU Agency for Cybersecurity, a permanent mandate and created the EU cybersecurity certification framework, under which products, services and processes can be certified. The cybersecurity certification in the name of Finland's Act 439/2026 refers to that framework.

The NIS2 Directive (EU) 2022/2555, implemented in Finland by Act 124/2025 (kyberturvallisuuslaki, known in English as Finland's Cybersecurity Act), is about organisations, not products. It requires mainly medium-sized and large organisations in listed sectors, and some others regardless of size, to manage their cybersecurity risks and report significant incidents. One company can be in scope of both: as a manufacturer under the CRA and as an entity under NIS2. Our guide to NIS2 training requirements covers the latter.

How Cyberact helps

The CRA does not require staff training, but reporting and vulnerability handling only work if people know what to do. Cyberact has a five-lesson module for the people who build, sell and support the product: why your company is a manufacturer, the report that starts the 24-hour clock, the researcher's finding, the SBOM, and what you may promise about updates. The management path has its own five-lesson module on your role, reporting readiness, CE marking, fines and the open source inside your product.

Each lesson takes two minutes, and the manager console turns completions into a report. Start for free at cyberact.io: your account is ready at once.

Sources

Checked against primary sources on 25 September 2026.

  • Cyber Resilience Act, Regulation (EU) 2024/2847, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
  • Act 439/2026 on the cyber resilience of certain products and on cybersecurity certification (Finnish), Finlex: https://www.finlex.fi/fi/lainsaadanto/2026/439
  • Traficom National Cyber Security Centre, Cyber Resilience Act: https://www.kyberturvallisuuskeskus.fi/en/our-activities/regulation-and-supervision/cyber-resilience-act-cra
  • European Commission, Cyber Resilience Act implementation – Frequently asked questions: https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-implementation-frequently-asked-questions
  • EU Cybersecurity Act, Regulation (EU) 2019/881, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2019/881/oj

Frequently asked questions

What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements, meaning software and connected hardware. It has been in force since 10 December 2024, and most of it applies from 11 December 2027.
When do CRA reporting obligations start?
On 11 September 2026. Manufacturers must send an early warning within 24 hours and a notification within 72 hours of becoming aware of an actively exploited vulnerability or a severe incident, through ENISA's Single Reporting Platform. This also covers products placed on the market before 11 December 2027.
Does the CRA apply to SaaS?
Mostly not. The CRA regulates products, not services. A cloud service is in scope only where it is a product's remote data processing: software the manufacturer is responsible for, without which the product could not perform one of its functions. NIS2 may also apply to the service.
Is the Cyber Resilience Act the same as the EU Cybersecurity Act?
No. The Cyber Resilience Act (EU) 2024/2847 sets requirements for products. The EU Cybersecurity Act, Regulation (EU) 2019/881, covers ENISA's mandate and the EU cybersecurity certification framework, which is mostly voluntary. The names are similar; the obligations are not.
Who supervises the CRA in Finland?
Traficom is the market surveillance authority under Act 439/2026. Traficom's National Cyber Security Centre is also the CSIRT that Finnish manufacturers' reports reach through ENISA's platform.
What are the fines under the Cyber Resilience Act?
Under Article 64, up to €15 million or 2.5 % of worldwide annual turnover for breaching the essential requirements or Articles 13 and 14, up to €10 million or 2 % for other obligations, and up to €5 million or 1 % for misleading information, whichever is higher. These ceilings apply from 11 December 2027. A product can also be ordered off the market.

Read next

Training your team will actually finish

Cyberact teaches security and practical AI in two minutes a day, and keeps a record of what each person knows.