What is the EU Cyber Resilience Act? Your Essential Guide

The EU Cyber Resilience Act (CRA) sets uniform cybersecurity standards for products with digital elements sold on the European market. Affected organizations can no longer treat product security simply as good practice or something to address during final testing before release. Instead, they will need to consider cybersecurity throughout the product lifecycle, from design and development through to security updates and end-of-support.

Beyond manufacturers, the regulation imposes responsibilities on importers and distributors, making CRA compliance relevant across the product supply chain.

Although most CRA requirements will not apply until December 2027, some obligations are already active. Relevant parties therefore need to understand which products are in scope, what role they play under the regulation, and what they will need to do to comply.

Cyber Resilience Act Timeline

DateRequirement
10 December 2024  CRA entered into force  
11 June 2026  Rules concerning notification of conformity assessment bodies began applying  
11 September 2026  Article 14 vulnerability and severe incident reporting requirements began applying  
11 December 2027  CRA becomes fully applicable  

Who Does the Cyber Resilience Act Apply to?

The CRA places obligations on the economic operators (manufacturers, importers and distributors) involved in bringing products with digital elements to the EU market. Manufacturers carry the largest share of CRA obligations; importers and distributors are then responsible for verifying that products comply with the CRA before making them available.

What About Organizations Outside the EU?

The CRA is not limited to organizations headquartered in the European Union, as the focus of the regulation is on products available on the EU market. As such, manufacturers based in the US, UK, Asia or elsewhere can still have CRA obligations if their products are sold in the EU. Those products may also bring EU-based importers and distributors into the compliance chain.

What Does the CRA Require?

The CRA requires manufacturers to address cybersecurity in two areas: how products are designed and built, and how vulnerabilities are managed after those products reach the market. Manufacturers must also define a support period during which they will handle vulnerabilities and provide the necessary security support. In most cases, that period is at least five years.

Secure by Design Product Requirements

Products with digital elements must be designed, developed, and produced with cybersecurity risks in mind. Depending on the product and its risk profile, this includes measures to:

  • Reduce exploitable vulnerabilities and attack surfaces.
  • Apply appropriate access controls and other security mechanisms.
  • Protect data and essential product functions.
  • Provide appropriate security logging and monitoring where relevant.

The key point is that security needs to be considered by design and by default, rather than added shortly before a product is released. Manufacturers must also assess cybersecurity risks and document how the product meets the applicable CRA requirements.

Vulnerability Management Requirements

The CRA also creates ongoing responsibilities once a product is on the market. Manufacturers must have processes to identify, document and remediate vulnerabilities, including those reported by external researchers or found in third-party components.

They are also expected to provide security updates and maintain a coordinated vulnerability disclosure process. Where a manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of a product, it must report it through the CRA reporting process. These reporting obligations have applied since 11 September 2026. Under the reporting guidelines, they must:

  • Issue an early warning within 24 hours.
  • Issue a main notification within 72 hours.
  • For exploited vulnerabilities, deliver a final report no later than 14 days after a corrective or mitigating measure is available.
  • For severe incidents, deliver a final report within one month of the 72-hour notification.

What Products are Covered by the CRA?

The CRA applies to most products made available on the EU market that connect either directly or indirectly to a network. This includes hardware like IoT devices and computers, as well as software ranging from video games to industrial control systems. Compliant products will display the CE marking.

Some products are excluded from the CRA because they are already covered by other EU legislation, including medical devices and cars.

How Can Organizations Prepare for the Cyber Resilience Act?

Organizations should already have vulnerability reporting processes in place to comply with active obligations under the CRA. Organizations should use the remaining implementation period to put the processes, testing and evidence they will need in place to comply with the full requirements. Below are some key areas to focus on:

  • Understand what’s in scope: Build an accurate inventory of the products with digital elements you make available in the EU, including the software and components they depend on.
  • Build security into the product lifecycle: Review where security testing fits into development, release and ongoing maintenance, rather than treating security as a final check.
  • Strengthen vulnerability management: Make sure you can identify, assess, remediate and report vulnerabilities quickly, with clear responsibilities and escalation paths.
  • Keep evidence of security activities: Maintain records of risk assessments, testing and remediation so you can demonstrate how applicable CRA requirements are being addressed.
  • Improve visibility of your attack surface: Environments change constantly. Continuous asset discovery and risk-based testing can help ensure new or unmanaged applications don’t fall outside your security program.

How Outpost24 Supports Your CRA Compliance Efforts

Outpost24’s unified platform supports an important part of CRA readiness by helping you maintain visibility of your external attack surface and test applications for vulnerabilities throughout their lifecycle.

  • CyberFlex combines PTaaS and EASM, replacing fixed annual penetration tests with a continuous, flexible security testing program. It identifies known, unknown and unmanaged applications, including shadow IT and newly deployed assets, so testing reflects your real environment. Teams can then use their testing budget where it matters most without waiting for the next scheduled assessment.
  • OutscanNX supports CRA vulnerability handling requirements with continuous, risk-based vulnerability management for all of your in-scope products. By combining real-world exploit intelligence with CVSS, KEV, EPSS, and asset context, OutscanNX helps identify which vulnerabilities pose the greatest risk so you can prioritize remediation accordingly. Solution- and delta-based reporting provides measurable evidence of remediation progress and risk reduction over time.
  • Outpost24 Digital Risk Protection strengthens the continuous cybersecurity risk awareness needed to protect products throughout their lifecycle. It helps surface emerging threats and external indicators that can inform ongoing cybersecurity risk assessments, so security teams can identify risks earlier and act.

The result is a security testing program that can adapt as products and risks change, helping organizations test according to risk and build evidence to support CRA compliance.

If you’re interested in seeing how Outpost24 can help you comply with the CRA and other regulations, book a demo today.

About the Author

Daniel Imber Cybersecurity Writer, Outpost24

Daniel is a cybersecurity writer based in the UK, with more than four years' experience writing about B2B technology and cybersecurity.