EU Cyber Resilience Act · Regulation (EU) 2024/2847

The CRA clock is already running. Reporting is live. CE marking lands December 2027.

If you make software or connected hardware sold in the EU, you are already inside the reporting regime, and you have until 11 December 2027 to be CE marked for cybersecurity. This briefing pack is the position as it stands, written for product and security leaders rather than lawyers.

Reporting live since 11 Sep 2026CE marking from 11 Dec 2027Up to €15m or 2.5% of turnover

Get the briefing pack

Scope, the four risk tiers, the 24-hour reporting clock, penalties and the standards timeline. One page, no vendor pitch.

We will email you the pack. No sequence you cannot leave in one click.

Three dates decide your plan

The CRA entered into force in December 2024. Most of the transition is behind us, and the obligations are now arriving in sequence.

11 Sep 2026

Reporting is already mandatory

Actively exploited vulnerabilities and severe incidents must be reported through ENISA's Single Reporting Platform. It covers products already on the market.

9 Dec 2026

Product Liability Directive transposes

Software becomes a product. A missing security update can be argued as a defect, so CRA non-compliance stops being only a fine and starts being a claim.

11 Dec 2027

CE marking or no EU sale

Essential requirements, conformity assessment, technical documentation and the EU declaration of conformity all apply in full.

The 24-hour clock

Triggered by an actively exploited vulnerability in your product or a severe incident affecting its security. The clock starts the moment you become aware with a reasonable degree of certainty.

24h

Early warning

Member States affected, whether malicious action is suspected.

72h

Notification

Product details, nature of the exploit, corrective measures taken.

14d

Final report

Within 14 days of a fix or mitigation being available.

1mo

Incident close-out

Root cause and mitigation, within a month of the 72h notification.

ENISA's reporting platform does not record when you became aware. You evidence that timestamp from your own records, and there is no API yet, so nothing submits automatically from your tooling.

Your category decides who signs off

Classification turns on core functionality. No CRA harmonised standard has been cited in the Official Journal yet, so Class I products cannot currently count on self-assessment.

Default

Everything else

Self-assessment

Apps, games, most IoT, business software installed locally.

Important · Class I

Annex III, Class I

Self-assess only if a harmonised standard is fully applied, otherwise a notified body

Identity and PAM, browsers, password managers, anti-malware, VPNs, SIEM, operating systems, routers and switches, smart home devices.

Important · Class II

Annex III, Class II

Notified body or EU certification scheme

Hypervisors and container runtimes, firewalls, intrusion detection and prevention, tamper-resistant microprocessors.

Critical · Annex IV

Critical products

European cybersecurity certification where required

Hardware devices with security boxes, smart meter gateways, smartcards and secure elements.

What is inside

  • Scope: what counts as a product with digital elements, and why pure SaaS sits outside it
  • The four conformity tiers and which one your products land in
  • The reporting workflow, including the evidence gap most teams miss
  • Penalties under Article 64 and the liability shift from December 2026
  • The standards timeline, including the dates that have already moved
  • A 30 / 90 / 2027 readiness plan you can lift straight into a programme

The regulation tells you to assess your product risk. We tell you what it costs.

Astragar classifies your products against the CRA tiers, maps the gap to Annex I, and puts a euro figure on the exposure that remains. The number a board can act on and an underwriter will recognise.

Book a 20-minute scoping call

This pack is a business briefing, not legal advice. Confirm product classification and your conformity route with EU regulatory counsel. Regulatory position as of 11 September 2026.

©Astragar All rights reserved.