Framework reference
CRA for EU B2B software companies.
The CRA covers hardware and software products with digital elements made available on the EU market. Manufacturer reporting starts on 11 September 2026; the main requirements apply from 11 December 2027.
Reviewed on
- Kaamos support
- Supported in Kaamos
- Category
- Binding EU regulations
- Obligation
- Binding
- Last updated
The obligation, in the act's words
When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I.
The duty attaches to placing the product on the market, so the evidence has to exist before release, not at the first audit afterwards.
Who it applies to
- Manufacturers develop products, or have them developed, and market them under their name or trademark. Scope includes separately marketed components and products whose intended or foreseeable use involves a direct or indirect connection to a device or network.
- Remote data processing is included where software is developed by, or under the responsibility of, the manufacturer and its absence would prevent a product function. A SaaS label alone does not establish this boundary.
- Products supplied outside commercial activity and certain products covered by other EU legislation are excluded. Reporting also covers in-scope products placed on the market before 11 December 2027.
What you need to do
- From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents affecting product security: early warning within 24 hours of awareness, followed by notification within 72 hours.
- For an actively exploited vulnerability, submit the final report within 14 days after a corrective or mitigating measure is available.
- For a severe security incident, submit the final report within one month after the 72-hour notification.
- Submit through the CRA Single Reporting Platform, established by ENISA, to the relevant national CSIRT and ENISA. The main CRA application date is 11 December 2027.
How Kaamos helps
- Organize product-security and vulnerability-handling requirements.
- Link risks, controls and evidence to the products in scope.
- Track preparation for reporting and conformity-assessment duties.
First reporting-day checklist
- Scope: identify the product, manufacturer and any function-dependent remote processing.
- Responsible owner: identify who will submit notifications and track the reporting deadlines.
- Reporting route: prepare access to the CRA Single Reporting Platform and identify the relevant national CSIRT.
- Evidence: retain awareness and submission timestamps, product and event details, and the date a corrective or mitigating measure became available so the reporting sequence can be traced.
Sources
Company profiles this applies to
- EU SaaS company building or embedding AI — watches Cyber Resilience Act as it grows.
Supported in Kaamos
Manage CRA controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.