The CRA is the first EU regulation to put cybersecurity duties on the product rather than the organisation, which is why it catches companies that have never dealt with a cybersecurity regulator. Scope turns on whether you place a product with digital elements on the EU market and in what role. The reporting duties start well before the full requirements do, so the calendar matters as much as the substance.
11 pages on Cyber Resilience Act, in the order the work happens. Jump to the stage you are at, or read straight through.
Work out whether your product is covered and whether you are the manufacturer, importer or distributor.
Put the staggered dates in your plan and size the exposure for missing them.
Budget conformity work, vulnerability handling and the SBOM effort.
See where the CRA overlaps NIS2 and DORA, then pick tooling that produces conformity evidence.
These sit under another subject but bear directly on Cyber Resilience Act.
The free compliance check runs the Cyber Resilience Act gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users