NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Cyber Resilience Act Requirements Explained
Learn

Cyber Resilience Act Requirements Explained

·Alexander Sverdlov

The Cyber Resilience Act requirements sit in three places in Regulation (EU) 2024/2847. Annex I sets the essential cybersecurity requirements: 13 security properties every product with digital elements must have (Part I) and 8 vulnerability handling duties the manufacturer must run for as long as the product is supported (Part II). Article 13 turns those into manufacturer obligations: a documented risk assessment, a support period of at least five years, technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking. Article 14 adds reporting: an actively exploited vulnerability or a severe incident must reach the designated CSIRT and ENISA with an early warning within 24 hours.

The timing is no longer theoretical. Article 14 has applied since 11 September 2026, and Article 69(3) extends it to products placed on the market before the rest of the Regulation applies. Everything else, including Annex I, the conformity assessment and CE marking, applies from 11 December 2027.

RequirementWhere it livesWhat it asks forApplies from
Product security propertiesAnnex I, Part I13 properties, from no known exploitable vulnerabilities at release to secure data deletion.11 December 2027
Vulnerability handlingAnnex I, Part II8 duties, including an SBOM, regular security testing, coordinated disclosure and free security updates.11 December 2027
Risk assessmentArticle 13(2) and (3)A documented cybersecurity risk assessment that shapes design and is updated through the support period.11 December 2027
Support periodArticle 13(8)At least five years, or the expected use time if the product is used for less.11 December 2027
Technical file and CE markingArticles 13(12), 28, 30, 31, 32Technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking.11 December 2027
ReportingArticle 1424 hour early warning, 72 hour notification and a final report, via the single reporting platform.11 September 2026
Cyber Resilience Act requirements by the numbers: 13 product properties in Annex I Part I, 8 vulnerability handling duties in Part II, a five year minimum support period and a ten year retention period for the technical file

What are the essential cybersecurity requirements in Annex I, Part I?

Part I opens with a general rule: products must be designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks. Point (2) then lists 13 properties, each applied on the basis of the manufacturer's risk assessment and where applicable. In summary, a product must:

PointThe product must
(a)Be made available without known exploitable vulnerabilities.
(b)Ship with a secure by default configuration, with the possibility to reset it to its original state.
(c)Allow vulnerabilities to be fixed through security updates, with automatic updates on by default where applicable and a clear opt out.
(d)Protect against unauthorised access through authentication, identity or access management, and report possible unauthorised access.
(e)Protect the confidentiality of data, for example by encrypting it at rest and in transit.
(f)Protect the integrity of data, commands, programs and configuration, and report corruption.
(g)Process only the data needed for its intended purpose.
(h)Protect the availability of essential functions, including resilience against denial of service.
(i)Minimise its own negative impact on other devices or networks.
(j)Limit attack surfaces, including external interfaces.
(k)Reduce the impact of an incident through exploitation mitigation.
(l)Record and monitor relevant internal activity, with a user opt out.
(m)Let users securely and permanently remove all data and settings.

The phrase "on the basis of the cybersecurity risk assessment" matters. Article 13(3) requires the risk assessment to say whether each point in Part I(2) applies and how it is implemented, and Article 13(4) requires a clear justification in the technical documentation for any essential requirement that does not apply. Skipping a point is allowed. Skipping it silently is not.

What does Annex I, Part II require for vulnerability handling?

Part II is a set of processes, not product properties, and it is where most manufacturers find the real work. The manufacturer must:

PointThe manufacturer must
(1)Identify and document vulnerabilities and components, including a software bill of materials in a commonly used, machine readable format covering at least the top level dependencies.
(2)Address and remediate vulnerabilities without delay, and ship security updates separately from functionality updates where technically feasible.
(3)Apply effective and regular tests and reviews of the product's security.
(4)Publicly disclose information about fixed vulnerabilities once an update is available, with a narrow option to delay in duly justified cases.
(5)Put in place and enforce a coordinated vulnerability disclosure policy.
(6)Facilitate the sharing of vulnerability information, including a contact address for reporting.
(7)Provide mechanisms to distribute updates securely, automatically where applicable for security updates.
(8)Disseminate security updates without delay and free of charge, with advisory messages, unless otherwise agreed for a tailor made product with a business user.

Article 13(8) ties Part II to the support period: vulnerabilities must be handled in line with Part II for the whole of it. Article 13(9) adds that each security update issued during the support period must stay available for at least 10 years or the rest of the support period, whichever is longer.

Venvera CRA controls page listing controls CRA-1 to CRA-24 grouped by governance, risk assessment and secure development, with implementation status and coverage

What must manufacturers do under Article 13?

Article 13 runs to 25 paragraphs. The ones that generate most of the work are these.

A documented risk assessment

Article 13(2) and (3) require an assessment of cybersecurity risks, considered through planning, design, development, production, delivery and maintenance, documented and updated during the support period. It goes into the technical documentation.

Due diligence on components

Article 13(5) requires due diligence when integrating third party components, including free and open source components. Article 13(6) requires the manufacturer to report a vulnerability it finds in a component to whoever maintains that component.

A support period, and saying when it ends

Article 13(8) sets the support period at a minimum of five years, unless the product is expected to be in use for less, in which case it matches the expected use time. Article 13(19) requires the end date, at least month and year, to be clear at the time of purchase.

Documentation, conformity and CE marking

Before placing a product on the market, Article 13(12) requires the technical documentation under Article 31, the conformity assessment under Article 32, the EU declaration of conformity under Article 28 and the CE marking under Article 30. Article 13(13) requires the documentation and declaration to be kept for at least 10 years or the support period, whichever is longer.

A single point of contact

Article 13(17) requires a single point of contact that lets users report vulnerabilities directly, and that is not limited to automated tools.

The core Cyber Resilience Act manufacturer duties: the risk assessment, Annex I Parts I and II, the Article 31 technical file, the Article 32 conformity assessment and Article 14 reporting

Which conformity assessment route applies?

Article 32 sets the route by product class, which our guide to Cyber Resilience Act scope explains in detail. Default products can use internal control (module A). Important class I products in Annex III can also use module A, but only where the manufacturer applies harmonised standards, common specifications or a certification scheme at assurance level at least substantial in full. Otherwise they need EU type examination (module B with module C) or full quality assurance (module H). Important class II products must use module B with C, module H, or a certification scheme at assurance level at least substantial. Critical products in Annex IV use a European cybersecurity certification scheme where Article 8(1) requires one, and otherwise the class II routes.

What are the Article 14 reporting requirements?

Article 14 has two triggers with the same first two clocks. Both go simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform in Article 16. The Commission states that ENISA's platform has been operational since 11 September 2026.

StageActively exploited vulnerabilitySevere incident affecting product security
Early warningWithin 24 hours of becoming aware, Art. 14(2)(a)Within 24 hours of becoming aware, Art. 14(4)(a)
NotificationWithin 72 hours of becoming aware, Art. 14(2)(b)Within 72 hours of becoming aware, Art. 14(4)(b)
Final reportNo later than 14 days after a corrective or mitigating measure is available, Art. 14(2)(c)Within one month of the incident notification, Art. 14(4)(c)

Article 14(5) defines a severe incident: one that affects or can affect the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that leads or can lead to malicious code in the product or in a user's systems. Article 14(8) adds a duty to inform impacted users, and where appropriate all users, about the vulnerability or incident and what they can do about it.

The Article 14 reporting clock for an actively exploited vulnerability: early warning within 24 hours, notification within 72 hours and a final report within 14 days of a fix being available

What do importers and distributors have to do?

Importers, under Article 19, may place a product on the market only if it meets Annex I. Before doing so they must ensure the manufacturer carried out the conformity assessment, drew up the technical documentation, affixed the CE marking and supplied the declaration of conformity and user information. Distributors, under Article 20, must act with due care and verify the CE marking and the required documents before making the product available.

Article 21 is the trap: an importer or distributor that places a product on the market under its own name or trademark, or carries out a substantial modification, is treated as the manufacturer and takes on Articles 13 and 14 in full. Who counts as which role is covered in our guide to who must comply with the Cyber Resilience Act.

Cyber Resilience Act economic operator duties: manufacturers under Articles 13 and 14, importers under Article 19, distributors under Article 20, and own brand sellers treated as manufacturers under Article 21

When does each requirement apply?

Article 71 staggers the dates. Chapter IV, the rules on notifying conformity assessment bodies, has applied since 11 June 2026. Article 14 has applied since 11 September 2026. Everything else applies from 11 December 2027. Article 69(2) means products placed on the market before 11 December 2027 only have to meet the rest of the Regulation if they are substantially modified after that date, but Article 69(3) makes Article 14 apply to them regardless. The full calendar is in our guide to Cyber Resilience Act deadlines for 2026 and 2027.

Cyber Resilience Act dates under Article 71: entry into force on 10 December 2024, notified body rules from 11 June 2026, Article 14 reporting from 11 September 2026 and everything else from 11 December 2027

What the other results get wrong

The first error is timing. Some guides say the Regulation applies in full three years after the reporting date. Reporting has applied since 11 September 2026, and full application follows 15 months later, on 11 December 2027.

The second is flattening Annex I into a single list of "requirements". Part I describes the product and is assessed at the point it is placed on the market. Part II describes processes that must keep running for the whole support period. A product can pass Part I on release day and fall out of compliance a year later because Part II stopped.

The third is treating the SBOM as the whole of vulnerability handling. It is point (1) of eight. Regular security testing, coordinated disclosure, free and prompt security updates and public disclosure of fixed vulnerabilities carry equal weight, and Article 64(2) puts the whole of Annex I in the top penalty tier of 15 million euros or 2.5% of worldwide annual turnover, whichever is higher. The tiers are set out in our guide to Cyber Resilience Act fines and penalties.

Where do you stand?

Fill this in for one product. A blank row is a gap.

QuestionYour answerRequirement
Could you file an early warning within 24 hours of learning a vulnerability is being exploited?Article 14(2)(a), in force now
Is there a documented risk assessment that addresses every point in Annex I, Part I(2)?Article 13(3)
Can you produce a machine readable SBOM for the current release?Annex I, Part II(1)
Is your coordinated vulnerability disclosure policy published, with a contact address?Annex I, Part II(5) and (6)
What is the support period, and is its end date shown at purchase?Article 13(8) and (19)
Which conformity assessment route does the product's class require?Article 32

Our CRA compliance checklist turns these into a working list, and a free compliance check gives you a baseline across the CRA areas. In Venvera, the CRA module tracks the obligations as controls with a gap assessment. It documents and tracks compliance; it does not test products or analyse code itself.

Venvera CRA gap assessment page listing a completed assessment scored at 58 percent and a second assessment in progress
The bottom line on Cyber Resilience Act requirements: the Regulation governs how a product is built and supported, not only what ships

Frequently asked questions

Do the CRA requirements apply to software?

Yes. A product with digital elements includes software, and remote data processing solutions that belong to it. Scope turns on whether the product has a data connection and is made available on the EU market in the course of a commercial activity.

Is an SBOM mandatory under the CRA?

Yes. Annex I, Part II, point (1) requires a software bill of materials in a commonly used, machine readable format covering at least the top level dependencies. It belongs in the technical documentation under Annex VII. Making it available to users is the manufacturer's choice, under Annex II, point 9.

How long must security updates be provided?

For the support period, which Article 13(8) sets at a minimum of five years unless the product is expected to be in use for less. Each security update must then remain available for at least 10 years after it is issued or for the rest of the support period, whichever is longer.

Do the reporting duties apply to products already on the market?

Yes. Article 69(3) applies Article 14 to all in scope products placed on the market before 11 December 2027, so older products are covered from 11 September 2026.

Do we need a notified body?

Not for default products, which can self assess. Important class I products need one unless harmonised standards, common specifications or a qualifying certification scheme are applied in full, and important class II products need a third party route or a certification scheme.

Primary sources

Requirements, articles and dates are taken from Articles 13, 14, 19, 20, 21, 32, 64, 69 and 71 and Annex I of Regulation (EU) 2024/2847, checked against its published corrigenda. The status of the single reporting platform is from the European Commission's CRA reporting obligations page. Annex I points are summarised; read the full text before relying on a specific provision.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING