The Cyber Resilience Act requirements sit in three places in Regulation (EU) 2024/2847. Annex I sets the essential cybersecurity requirements: 13 security properties every product with digital elements must have (Part I) and 8 vulnerability handling duties the manufacturer must run for as long as the product is supported (Part II). Article 13 turns those into manufacturer obligations: a documented risk assessment, a support period of at least five years, technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking. Article 14 adds reporting: an actively exploited vulnerability or a severe incident must reach the designated CSIRT and ENISA with an early warning within 24 hours.
The timing is no longer theoretical. Article 14 has applied since 11 September 2026, and Article 69(3) extends it to products placed on the market before the rest of the Regulation applies. Everything else, including Annex I, the conformity assessment and CE marking, applies from 11 December 2027.
| Requirement | Where it lives | What it asks for | Applies from |
|---|---|---|---|
| Product security properties | Annex I, Part I | 13 properties, from no known exploitable vulnerabilities at release to secure data deletion. | 11 December 2027 |
| Vulnerability handling | Annex I, Part II | 8 duties, including an SBOM, regular security testing, coordinated disclosure and free security updates. | 11 December 2027 |
| Risk assessment | Article 13(2) and (3) | A documented cybersecurity risk assessment that shapes design and is updated through the support period. | 11 December 2027 |
| Support period | Article 13(8) | At least five years, or the expected use time if the product is used for less. | 11 December 2027 |
| Technical file and CE marking | Articles 13(12), 28, 30, 31, 32 | Technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking. | 11 December 2027 |
| Reporting | Article 14 | 24 hour early warning, 72 hour notification and a final report, via the single reporting platform. | 11 September 2026 |
What are the essential cybersecurity requirements in Annex I, Part I?
Part I opens with a general rule: products must be designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks. Point (2) then lists 13 properties, each applied on the basis of the manufacturer's risk assessment and where applicable. In summary, a product must:
| Point | The product must |
|---|---|
| (a) | Be made available without known exploitable vulnerabilities. |
| (b) | Ship with a secure by default configuration, with the possibility to reset it to its original state. |
| (c) | Allow vulnerabilities to be fixed through security updates, with automatic updates on by default where applicable and a clear opt out. |
| (d) | Protect against unauthorised access through authentication, identity or access management, and report possible unauthorised access. |
| (e) | Protect the confidentiality of data, for example by encrypting it at rest and in transit. |
| (f) | Protect the integrity of data, commands, programs and configuration, and report corruption. |
| (g) | Process only the data needed for its intended purpose. |
| (h) | Protect the availability of essential functions, including resilience against denial of service. |
| (i) | Minimise its own negative impact on other devices or networks. |
| (j) | Limit attack surfaces, including external interfaces. |
| (k) | Reduce the impact of an incident through exploitation mitigation. |
| (l) | Record and monitor relevant internal activity, with a user opt out. |
| (m) | Let users securely and permanently remove all data and settings. |
The phrase "on the basis of the cybersecurity risk assessment" matters. Article 13(3) requires the risk assessment to say whether each point in Part I(2) applies and how it is implemented, and Article 13(4) requires a clear justification in the technical documentation for any essential requirement that does not apply. Skipping a point is allowed. Skipping it silently is not.
What does Annex I, Part II require for vulnerability handling?
Part II is a set of processes, not product properties, and it is where most manufacturers find the real work. The manufacturer must:
| Point | The manufacturer must |
|---|---|
| (1) | Identify and document vulnerabilities and components, including a software bill of materials in a commonly used, machine readable format covering at least the top level dependencies. |
| (2) | Address and remediate vulnerabilities without delay, and ship security updates separately from functionality updates where technically feasible. |
| (3) | Apply effective and regular tests and reviews of the product's security. |
| (4) | Publicly disclose information about fixed vulnerabilities once an update is available, with a narrow option to delay in duly justified cases. |
| (5) | Put in place and enforce a coordinated vulnerability disclosure policy. |
| (6) | Facilitate the sharing of vulnerability information, including a contact address for reporting. |
| (7) | Provide mechanisms to distribute updates securely, automatically where applicable for security updates. |
| (8) | Disseminate security updates without delay and free of charge, with advisory messages, unless otherwise agreed for a tailor made product with a business user. |
Article 13(8) ties Part II to the support period: vulnerabilities must be handled in line with Part II for the whole of it. Article 13(9) adds that each security update issued during the support period must stay available for at least 10 years or the rest of the support period, whichever is longer.

What must manufacturers do under Article 13?
Article 13 runs to 25 paragraphs. The ones that generate most of the work are these.
A documented risk assessment
Article 13(2) and (3) require an assessment of cybersecurity risks, considered through planning, design, development, production, delivery and maintenance, documented and updated during the support period. It goes into the technical documentation.
Due diligence on components
Article 13(5) requires due diligence when integrating third party components, including free and open source components. Article 13(6) requires the manufacturer to report a vulnerability it finds in a component to whoever maintains that component.
A support period, and saying when it ends
Article 13(8) sets the support period at a minimum of five years, unless the product is expected to be in use for less, in which case it matches the expected use time. Article 13(19) requires the end date, at least month and year, to be clear at the time of purchase.
Documentation, conformity and CE marking
Before placing a product on the market, Article 13(12) requires the technical documentation under Article 31, the conformity assessment under Article 32, the EU declaration of conformity under Article 28 and the CE marking under Article 30. Article 13(13) requires the documentation and declaration to be kept for at least 10 years or the support period, whichever is longer.
A single point of contact
Article 13(17) requires a single point of contact that lets users report vulnerabilities directly, and that is not limited to automated tools.
Which conformity assessment route applies?
Article 32 sets the route by product class, which our guide to Cyber Resilience Act scope explains in detail. Default products can use internal control (module A). Important class I products in Annex III can also use module A, but only where the manufacturer applies harmonised standards, common specifications or a certification scheme at assurance level at least substantial in full. Otherwise they need EU type examination (module B with module C) or full quality assurance (module H). Important class II products must use module B with C, module H, or a certification scheme at assurance level at least substantial. Critical products in Annex IV use a European cybersecurity certification scheme where Article 8(1) requires one, and otherwise the class II routes.
What are the Article 14 reporting requirements?
Article 14 has two triggers with the same first two clocks. Both go simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform in Article 16. The Commission states that ENISA's platform has been operational since 11 September 2026.
| Stage | Actively exploited vulnerability | Severe incident affecting product security |
|---|---|---|
| Early warning | Within 24 hours of becoming aware, Art. 14(2)(a) | Within 24 hours of becoming aware, Art. 14(4)(a) |
| Notification | Within 72 hours of becoming aware, Art. 14(2)(b) | Within 72 hours of becoming aware, Art. 14(4)(b) |
| Final report | No later than 14 days after a corrective or mitigating measure is available, Art. 14(2)(c) | Within one month of the incident notification, Art. 14(4)(c) |
Article 14(5) defines a severe incident: one that affects or can affect the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that leads or can lead to malicious code in the product or in a user's systems. Article 14(8) adds a duty to inform impacted users, and where appropriate all users, about the vulnerability or incident and what they can do about it.
What do importers and distributors have to do?
Importers, under Article 19, may place a product on the market only if it meets Annex I. Before doing so they must ensure the manufacturer carried out the conformity assessment, drew up the technical documentation, affixed the CE marking and supplied the declaration of conformity and user information. Distributors, under Article 20, must act with due care and verify the CE marking and the required documents before making the product available.
Article 21 is the trap: an importer or distributor that places a product on the market under its own name or trademark, or carries out a substantial modification, is treated as the manufacturer and takes on Articles 13 and 14 in full. Who counts as which role is covered in our guide to who must comply with the Cyber Resilience Act.
When does each requirement apply?
Article 71 staggers the dates. Chapter IV, the rules on notifying conformity assessment bodies, has applied since 11 June 2026. Article 14 has applied since 11 September 2026. Everything else applies from 11 December 2027. Article 69(2) means products placed on the market before 11 December 2027 only have to meet the rest of the Regulation if they are substantially modified after that date, but Article 69(3) makes Article 14 apply to them regardless. The full calendar is in our guide to Cyber Resilience Act deadlines for 2026 and 2027.
What the other results get wrong
The first error is timing. Some guides say the Regulation applies in full three years after the reporting date. Reporting has applied since 11 September 2026, and full application follows 15 months later, on 11 December 2027.
The second is flattening Annex I into a single list of "requirements". Part I describes the product and is assessed at the point it is placed on the market. Part II describes processes that must keep running for the whole support period. A product can pass Part I on release day and fall out of compliance a year later because Part II stopped.
The third is treating the SBOM as the whole of vulnerability handling. It is point (1) of eight. Regular security testing, coordinated disclosure, free and prompt security updates and public disclosure of fixed vulnerabilities carry equal weight, and Article 64(2) puts the whole of Annex I in the top penalty tier of 15 million euros or 2.5% of worldwide annual turnover, whichever is higher. The tiers are set out in our guide to Cyber Resilience Act fines and penalties.
Where do you stand?
Fill this in for one product. A blank row is a gap.
| Question | Your answer | Requirement |
|---|---|---|
| Could you file an early warning within 24 hours of learning a vulnerability is being exploited? | Article 14(2)(a), in force now | |
| Is there a documented risk assessment that addresses every point in Annex I, Part I(2)? | Article 13(3) | |
| Can you produce a machine readable SBOM for the current release? | Annex I, Part II(1) | |
| Is your coordinated vulnerability disclosure policy published, with a contact address? | Annex I, Part II(5) and (6) | |
| What is the support period, and is its end date shown at purchase? | Article 13(8) and (19) | |
| Which conformity assessment route does the product's class require? | Article 32 |
Our CRA compliance checklist turns these into a working list, and a free compliance check gives you a baseline across the CRA areas. In Venvera, the CRA module tracks the obligations as controls with a gap assessment. It documents and tracks compliance; it does not test products or analyse code itself.

Frequently asked questions
Do the CRA requirements apply to software?
Yes. A product with digital elements includes software, and remote data processing solutions that belong to it. Scope turns on whether the product has a data connection and is made available on the EU market in the course of a commercial activity.
Is an SBOM mandatory under the CRA?
Yes. Annex I, Part II, point (1) requires a software bill of materials in a commonly used, machine readable format covering at least the top level dependencies. It belongs in the technical documentation under Annex VII. Making it available to users is the manufacturer's choice, under Annex II, point 9.
How long must security updates be provided?
For the support period, which Article 13(8) sets at a minimum of five years unless the product is expected to be in use for less. Each security update must then remain available for at least 10 years after it is issued or for the rest of the support period, whichever is longer.
Do the reporting duties apply to products already on the market?
Yes. Article 69(3) applies Article 14 to all in scope products placed on the market before 11 December 2027, so older products are covered from 11 September 2026.
Do we need a notified body?
Not for default products, which can self assess. Important class I products need one unless harmonised standards, common specifications or a qualifying certification scheme are applied in full, and important class II products need a third party route or a certification scheme.
Primary sources
Requirements, articles and dates are taken from Articles 13, 14, 19, 20, 21, 32, 64, 69 and 71 and Annex I of Regulation (EU) 2024/2847, checked against its published corrigenda. The status of the single reporting platform is from the European Commission's CRA reporting obligations page. Annex I points are summarised; read the full text before relying on a specific provision.





