Who it applies to
The CRA applies mainly to manufacturers of products with digital elements, such as connected devices, software sold as a product and their components, and also places obligations on importers and distributors. Products already covered by specific rules, such as medical devices, vehicles and aviation, are largely excluded. Pure SaaS is generally outside its scope, unless it is the remote data processing part of a product.
What it requires
Products must be designed with security in mind, be placed on the market without known exploitable vulnerabilities, have secure default settings, receive security updates during a defined support period, and be documented with a software bill of materials (SBOM). Products considered important or critical need a stricter conformity assessment, and compliant products carry the CE marking.
Reporting since September 2026
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products through ENISA's Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours and a final report afterwards. This also applies to products already on the market.
Penalties and timeline
Fines can reach 15 million euros or 2.5% of global annual turnover. The full text is on EUR-Lex. Secure development practices such as SAST and DAST and a clear vulnerability handling process are the core of preparing for it.




