The Cyber Resilience Act imposes cybersecurity requirements on all products with digital elements (hardware and software) placed on the market of the European Union. SYAGA supports you in understanding your obligations and building your compliance file, without improvising.
The Cyber Resilience Act (CRA) is a horizontal European text on the cybersecurity of digital products
The CRA covers products with digital elements (connected hardware, software, firmware) intended to be placed on the EU market, with cybersecurity requirements throughout the product's lifecycle.
Manufacturer, importer or distributor: the regulation distributes different obligations depending on your position in the placing-on-the-market chain, following the model already used by other European product regulations.
The text entered into force on 10 December 2024 and provides for a tiered application over time. The precise deadlines that concern you must be verified against the official text for your situation.
As with other recent European cyber texts, CRA compliance requires a method (product mapping, gap analysis, technical documentation) that most software vendors and manufacturers have not yet undertaken due to a lack of dedicated internal resources.
The CRA is addressed to economic operators who place digital products on the EU market
Companies that design or have designed products with digital elements (hardware, software, firmware) marketed under their name or trademark.
Companies that place on the EU market a digital product designed outside the Union.
Companies that make a product available on the EU market without being its manufacturer or importer.
A structured approach to map your products, measure gaps and build your compliance action plan
Interview with management or the R&D team to identify the products potentially affected by the CRA (connected hardware, embedded software, firmware) and your role as an economic operator (manufacturer, importer, distributor).
Mapping of your digital products and their current cybersecurity elements (vulnerability management, security updates, existing documentation), compared against the regulation's requirements.
Prioritised compliance plan: what needs to be handled first, what can wait for upcoming regulatory deadlines, and the resources to mobilise internally.
Support in structuring the technical documentation expected by the regulation (product description, cybersecurity risk management, vulnerability handling procedures).
Presentation of the diagnosis and action plan to management, with delivery of editable materials for your teams to take ownership of.
A diagnosis and a roadmap to steer your CRA compliance
Inventory of your products with digital elements and qualification of their exposure to the regulation.
Summary of the gaps between your current practice and the regulation's requirements.
Prioritised roadmap to close the identified gaps.
Support in structuring the documentation expected by the regulation.
Monitoring of implementing texts and official clarifications published on the CRA.
All documents in formats you can modify and maintain internally.
The CRA does not replace your other compliance efforts, it complements them
NIS2 governs cyber risk management for essential and important entities; the CRA governs the security of the digital products they use or market. The two texts are complementary.
An information security management system already in place makes it easier to structure the vulnerability management processes required by the CRA.
If your digital product processes personal data, the CRA's security requirements partly overlap with the technical and organisational measures expected under Article 32 of the GDPR.
If your product incorporates artificial intelligence components, the CRA and the AI Act may apply jointly depending on the nature of the product. A point to clarify case by case with your legal counsel.
Every product, every scope is different: we prepare a quote tailored to your situation
One product, a limited scope
Multiple products, active compliance work
Product range, continuous compliance cycle
What the CRA text really says, explained simply. Each point links to its official source (EUR-Lex or the European Commission) so you can verify for yourself.
The Cyber Resilience Act is a European regulation (Regulation (EU) 2024/2847) that sets
cybersecurity rules for digital products - hardware and software - sold in the
European Union. It entered into force on 10 December 2024.
official source ↗
Any product with digital elements intended to connect, directly or indirectly, to
a device or network. Products already covered by other European texts are excluded:
medical devices, vehicles, aviation, marine equipment, identical spare parts, or
products designed exclusively for defence/national security.
official source (Article 2) ↗
10 December 2024: the text entered into force.
11 June 2026: the authorities responsible for enforcing it must be in
place. 11 September 2026: vulnerability and incident reporting
obligations start. 11 December 2027: most obligations, including CE
marking, become applicable.
official source (Article 71) ↗
If an actively exploited vulnerability or a serious incident affects your product,
the regulation requires you to notify the authorities: an initial early warning within
24 hours, a more detailed notification within 72 hours,
then a final report no later than 14 days after a fix becomes
available.
official source (Article 14) ↗
The text distinguishes categories of products considered more sensitive (for
example antivirus, VPNs, password managers, operating systems, routers, connected home
security devices) and "critical" products (for example smart cards, smart metering
gateways), subject to reinforced requirements.
official source (Annexes III and IV) ↗
Up to 15 million euros or 2.5% of worldwide turnover (whichever is
higher) for the most serious breaches of essential security requirements. Up to
10 million or 2% for other obligations, and up to 5 million or
1% for providing misleading information to the authorities. Micro and small
enterprises benefit from a specific waiver regarding delays on the 24-hour reporting
deadline.
official source (Article 64) ↗
The CRA complements the NIS2 directive and builds on the EU's 2020 cybersecurity
strategy. CE marking will be required to attest compliance, and national market
surveillance authorities will oversee its enforcement.
official source (European Commission) ↗
The regulation sets 3 fine tiers depending on the severity of the breach. Here is exactly what the official text says, with no rounding or approximation.
Non-compliance with basic cybersecurity requirements (Annex I) or manufacturers' obligations (Articles 13 and 14: secure design, vulnerability management, incident reporting).
Breaches of authorised representatives' obligations, of the EU declaration of conformity (CE marking), of requirements relating to notified bodies, and of data access requested by the authorities (Articles 18 to 53 depending on the case).
Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority questioning you.
official source - Regulation (EU) 2024/2847, Article 64, paragraphs 2 to 4 ↗
It is each Member State's national market surveillance authority that applies these fines (not the European Commission directly). Depending on the country's legal system, the fine may also be imposed by a competent national court. Authorities in different Member States communicate fines applied to each other.
The text does not impose an automatic amount: the authority must take into account, on a case-by-case basis:
The text provides for a single quantified derogation: manufacturers that are micro or small enterprises are not exposed to tier 2 and tier 3 fines if they only exceed the incident reporting deadline set out in Article 14 (24h/72h/final report). For everything else (security requirements, CE marking, misleading information...), the same caps apply, regardless of company size. Open source software stewards, for their part, benefit from a broader exemption.
The penalty regime (Article 64) follows the regulation's general date of application, i.e. 11 December 2027 - it is not part of the few exceptions that apply earlier (manufacturers' reporting obligations from 11 September 2026, authorities set up from 11 June 2026). In practice: as of 18 July 2026, this penalty regime is not yet in force, and no CRA fine has therefore been issued yet. This is also why we do not display an example of a real penalty here: there isn't one yet, and we will not invent one.
No legal jargon: simple answers, each backed by the official text it is based on.
The regulation does not apply all at once: it advances in stages, over several years. Here are the dates that really matter, in order, with what they concretely mean for you. Each date links to the official text for verification.
The text of regulation (EU) 2024/2847 is published in the Official Journal of the
European Union. This is the starting point of the countdown: all subsequent
deadlines are calculated from this date.
official source (EUR-Lex, publication) ↗
The regulation enters into force twenty days after its publication (the standard
rule for European texts). The text has therefore legally existed since this date -
but the vast majority of concrete obligations for companies are not yet due: they
arrive in stages, see the rest of the calendar.
official source (Article 71 §1) ↗
The chapter of the regulation dedicated to the bodies responsible for assessing
product conformity ("notified bodies") applies from this date. This is an
organisational step on the Member States' side: it is not yet a direct deadline for
your company.
official source (Article 71 §2, Chapter IV) ↗
This is the first deadline that really concerns you. From this date, any
actively exploited vulnerability or any serious incident affecting one of your
digital products must be reported to the authorities within strict deadlines: an
initial alert within 24 hours, a detailed notification within
72 hours, then a final report (14 days after the fix for a
vulnerability, 1 month after the notification for an incident).
official source (Article 71 §2, Article 14) ↗
Member States must "endeavour" to have set up enough notified bodies to avoid
administrative bottlenecks, one year before the general date of application. This
is not a binding obligation for companies, but an organisational milestone on the
administrations' side.
official source (Article 35 §2) ↗
This is THE structuring date to remember. CE marking, compliance with essential
cybersecurity requirements (technical documentation, vulnerability lifecycle
management, security updates...): almost all of the CRA's obligations become
enforceable on this date for products placed on the market.
official source (Article 71 §2) ↗
If your products are already covered by another European regulation (for
example radio equipment or machinery) and already hold a cybersecurity certificate
obtained under that text, it remains valid at the latest until this date, unless it
expires earlier.
official source (Article 69 §1) ↗
Beyond the three roles (manufacturer, importer, distributor), here is exactly what the text says: the criterion that triggers the regulation, what is excluded from it, and concrete examples of products to help you know whether you are affected, without jargon.
The criterion used by the regulation is not a list of sectors, it is a technical
criterion: connectivity. The text applies to any "product with
digital elements" whose intended, or reasonably foreseeable, use includes
a direct or indirect, logical or physical connection to a device or a
network. An object that never connects to anything remains outside the scope; a
piece of software, an app, an embedded component that talks to a network falls within it,
regardless of its size or sector.
official source, Regulation (EU) 2024/2847, Article 2 §1 ↗
The one who develops or has developed a digital product and markets it under their name or trademark. The text explicitly states that manufacturer status applies "whether for payment, through monetisation or free of charge": offering a free product is not enough to fall outside the scope.
Any person established in the EU who places on the European market a product bearing the name or trademark of a person established outside the Union. An SME that resells, under its own name, connected hardware manufactured outside the EU takes on this role, with the obligations that come with it.
Any person in the supply chain, other than the manufacturer or importer, who makes a product available on the EU market without altering its properties. This is the default role of a reseller or integrator who does not modify the product.
Already covered by their own safety regulation (Regulations (EU) 2017/745 and 2017/746): the CRA does not add on top.
Covered by the type-approval regulation (EU) 2019/2144, which already addresses vehicle cybersecurity.
Products certified under regulation (EU) 2018/1139 on civil aviation remain under this dedicated sector-specific framework.
Equipment covered by directive 2014/90/EU on marine equipment has its own regime and is outside the CRA.
A replacement part manufactured to the same specifications as the original component it replaces is not a new product within the meaning of the CRA.
Products developed or modified exclusively for defence or national security, or designed to handle classified information, fall outside the scope.
The regulation itself lists categories of products considered "important" (reinforced surveillance) or "critical" (the highest level of requirements). These are only illustrative examples among all the connected products covered, but they give a very concrete idea of the sectors targeted as a priority.
full list, official source, Annexes III and IV of the regulation ↗
This official definition is the one the regulation uses everywhere it mentions micro, small and medium-sized enterprises (simplified documentation, targeted derogations on the fines already detailed above). official source, Recommendation 2003/361/EC, Article 2 of the annex ↗
In Europe, every country has its own authorities. Below, for the 30 countries of the European Economic Area, are the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official site.
Sources: official authority websites and the list of EDPB members (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" mentions indicate an official source not yet stabilised as of this date.
Contact us to receive a quote tailored to your products and your situation.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu