HomeFrameworksAI Governance & Privacy FrameworksEU CRA

Framework  AI Governance & Privacy Frameworks

EU CRA

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU, from consumer routers and smart devices to enterprise software and operating systems. It entered into force on December 10, 2024.

Manufacturers must design products to be secure by default, ship them without known exploitable vulnerabilities, provide security updates for a defined support period (five years by default), and handle vulnerabilities through a documented process with a coordinated disclosure policy and a software bill of materials.

Reporting duties start on September 11, 2026: actively exploited vulnerabilities and severe incidents go to ENISA's single reporting platform and the national CSIRT with an early warning inside 24 hours and a fuller notification inside 72 hours. The remaining obligations, including conformity assessment and CE marking, apply from December 11, 2027.

In writing, a manufacturer needs a cybersecurity risk assessment for each product, technical documentation covering the Annex I essential requirements, a vulnerability handling process and disclosure policy, the SBOM, a support period statement, user information and instructions, and an EU declaration of conformity.

The conformity route depends on the product class: most products self-assess; "important" products in Class I and II need either harmonized standards or a notified body; "critical" products may be required to hold a European cybersecurity certificate.

AI-compiled
Share
Sponsored
EU
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with EU CRA
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Manufacturers of products with digital elements made available on the EU market, wherever the manufacturer is based, plus importers and distributors. Open-source software supplied outside a commercial activity is largely excluded, and products already covered by sectoral rules (medical devices, vehicles, aviation) are carved out.

The reporting duties from September 2026 cover products already on the market, not only new ones.

What the assessor asks to see

Product classification rationale; cybersecurity risk assessment; technical documentation against Annex I Part I (product requirements) and Part II (vulnerability handling); SBOM; coordinated vulnerability disclosure policy and contact point; security update and support period statement; user information; test reports; declaration of conformity and CE marking file; reporting records submitted to ENISA and the CSIRT; for notified body routes, the quality system documentation.

Where the requirement sits: EU Cyber Resilience Act Annex I

Key dates

Entry into force December 10, 2024. Notified body chapter applies from June 11, 2026. Vulnerability and incident reporting from September 11, 2026.

Full application, including conformity assessment and CE marking, from December 11, 2027.

Assessors

Who assesses EU CRA

Manufacturer self-assessment (internal control, Module A) for the default category. Notified bodies for important products where harmonized standards are not fully applied and for products where the manufacturer chooses third-party assessment.

Conformity assessment bodies under the EU Cybersecurity Act certification schemes (for example EUCC) where a European certificate is used. Notified body provisions applied from June 11, 2026.

Accredited by National notifying authorities designate CRA notified bodies, with accreditation by the national accreditation body (for example DAkkS, COFRAC, UKAS is not applicable) as the normal basis. Listings appear in NANDO once designations begin.

Public register of assessors: https://webgate.ec.europa.eu/single-market-compliance-space/#/notified-bodies

No firm has claimed a EU CRA assessor listing yet. Claim yours →

Consultants

Who helps with EU CRA

Product security consultancies, testing labs, and law firms are building CRA practices. Engagements typically classify the product portfolio into default, important, and critical categories, run gap assessments against Annex I, set up the vulnerability handling and SBOM process, and prepare the technical file.

Testing labs that already work under the Radio Equipment Directive or IEC 62443 are common partners.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a EU CRA consultant listing yet. Claim yours →

Software

Tools for EU CRA

Tools that name this framework in their own material.

No firm has claimed a EU CRA tool listing yet. Claim yours →

Related reading

  1. The Cyber Resilience Act: EU-wide requirements for the cybersecurity of productsExplains which products are caught, what security by design means in practice and how the phased dates fall.Taylor Wessing
  2. EU Cyber Resilience Act: key 2026 milestones toward CRA complianceFocuses on the September 2026 reporting duties and the 24-hour, 72-hour and 14-day clocks manufacturers must meet.Hogan Lovells
  3. The European Union's Cyber Resilience ActIndustry working group's practical reading of what the Act asks of software makers, including open source stewards.Open Regulatory Compliance Working Group

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for EU CRA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with EU CRA

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.