EU Cyber Resilience Act · Regulation (EU) 2024/2847
CRA compliance without a compliance team
The CRA applies to more teams than you think. Vexwatch tells you in about three minutes whether your product is in scope and which obligations hit on which date, then gives you the documents you need to comply.
Timeline
Two dates decide your planning
- 11 September 2026
- Reporting duties start. Manufacturers must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days for vulnerabilities, within one month for severe incidents) (Regulation (EU) 2024/2847, Article 14, applicable per Article 71(2)).
- 11 December 2027
- The remaining obligations apply: secure-by-design lifecycle, technical documentation, conformity assessment and CE marking (Regulation (EU) 2024/2847, Article 71(2)).
Who this is for
Built for teams the CRA catches off guard
- Independent software vendors selling into the EU
- SaaS products that ship a desktop client, browser extension, or mobile app
- Agencies that build and resell software
- Small IoT and hardware makers
Inside the pack
Look inside before you reserve
Six documents, 59 pages, in a light print edition and a dark screen edition. Every regulatory claim cites the provision of Regulation (EU) 2024/2847 it rests on, so you, or your lawyer, can check every step (how we verify). These are real pages from the current draft (v1.0, July 2026); the finished pack ships from September 2026.
Select any page to enlarge it and read every line.
Take a page with you
The runbook's one-page cheat sheet, free: the 24-hour, 72-hour, and final-report deadlines of Article 14 on a single printable page, each with its citation. Reporting duties start 11 September 2026.
Common questions
The questions teams ask first, answered with citations
We are pure web SaaS with no downloads. Are we in CRA scope?
On its face, no. A service consumed only in the browser is not a product with digital elements, and the recitals put SaaS under NIS2 rather than the CRA. Confirm you genuinely ship nothing installable, because a single extension or helper app changes the answer. (Art. 3(1), Recital 12)
Read the full guide: Does the CRA apply to your SaaS company?
When do the reporting obligations start?
From 11 September 2026. Article 71(2) brings Article 14 forward, so the duty to report actively exploited vulnerabilities and severe incidents applies well before the rest of the regulation. (Art. 14, Art. 71(2))
Read the full guide: What are the key CRA compliance deadlines?
We resell a vendor tool under our own brand. Does the CRA reach us?
Yes. Placing a product on the market under your own name or trademark makes you a manufacturer under the CRA, subject to Articles 13 and 14, even though the vendor built it. Reselling it unchanged under the vendor brand keeps you in the lighter distributor role instead. (Art. 21, Art. 20)
Read the full guide: What the CRA means for agencies that build and resell software
We sell paid support for our open-source project. Does the CRA apply?
It may. Charging for technical support where this does more than recover actual costs points toward a commercial activity. This is a genuine edge case, so assess it against the recitals and, if your model is unusual, confirm with counsel. (Recital 15, Recital 18)
Read the full guide: Is open-source software in scope of the EU CRA?
The CRA Blueprint
The regulator tells you the CRA applies. We get you compliant.
Every document a small team needs to get compliant, written for people without a compliance background: a scope and classification memo template, a coordinated vulnerability disclosure policy aligned to Annex I, Part II of the CRA (binding on manufacturers via Article 13), a coordinated disclosure workflow with security.txt, the CRA reporting runbook (24 hour, 72 hour, and final report deadlines), RACI and internal register templates, and an SBOM starter guide.
- Founding price: EUR 49, one time
- First documents delivered from August 2026
- The ENISA Single Reporting Platform walkthrough is added free on 11 September 2026, the day the platform goes live
Not sure the CRA applies to you?
Start with the free check