EU Cyber Resilience Act · Regulation (EU) 2024/2847

CRA compliance without a compliance team

The CRA applies to more teams than you think. Vexwatch tells you in about three minutes whether your product is in scope and which obligations hit on which date, then gives you the documents you need to comply.

Timeline

Two dates decide your planning

11 September 2026
Reporting duties start. Manufacturers must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days for vulnerabilities, within one month for severe incidents) (Regulation (EU) 2024/2847, Article 14, applicable per Article 71(2)).
11 December 2027
The remaining obligations apply: secure-by-design lifecycle, technical documentation, conformity assessment and CE marking (Regulation (EU) 2024/2847, Article 71(2)).

Who this is for

Built for teams the CRA catches off guard

  • Independent software vendors selling into the EU
  • SaaS products that ship a desktop client, browser extension, or mobile app
  • Agencies that build and resell software
  • Small IoT and hardware makers

Inside the pack

Look inside before you reserve

Six documents, 59 pages, in a light print edition and a dark screen edition. Every regulatory claim cites the provision of Regulation (EU) 2024/2847 it rests on, so you, or your lawyer, can check every step (how we verify). These are real pages from the current draft (v1.0, July 2026); the finished pack ships from September 2026.

Select any page to enlarge it and read every line.

01 · The Reporting Runbook
01 · The four clocks, one page
02 · Classification worksheet
03 · The dark screen edition
04 · Every duty, one owner
Cover page of the CRA Reporting Runbook
01 · The Reporting Runbook
The one-page cheat sheet with the 24-hour, 72-hour, and final-report clocks
01 · The four clocks, one page
The product classification worksheet from the Scope and Classification Memo
02 · Classification worksheet
A page from the CVD policy in the dark screen edition
03 · The dark screen edition
The RACI matrix mapping every CRA duty to a role
04 · Every duty, one owner

Take a page with you

The runbook's one-page cheat sheet, free: the 24-hour, 72-hour, and final-report deadlines of Article 14 on a single printable page, each with its citation. Reporting duties start 11 September 2026.

Instant download, no payment details. We may email you about the Blueprint; unsubscribe anytime. See our privacy notice. Compliance tooling, not legal advice.

Common questions

The questions teams ask first, answered with citations

We are pure web SaaS with no downloads. Are we in CRA scope?

On its face, no. A service consumed only in the browser is not a product with digital elements, and the recitals put SaaS under NIS2 rather than the CRA. Confirm you genuinely ship nothing installable, because a single extension or helper app changes the answer. (Art. 3(1), Recital 12)

Read the full guide: Does the CRA apply to your SaaS company?

When do the reporting obligations start?

From 11 September 2026. Article 71(2) brings Article 14 forward, so the duty to report actively exploited vulnerabilities and severe incidents applies well before the rest of the regulation. (Art. 14, Art. 71(2))

Read the full guide: What are the key CRA compliance deadlines?

We resell a vendor tool under our own brand. Does the CRA reach us?

Yes. Placing a product on the market under your own name or trademark makes you a manufacturer under the CRA, subject to Articles 13 and 14, even though the vendor built it. Reselling it unchanged under the vendor brand keeps you in the lighter distributor role instead. (Art. 21, Art. 20)

Read the full guide: What the CRA means for agencies that build and resell software

We sell paid support for our open-source project. Does the CRA apply?

It may. Charging for technical support where this does more than recover actual costs points toward a commercial activity. This is a genuine edge case, so assess it against the recitals and, if your model is unusual, confirm with counsel. (Recital 15, Recital 18)

Read the full guide: Is open-source software in scope of the EU CRA?

The CRA Blueprint

The regulator tells you the CRA applies. We get you compliant.

Every document a small team needs to get compliant, written for people without a compliance background: a scope and classification memo template, a coordinated vulnerability disclosure policy aligned to Annex I, Part II of the CRA (binding on manufacturers via Article 13), a coordinated disclosure workflow with security.txt, the CRA reporting runbook (24 hour, 72 hour, and final report deadlines), RACI and internal register templates, and an SBOM starter guide.

  • Founding price: EUR 49, one time
  • First documents delivered from August 2026
  • The ENISA Single Reporting Platform walkthrough is added free on 11 September 2026, the day the platform goes live

No payment now. We will email you when the Blueprint is ready, at the founding price of EUR 49, and you decide then. Unsubscribe anytime. See our privacy notice. Documents only, no consulting. Compliance tooling, not legal advice.

Not sure the CRA applies to you?

Start with the free check