Step 1: confirm scope and your category Art. 2(1), Art. 3(22), Art. 7, Annex III
Software supplied on the EU market in the course of a commercial activity, with a direct or indirect data connection to a device or network, is a product with digital elements in scope (Art. 2(1)). Free of charge does not take you out; only free and open-source software supplied outside a commercial activity stays out (Art. 3(22)).
Next, check core functionality against the important categories in Annex III and the critical ones in Annex IV (Art. 7). Most business software is default-category and can self-assess. If your product's core function is something like identity management, a password manager, or a VPN, it is an important product and your conformity route narrows. Merely embedding such a component does not by itself put you in the category (Art. 7(1)).
Step 2: build to the essential requirements Art. 13(1), Art. 13(2), Art. 13(3), Annex I Part I
Design, develop, and produce the product in line with the essential cybersecurity requirements in Part I of Annex I, on the back of a documented cybersecurity risk assessment that feeds the whole lifecycle (Art. 13(1), Art. 13(2)). These are secure-by-design and secure-by-default obligations: no known exploitable vulnerabilities at release, protection of confidentiality and integrity, a minimised attack surface, and security updates among them.
Step 3: handle vulnerabilities across the support period Art. 13(8), Annex I Part II
The process side of the CRA is the vulnerability handling requirements in Part II of Annex I, which apply throughout a support period you set to reflect how long the product is expected to be in use, and which is at least five years unless the product is used for less (Art. 13(8)). This includes a software bill of materials, timely security updates, and a coordinated vulnerability disclosure policy (Annex I Part II, points (1) and (5)).
Step 4: document, assess, and CE-mark Art. 31, Art. 32, Art. 13(12), Art. 13(13)
Before placing the product on the market, draw up the technical documentation (Art. 31, Annex VII) and carry out the conformity assessment (Art. 32). Default-category products can use internal control (module A); important Class I products can self-assess only where harmonised standards, common specifications, or eligible certification are applied in full, otherwise a notified body route applies (Art. 32(1), Art. 32(2)).
On success, draw up the EU declaration of conformity and affix the CE marking (Art. 13(12)). Keep the documentation and declaration available to market surveillance authorities for at least ten years after placing on the market, or the support period if longer (Art. 13(13)).
Step 5: report once duties start Art. 14, Art. 16
From 11 September 2026, notify actively exploited vulnerabilities and severe incidents via ENISA's single reporting platform: an early warning within 24 hours, a notification within 72 hours, and a final report (within 14 days after a corrective measure is available for a vulnerability, within one month after the notification for a severe incident) (Art. 14, Art. 16).