For software vendors ยท Regulation (EU) 2024/2847

The CRA manufacturer programme for independent software vendors

Verified against the Official Journal text on

If you develop software and make it available on the EU market in the course of business, you are a manufacturer under the CRA and carry the full programme (Art. 2(1), Art. 3(13)). That means building to the essential cybersecurity requirements, handling vulnerabilities across a support period, drawing up technical documentation, running a conformity assessment, affixing the CE marking, and reporting actively exploited vulnerabilities and severe incidents (Art. 13, Art. 14). First check whether your product matches an important or critical category, because that decides whether you can self-assess or need a notified body (Art. 7, Annex III).

Basis: Art. 2(1), Art. 3(13), Art. 13, Art. 14, Art. 7

Step 1: confirm scope and your category Art. 2(1), Art. 3(22), Art. 7, Annex III

Software supplied on the EU market in the course of a commercial activity, with a direct or indirect data connection to a device or network, is a product with digital elements in scope (Art. 2(1)). Free of charge does not take you out; only free and open-source software supplied outside a commercial activity stays out (Art. 3(22)).

Next, check core functionality against the important categories in Annex III and the critical ones in Annex IV (Art. 7). Most business software is default-category and can self-assess. If your product's core function is something like identity management, a password manager, or a VPN, it is an important product and your conformity route narrows. Merely embedding such a component does not by itself put you in the category (Art. 7(1)).

Step 2: build to the essential requirements Art. 13(1), Art. 13(2), Art. 13(3), Annex I Part I

Design, develop, and produce the product in line with the essential cybersecurity requirements in Part I of Annex I, on the back of a documented cybersecurity risk assessment that feeds the whole lifecycle (Art. 13(1), Art. 13(2)). These are secure-by-design and secure-by-default obligations: no known exploitable vulnerabilities at release, protection of confidentiality and integrity, a minimised attack surface, and security updates among them.

Step 3: handle vulnerabilities across the support period Art. 13(8), Annex I Part II

The process side of the CRA is the vulnerability handling requirements in Part II of Annex I, which apply throughout a support period you set to reflect how long the product is expected to be in use, and which is at least five years unless the product is used for less (Art. 13(8)). This includes a software bill of materials, timely security updates, and a coordinated vulnerability disclosure policy (Annex I Part II, points (1) and (5)).

Step 4: document, assess, and CE-mark Art. 31, Art. 32, Art. 13(12), Art. 13(13)

Before placing the product on the market, draw up the technical documentation (Art. 31, Annex VII) and carry out the conformity assessment (Art. 32). Default-category products can use internal control (module A); important Class I products can self-assess only where harmonised standards, common specifications, or eligible certification are applied in full, otherwise a notified body route applies (Art. 32(1), Art. 32(2)).

On success, draw up the EU declaration of conformity and affix the CE marking (Art. 13(12)). Keep the documentation and declaration available to market surveillance authorities for at least ten years after placing on the market, or the support period if longer (Art. 13(13)).

Step 5: report once duties start Art. 14, Art. 16

From 11 September 2026, notify actively exploited vulnerabilities and severe incidents via ENISA's single reporting platform: an early warning within 24 hours, a notification within 72 hours, and a final report (within 14 days after a corrective measure is available for a vulnerability, within one month after the notification for a severe incident) (Art. 14, Art. 16).

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy and a software bill of materials. (Art. 13(8), Annex I Part II)
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 31, Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Does the CRA apply if our software is free?

Free of charge does not remove you from scope. Making available on the market covers supply in the course of a commercial activity whether paid or free. Only free and open-source software supplied entirely outside a commercial activity stays out. (Art. 3(22), Recital 15)

Can we self-assess, or do we need a notified body?

Default-category products can self-assess under internal control. If your product's core functionality matches an important Class I category, self-assessment is available only where you apply harmonised standards, common specifications, or eligible certification in full; otherwise a notified body route applies. (Art. 32(1), Art. 32(2))

How long is the support period?

You set it to reflect how long the product is expected to be in use, taking reasonable user expectations and the nature of the product into account. It must be at least five years, unless the product is expected to be in use for less, in which case it matches that shorter time. (Art. 13(8))

What are the two dates we must plan for?

Reporting duties for actively exploited vulnerabilities and severe incidents start 11 September 2026. The full obligations, including essential requirements, technical documentation, conformity assessment, and CE marking, apply from 11 December 2027. (Art. 71(2))

Confirm your category, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes and flags whether your product looks default-category or lands in an important or critical class.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.