An actively exploited vulnerability must be reported within strict deadlines: an early warning within 24 hours and a notification within 72 hours of becoming aware, and a final report within 14 days of a fix becoming available. You only meet these deadlines if the documentation, responsibilities and reporting process are ready in advance.
The CRA applies to all products with digital elements placed on the EU market, whether software or hardware. The obligations therefore also apply to device manufacturers, such as suppliers of Internet of Things (IoT) devices and other connected devices, whenever software is part of the product. What matters is not the industry but whether the product contains digital elements.
If a software service involves an installable component, such as an agent or a desktop or mobile application, it is likely within the scope of the CRA. The same applies to devices that contain software. Scope is assessed per product, and that is the first item in the review.
The Cyber Resilience Act entered into force in the EU. In Finland, Traficom is responsible for market surveillance and enforcement.
Actively exploited vulnerabilities and serious incidents must be reported: within 24 h, 72 h and 14 days.
Technical documentation (Annex VII) retained for 10 years, a software bill of materials, a support period of at least 5 years and CE marking.
Sanctions for breaching the key obligations: up to €15 million or 2.5% of worldwide turnover. The dates and reporting obligations are based on guidance from Traficom and the National Cyber Security Centre. Check the application to your own product with an expert; this page is not legal advice.
Before a product can be placed on the EU market, the manufacturer must demonstrate that it meets the essential cybersecurity requirements of the Cyber Resilience Act. This is called the conformity assessment. The assessment is based on documentation that must be kept up to date and presented to the authority on request.
What must be documented
The product's risks are assessed and the assessment is kept up to date throughout the lifecycle. It guides design and development and is part of the technical documentation.
Describes the product, its design and production, the risk assessment, the standards applied and the handling of vulnerabilities. Retained for at least 10 years.
Demonstration that the product meets the cybersecurity requirements of Annex I, for example test results and the harmonised standards applied.
The manufacturer declares that the requirements are met, and the CE marking is affixed to the product.
Most products can be self-assessed by the manufacturer through an internal assessment. Important and critical product classes may require the application of harmonised standards or an assessment by a notified body. The assessment relies on traceable and approved documentation, which ComplianceCoded keeps ready with its version history for presentation to the authority.
ComplianceCoded is a documentation platform where every change, approval and sign-off is recorded in the version history. The same capability that supports an ISO 27001 audit produces the evidence the CRA requires.
The documentation must be shown to the authority on request and must describe the product, the risk assessment and the handling of vulnerabilities across the entire lifecycle.
On the platformdocuments with a version history: who changed what and when, and who approved it. The history you need to show ten years later is created as you work, not assembled afterwards.
The report is submitted to the central platform of the EU Agency for Cybersecurity (ENISA), from where it is forwarded in Finland to Traficom's National Cyber Security Centre. The deadlines are short, and the first one likely falls in the middle of the busiest possible day.
On the platforma reporting process with responsibilities ready and signed off. When an incident is underway, no one looks for the instructions: everyone knows their role and the templates are ready.
The product must maintain a list of components, and security updates must be provided throughout the support period.
On the platformpractices for the software bill of materials (SBOM) and documenting the support period as part of the CRA content set. Tell us you are interested; the content is built together with the first customers.
If ISO 27001 work is done or under way, a large part of the CRA's process requirements is already covered.
On the platformthe same documentation serves both: ISO 27001 controls are mapped to the CRA requirements, and the same content is not written twice.
ComplianceCoded is also delivered installed in the customer's own environment, so the Cyber Resilience Act applies to our own product. We produce the same CRA documentation for ourselves on the same platform, alongside our own ISO 27001 certification process. We do not offer a tool we would not put under inspection ourselves.
We go through which of your products fall within the scope of the CRA, which obligations you already meet and which measures you still need to take before 11 September 2026. The review is about your products, not a generic pitch.