ComplianceCodedSuomeksiBook a 30-min review
EU Cyber Resilience Act · CRA

CRA reporting starts on 11 September 2026. The first deadline is 24 hours.

An actively exploited vulnerability must be reported within strict deadlines: an early warning within 24 hours and a notification within 72 hours of becoming aware, and a final report within 14 days of a fix becoming available. You only meet these deadlines if the documentation, responsibilities and reporting process are ready in advance.

early warning 24 hnotification 72 hfinal report 14 days11 Sep 2026counting
Book a 30-min reviewDoes the CRA apply to us?
Scope

Does the CRA apply to you?

The CRA applies to all products with digital elements placed on the EU market, whether software or hardware. The obligations therefore also apply to device manufacturers, such as suppliers of Internet of Things (IoT) devices and other connected devices, whenever software is part of the product. What matters is not the industry but whether the product contains digital elements.

In scope of the CRA

  • Devices where software is part of the product, such as IoT devices and other connected devices
  • Embedded software and firmware
  • Software products: desktop, mobile and locally installed applications
  • Software libraries and components delivered for others to install
  • Remote processing solutions essential to the product's functioning

Out of scope (but other rules may apply)

  • Purely browser-based software services, which fall under the Network and Information Security Directive (NIS2)
  • Non-commercial open source
  • Separately regulated products, such as medical devices and certain vehicles

If a software service involves an installable component, such as an agent or a desktop or mobile application, it is likely within the scope of the CRA. The same applies to devices that contain software. Scope is assessed per product, and that is the first item in the review.

Timeline

Three dates that matter

10 Dec 2024 · in force

Regulation enters into force in the EU

The Cyber Resilience Act entered into force in the EU. In Finland, Traficom is responsible for market surveillance and enforcement.

11 Sep 2026 · reporting

Reporting obligations begin

Actively exploited vulnerabilities and serious incidents must be reported: within 24 h, 72 h and 14 days.

11 Dec 2027 · full application

All obligations apply

Technical documentation (Annex VII) retained for 10 years, a software bill of materials, a support period of at least 5 years and CE marking.

Sanctions for breaching the key obligations: up to €15 million or 2.5% of worldwide turnover. The dates and reporting obligations are based on guidance from Traficom and the National Cyber Security Centre. Check the application to your own product with an expert; this page is not legal advice.

Conformity

Before it is placed on the market, a product must be shown to be conformant

Before a product can be placed on the EU market, the manufacturer must demonstrate that it meets the essential cybersecurity requirements of the Cyber Resilience Act. This is called the conformity assessment. The assessment is based on documentation that must be kept up to date and presented to the authority on request.

What must be documented

Cybersecurity risk assessment

The product's risks are assessed and the assessment is kept up to date throughout the lifecycle. It guides design and development and is part of the technical documentation.

Technical documentation (Annex VII)

Describes the product, its design and production, the risk assessment, the standards applied and the handling of vulnerabilities. Retained for at least 10 years.

Evidence that the essential requirements are met

Demonstration that the product meets the cybersecurity requirements of Annex I, for example test results and the harmonised standards applied.

EU declaration of conformity and CE marking

The manufacturer declares that the requirements are met, and the CE marking is affixed to the product.

Most products can be self-assessed by the manufacturer through an internal assessment. Important and critical product classes may require the application of harmonised standards or an assessment by a notified body. The assessment relies on traceable and approved documentation, which ComplianceCoded keeps ready with its version history for presentation to the authority.

Requirement and solution

The CRA requires verifiable documentation.

ComplianceCoded is a documentation platform where every change, approval and sign-off is recorded in the version history. The same capability that supports an ISO 27001 audit produces the evidence the CRA requires.

CRA · Annex VII

Technical documentation, 10-year retention

The documentation must be shown to the authority on request and must describe the product, the risk assessment and the handling of vulnerabilities across the entire lifecycle.

On the platformdocuments with a version history: who changed what and when, and who approved it. The history you need to show ten years later is created as you work, not assembled afterwards.

CRA · reporting

Reporting in 24 h, 72 h and 14 days

The report is submitted to the central platform of the EU Agency for Cybersecurity (ENISA), from where it is forwarded in Finland to Traficom's National Cyber Security Centre. The deadlines are short, and the first one likely falls in the middle of the busiest possible day.

On the platforma reporting process with responsibilities ready and signed off. When an incident is underway, no one looks for the instructions: everyone knows their role and the templates are ready.

CRA · SBOM and support periodComing

Software bill of materials

The product must maintain a list of components, and security updates must be provided throughout the support period.

On the platformpractices for the software bill of materials (SBOM) and documenting the support period as part of the CRA content set. Tell us you are interested; the content is built together with the first customers.

Foundation in place

ISO 27001 already covers a large part

If ISO 27001 work is done or under way, a large part of the CRA's process requirements is already covered.

On the platformthe same documentation serves both: ISO 27001 controls are mapped to the CRA requirements, and the same content is not written twice.

Proof

We are in scope of the CRA ourselves.

ComplianceCoded is also delivered installed in the customer's own environment, so the Cyber Resilience Act applies to our own product. We produce the same CRA documentation for ourselves on the same platform, alongside our own ISO 27001 certification process. We do not offer a tool we would not put under inspection ourselves.

documentationversion historyapprovalssign-offssourced answers

Half an hour is enough for a clear picture.

We go through which of your products fall within the scope of the CRA, which obligations you already meet and which measures you still need to take before 11 September 2026. The review is about your products, not a generic pitch.

Book a 30-min review