Compliance & Regulations/European Union/EU CRA
Product Security · European Union — products with digital elements

EU Cyber Resilience Act

The EU Cyber Resilience Act — product cybersecurity requirements with CE marking for all products with digital elements sold in the EU.

Regulator
European Commission + national market surveillance
Jurisdiction
European Union — products with digital elements
Status
Adopted October 2024 — main obligations apply from 11 December 2027 (incident reporting from September 2026).
In force since
10 December 2024 (entered into force).
Regulator's source
Who it applies to

Any product with digital elements placed on the EU market, including software and IoT.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What EU CRA actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Security by design and by default per Annex I.

02

Vulnerability handling for the product lifetime, including coordinated disclosure.

03

SBOM for each product with digital elements.

04

24-hour early warning + 72-hour incident notification + 14-day final report for actively exploited vulnerabilities and severe incidents.

05

Conformity assessment and CE marking.

06

Free security updates throughout the declared support period.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Product CRA-tier classification (default / important class I / II / critical) with conformity track recommendation.

Annex I checklist auto-populated from telemetry.

Vulnerability handling pipeline with mandatory disclosure timelines.

SBOM publication per product release.

24/72/14 incident reporting timer with ENISA-compatible export.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Annex I conformity assessment evidence.

Per-product SBOM with VEX.

Vulnerability disclosure log.

Incident reports per CRA template.

Ready for EU CRA?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing