REGULATION · CRA
CRA conformity you can evidence, product by product.
From 2027, products with digital elements enter the EU market only with cybersecurity designed in and vulnerabilities handled for the whole support period. Mindlapse turns those duties into controls you verify continuously, not a binder assembled at CE-marking time.
WHAT IS THE CRA?
The EU’s cybersecurity law for products with digital elements.
The CRA (Regulation (EU) 2024/2847) is the Cyber Resilience Act: the first horizontal EU regulation making cybersecurity a condition of market access for products with digital elements, hardware and software alike. It entered into force on 10 December 2024; its main obligations apply from 11 December 2027, with vulnerability and incident reporting duties starting on 11 September 2026.
It binds manufacturers first, importers and distributors behind them: essential cybersecurity requirements across the product lifecycle (Annex I), a documented cybersecurity risk assessment, secure-by-default configuration, a vulnerability handling process with coordinated disclosure, and security updates for the support period. Conformity is declared through CE marking, with stricter assessment paths for important and critical product classes.
Non-compliance carries fines up to 15 million euros or 2.5% of worldwide turnover, and non-compliant products can be pulled from the market. Like NIS2 and DORA, the CRA expects operation you can demonstrate, not intentions.
THE OBLIGATIONS
What the CRA actually asks of you.
Security by design (Annex I, Part I)
Products ship without known exploitable vulnerabilities, secure by default, attack surface minimized, with confidentiality and integrity protection designed in.
Cybersecurity risk assessment
A documented assessment of the product’s risks, maintained through planning, design, development and maintenance, and included in the technical documentation.
Vulnerability handling (Annex I, Part II)
Identify and document components, including a machine-readable SBOM; remediate vulnerabilities without delay; run coordinated disclosure; distribute security updates across the support period.
Reporting duties (Art. 14)
From September 2026: notify actively exploited vulnerabilities and severe incidents affecting product security to your CSIRT and ENISA, on staged 24-hour and 72-hour timelines.
Conformity & CE marking
Technical documentation, a conformity assessment matched to the product class (from self-assessment to notified body), the EU declaration of conformity and the CE marking before placing on the market.
HOW MINDLAPSE HELPS
Product duties, run as verified controls.
The CRA rewards teams that already operate a control set: its requirements join your existing frameworks, its risk assessment lives as records, and the evidence is dated rather than declared.
Annex I requirements as controls
Smart Compliance carries the CRA’s essential requirements into your control set with cross-framework mapping, so a measure you already run for ISO 27001 or IEC 62443 is implemented once and evidenced for the CRA too.
Product risk assessment, maintained
Risk Intelligence keeps the product cybersecurity risk assessment as living records: threats, likelihood and impact, treatment decisions, ready for the technical documentation instead of rebuilt for it.
Component & supplier exposure
TPRM assesses the suppliers behind your components, and the Business Value Chain maps which products depend on them, so a vulnerable dependency traces to the products it ships in.
Secure development, from design
The Security by Design workflow attaches security requirements to product initiatives at the design stage and verifies them along the project, never bolted on before release.
Evidence for conformity
The Cyber Cockpit consolidates verified control state into documentation-grade views: what the CE-marking file claims, backed by sourced, dated verdicts.
CRA - FAQ
Frequently asked, directly answered.
Who does the CRA apply to?
To manufacturers of products with digital elements placed on the EU market, hardware or software, consumer or industrial, and to importers and distributors behind them. Open-source software developed outside a commercial activity is largely out of scope, and open-source stewards get a lighter dedicated regime.
When does the CRA apply?
It entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026; the main obligations, including Annex I requirements and CE marking, from 11 December 2027.
What is the support period?
The period during which the manufacturer must handle vulnerabilities and provide security updates. It is set per product to reflect the time users can reasonably expect to use it, with five years as the default reference unless a shorter lifetime is justified.
Does the CRA require an SBOM?
Yes. Manufacturers must identify and document the product’s components, including a software bill of materials in a machine-readable format covering at least the top-level dependencies. It is not published by default, but market surveillance authorities can request it.
How does the CRA relate to NIS2?
NIS2 secures organizations; the CRA secures the products those organizations build, buy and run. A company in both scopes shares most of the underlying measures: Mindlapse maps both regimes onto one control set, so each measure is implemented once and evidenced for each.
GLOSSARY
Terms to know
CRA, OPERATIONALIZED
Your product security, evidence-ready.
Bring one product line. We will show its CRA duties as verified controls, not a checklist.