Back to all articles
Fundamentals·21 July 2026·4 min read

What the Cyber Resilience Act actually is, in plain English

The CRA in one read: what it covers, who it binds, and the two dates that decide how urgent it is for you.

The Cyber Resilience Act, Regulation (EU) 2024/2847, is the EU's cybersecurity law for products. If you sell something that runs software or connects to a network into the EU, it sets rules for how secure that product has to be, how you handle flaws in it, and what you have to tell the authorities when something goes wrong.

It is easy to assume this is another privacy law like GDPR. It is not. GDPR is about how you handle personal data. The CRA is about the security of the product itself, from how it is built to how long you keep patching it.

What it covers

The CRA covers products with digital elements. That phrase is deliberately broad. It includes connected hardware, the firmware inside it, and standalone software such as apps, operating systems, and developer tools sold commercially. Pure online services with nothing to install are generally outside scope, unless the cloud service is the backend a covered product needs to function.

Who it binds

The duties fall mainly on the manufacturer, meaning whoever develops the product or sells it under their own name. This holds even if you are outside the EU. A company in the United States selling a smart sensor through a German distributor is covered, and its EU distributor cannot take the obligation on for it. The distributor's job is to check that the manufacturer did the work, not to do it for them.

The two dates

Two deadlines decide how urgent this is. On 11 September 2026, the reporting duties begin: you must report actively exploited vulnerabilities and severe incidents on a fixed clock. From 11 December 2027, the full regulation applies, and a product without a compliant technical file cannot carry the CE mark or stay on the EU market. Penalties reach 15 million euro or 2.5% of worldwide turnover, whichever is higher.

The good news most teams miss: about 90% of products can legally self-assess, without a notified body or a lab. The work is documentation, and it is doable. The next articles walk through each piece.