ConfirmedEU-wideCyber Resilience Act

CRA: full application – secure-by-design requirements, conformity assessment and CE marking for software and connected products

460 days from today

What changes

From this date every product with digital elements placed on the EU market must meet the essential cybersecurity requirements (secure defaults, no known exploitable vulnerabilities, security updates for the support period, SBOM), pass a conformity assessment and carry CE marking. Importers and distributors must check compliance.

Who is affected

Manufacturers, importers and distributors of software and connected hardware sold in the EU, including small SaaS vendors that ship client software, IoT makers and app developers.

Sizes: micro, small, medium, large · Sectors: Software / SaaS, Hardware / electronics, Manufacturing · Applies if: We make connected hardware / devices; We sell online

What to do

Classify each product (default, important class I/II, or critical) to know whether self-assessment is enough. Implement a secure development lifecycle, vulnerability handling and update policy, and generate an SBOM. Prepare technical documentation, the EU declaration of conformity and user security information. Define the product's support period (at least 5 years by default).

Penalty

Up to €15M or 2.5% of worldwide turnover

Sources

Last verified 7 September 2026. Informational only, not legal advice.

More Cyber Resilience Act deadlines