EU Cyber Resilience Act (CRA) Compliance

Introduction

The EU Cyber Resilience Act (CRA) introduces strict cybersecurity standards for all hardware and software products with digital elements sold within the European market. Software creators, MedTech developers, and SaaS providers face legal mandates covering security-by-design, mandatory Software Bill of Materials (SBOM) tracking, and rapid 24-hour vulnerability reporting to ENISA.

The comparison

Compliance Domain EU CRA Legal Requirement Operational & Technical Execution
Product Risk Classification Tiered categorization based on cybersecurity risk: Default, Important (Class I & II), and Critical. Audit software components to determine required conformity path (self-assessment vs. third-party certification).
Security by Design & Default Products must be delivered secure-by-default, minimizing attack surface and eliminating known exploitable flaws. Integrate secure coding practices, zero-trust architecture, and strict encryption for data at rest and in transit.
Software Bill of Materials (SBOM) Mandatory identification and documentation of all third-party and open-source software dependencies. Maintain real-time, machine-readable SBOM tracking (e.g., SPDX or CycloneDX) across the full software supply chain.
Vulnerability & Incident Reporting Active reporting of exploited vulnerabilities within 24 hours to ENISA/CSIRTs, with full updates within 72 hours. Deploy automated vulnerability scanning, coordinated disclosure protocols, and rapid hotfix deployment pipelines.
Lifecycle Support & CE Marking Guaranteed security update support period (minimum 5 years) and mandatory CE marking before market release. Publish clear update commitments, issue technical documentation (Annex V), and affix CE mark to compliant software/hardware.

Mandatory CRA Requirements for Digital Products

The EU Cyber Resilience Act (CRA) establishes hardware and software security rules for products with digital elements sold within the EU market.

  • Security by Design: Software products must be delivered without known exploitable vulnerabilities and configured securely by default.
  • Vulnerability Handling: Manufacturers must document, patch, and publicly report actively exploited vulnerabilities within 24 hours to ENISA.
  • Software Bill of Materials (SBOM): Companies must maintain an up-to-date SBOM covering all third-party and open-source dependencies.
  • CE Marking for Software: Compliant products must bear the CE mark to demonstrate conformity before commercial release in the EU.