CloudSignLab

Cyber Resilience Act, Regulation (EU) 2024/2847

Cyber Resilience Act for products with digital elements

The CRA sets security requirements for hardware and software sold in the EU. Reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026, the other obligations from 11 December 2027. CloudSignLab keeps your products, their SBOM and support period, and the reporting deadlines.

Cyber Resilience Act for products with digital elements

What the CRA asks of manufacturers

  • Security by design

    Products are designed, developed and delivered with appropriate cybersecurity, without known exploitable vulnerabilities, with secure default settings.

  • Vulnerability handling

    Identify and document components, including a software bill of materials (SBOM), fix vulnerabilities without delay and provide security updates.

  • Support period

    Security updates for the expected time of use of the product, normally at least five years, stated to the buyer.

  • Reporting

    Actively exploited vulnerabilities and severe incidents are reported through ENISA's single reporting platform: an early warning within 24 hours, a notification within 72 hours and a final report later.

How CloudSignLab helps

  • Product register

    Your products with digital elements, their version, support period and the SBOM file, in one list.

  • Reporting clock

    Mark a vulnerability as actively exploited and see the 24-hour and 72-hour deadlines from the moment you became aware.

  • Vulnerability management

    Record vulnerabilities with severity, owner and due date, linked to the product, and follow them until they are fixed.

  • Readiness from your controls

    Link controls to the CRA requirements and see what is covered before the obligations apply.

Read the CRA guide →

Questions about the CRA

Does the CRA apply to software as a service?

Pure software as a service is generally outside the CRA unless it is remote data processing needed for a product to work; products you sell or install are in scope. Check the definitions in the regulation for your case.

Be ready before the reporting duty starts

Start free, add your products and their SBOM today.

Start free