All solutions Solution · Cyber Resilience Act

Implement the Cyber Resilience Act: conformity that stands before the incident

From the essential requirements in Annex I through vulnerability handling to the reporting chain, isidaten maps the CRA duties in one place. The reporting duties apply from 11 September 2026, full applicability follows on 11 December 2027.

Request a demo
Background

What Cyber Resilience Act requires

The Cyber Resilience Act, Regulation (EU) 2024/2847, requires manufacturers of products with digital elements to ensure cybersecurity across the entire lifecycle. This includes the essential requirements from Annex I, a vulnerability-handling process, a conformity assessment with declaration of conformity and technical documentation, plus reporting duties for actively exploited vulnerabilities and severe incidents.

Essential cybersecurity requirements (Annex I Part I)Vulnerability-handling requirements (Annex I Part II)Reporting of actively exploited vulnerabilities within 24h, 72h and 14 daysConformity assessment and declaration of conformity (DoC)Technical documentation of the productsSecurity updates throughout the support period
FAQ

Frequently asked questions

Who does the Cyber Resilience Act apply to?

The CRA applies to manufacturers, importers and distributors of products with digital elements, meaning hardware and software that can connect to a network or device. Areas with their own regulation, such as medical devices or motor vehicles, are excluded.

When do the duties apply?

The regulation entered into force on 10 December 2024. The reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, the remaining requirements from 11 December 2027.

Does isidaten make me CRA-compliant?

No. Software alone does not create compliance. isidaten maps the control catalog from Annex I in a structured way, keeps the declaration of conformity and documentation and provides the evidence. Implementation and accountability remain with the manufacturer.

How are the CRA and NIS2 related?

The CRA addresses the security of products, NIS2 the security of operators and their networks. Whoever meets both can run vulnerabilities, incidents and evidence on one shared base instead of maintaining two separate worlds.

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.