Implement the Cyber Resilience Act: conformity that stands before the incident
From the essential requirements in Annex I through vulnerability handling to the reporting chain, isidaten maps the CRA duties in one place. The reporting duties apply from 11 September 2026, full applicability follows on 11 December 2027.
What Cyber Resilience Act requires
The Cyber Resilience Act, Regulation (EU) 2024/2847, requires manufacturers of products with digital elements to ensure cybersecurity across the entire lifecycle. This includes the essential requirements from Annex I, a vulnerability-handling process, a conformity assessment with declaration of conformity and technical documentation, plus reporting duties for actively exploited vulnerabilities and severe incidents.
How isidaten maps Cyber Resilience Act
Each requirement meets a module that runs on the same object base as the risk register, so the evidence stays connected instead of copied across tools.
Handle vulnerabilities
Capture and assess vulnerabilities in your own products and document their handling, as Annex I Part II requires.
View module: Vulnerability ManagementReport incidents and meet deadlines
Record incidents in a structured way and meet the staged deadlines of 24 hours, 72 hours and 14 days.
View module: IT Service ManagementMake the attack surface visible
Detect exposed assets and vulnerabilities before they are actively exploited and trigger a report.
View module: Attack Surface ManagementAssess risks
Run the risk assessment on which the essential requirements from Annex I build.
View module: Risk RegisterComponents and supply chain
Keep suppliers and components on file, as the basis for due diligence along the supply chain.
View module: Supplier ManagementFrequently asked questions
Who does the Cyber Resilience Act apply to?
The CRA applies to manufacturers, importers and distributors of products with digital elements, meaning hardware and software that can connect to a network or device. Areas with their own regulation, such as medical devices or motor vehicles, are excluded.
When do the duties apply?
The regulation entered into force on 10 December 2024. The reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, the remaining requirements from 11 December 2027.
Does isidaten make me CRA-compliant?
No. Software alone does not create compliance. isidaten maps the control catalog from Annex I in a structured way, keeps the declaration of conformity and documentation and provides the evidence. Implementation and accountability remain with the manufacturer.
How are the CRA and NIS2 related?
The CRA addresses the security of products, NIS2 the security of operators and their networks. Whoever meets both can run vulnerabilities, incidents and evidence on one shared base instead of maintaining two separate worlds.
Ready to simplify your compliance?
Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.