Cyber Resilience Act · Products with digital elements

Cyber Resilience Act: What applies to your product – and what do you need to do now?

A component supplier reports a vulnerability. A product is approaching release. An external signal suggests a possible security incident. Or you need to determine which CRA requirements are relevant to your product and your role.

The key is to connect the specific product case, your economic-operator role, the current product and version state, and the actual trigger.

Common starting situations

Which situation has brought you to the CRA?

Supplier

A supplier or component manufacturer reports a vulnerability

Does it affect our product, a component we use or a released version?

Connect product and version relevance with component and supplier information and your vulnerability process.

Vulnerability

You learn about a CVE or another vulnerability

How do we determine whether our product is actually affected?

Establish whether the affected component and version are present in your product and what follows technically and operationally.

Incident

A security incident or external signal occurs

Is our product affected – and do we need to assess a CRA reporting path?

Connect first signal, awareness time, technical assessment, internal escalation and any possible reporting obligation.

Release

Your product is approaching release

Which CRA tasks, decisions and evidence need to be completed or consciously managed as open?

Open items need to remain visible and have a controlled next step.

Change

A supplier, firmware item, component or configuration changes

Do we need to reassess our previous CRA work status?

Changes can affect product scope, risk, vulnerability status, supplier evidence or technical documentation.

Evidence

Supplier, SBOM or security evidence is missing

Which information do we actually need – and how should we manage open gaps?

Missing information should remain visible and be requested deliberately.

Overview

What does the Cyber Resilience Act regulate?

The CRA combines cybersecurity requirements for products with obligations across the product lifecycle. Implementation therefore goes beyond technical documentation or a single conformity activity.

  • product security and cybersecurity risk
  • component and supplier control
  • vulnerability management
  • security updates and support
  • reporting of covered events
  • technical documentation and evidence
  • release and reassessment
Practical implementation

From a concrete event to a controlled CRA work status

1

Clarify product case, role and timing

Define the product, variant and version and determine the relevant role.

2

Translate requirements into concrete tasks

Connect requirements with ownership, timing, completion criteria and expected evidence.

3

Work through product security and cybersecurity risk

Tie assessments and measures to the actual product and version state.

4

Connect components, suppliers, SBOM and VEX

Keep supplier and component information connected to product, vulnerability and evidence states.

5

Control vulnerabilities, security updates and support

Turn an external signal into a robust own assessment and response.

6

Prepare security incident and CRA reporting processes

Connect intake, assessment, escalation, reporting decision and supporting evidence.

7

Consolidate evidence and technical target documentation

Keep evidence traceable to a specific product case and decision.

8

Control release, closure and reassessment

Keep open items and future reassessment triggers visible.

Current priority

CRA reporting since September 2026

11 Sep 2026Article 14 applies
24 hinitial reporting step for covered cases
72 hfurther reporting step for covered cases

Mandatory notifications are submitted through the CRA Single Reporting Platform. The concrete reporting obligation must be assessed case by case.

Boundary

Supplier issue or CRA product issue?

CRA product case

The affected component is part of your own product

Product/version relevance, product security, vulnerability assessment, updates, evidence and possible reporting need to be connected.

View the CRA Praxis-Kit →
Structured work

Work through CRA tasks for your specific product case

The SP Services CRA Praxis-Kit supports the path from case orientation through operational work to release, evidence status, closure and reassessment.

View the CRA Praxis-Kit
Cyber Resilience Act (CRA) implementation Praxis-Kit
Official sources and information status
Regulation (EU) 2024/2847 – EUR-Lex
European Commission – CRA Reporting Obligations
Information status: September 2026.