Getting Started with the Cyber Resilience Act
The Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital elements sold on the EU market. This covers hardware and software products that can connect to a device or network - from IoT devices and operating systems to firmware and standalone software applications. The CRA entered into force on December 10, 2024. Reporting obligations for actively exploited vulnerabilities begin September 11, 2026, and the full set of product security requirements becomes enforceable on December 11, 2027. Matproof maps CRA obligations to controls, evidence workflows, and vulnerability management processes so manufacturers can demonstrate compliance to market surveillance authorities.Activate the CRA under Settings - Frameworks - Cyber Resilience Act. Controls are pre-populated based on whether your products are classified as default, important (Class I or II), or critical.
Am I in Scope?
The CRA applies to any organization that places products with digital elements on the EU market:Product Classification
The CRA uses a tiered classification for products with digital elements:Key Enforcement Dates
Core Requirements in Matproof
Secure by Design
ControlsProducts must be designed and developed with appropriate cybersecurity measures from the start. No known exploitable vulnerabilities at time of release.
Vulnerability Handling
Incidents, ControlsManufacturers must identify and remediate vulnerabilities throughout the product’s expected lifetime (minimum 5 years). Provide security updates free of charge.
Technical Documentation
Evidence, PoliciesMaintain documentation covering security architecture, risk assessment, SBOM (Software Bill of Materials), and testing results.
Conformity Assessment
Audit ProgramsComplete the applicable conformity assessment procedure before placing the product on the market. Affix CE marking.
Incident Reporting
IncidentsReport actively exploited vulnerabilities to ENISA within 24 hours of becoming aware. Report severe incidents within 72 hours.
Security Updates
ControlsProvide timely, free security updates for the entire support period. Document your update delivery mechanism.
Recommended Implementation Plan
Penalties
Next Steps
- Risk Management - product security risk assessments
- Incidents - vulnerability reporting and handling workflows
- Audit Programs - conformity assessment procedures
- Vendor Risk - managing third-party component risks in your supply chain