Skip to main content

Getting Started with the Cyber Resilience Act

The Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital elements sold on the EU market. This covers hardware and software products that can connect to a device or network - from IoT devices and operating systems to firmware and standalone software applications. The CRA entered into force on December 10, 2024. Reporting obligations for actively exploited vulnerabilities begin September 11, 2026, and the full set of product security requirements becomes enforceable on December 11, 2027. Matproof maps CRA obligations to controls, evidence workflows, and vulnerability management processes so manufacturers can demonstrate compliance to market surveillance authorities.
Activate the CRA under Settings - Frameworks - Cyber Resilience Act. Controls are pre-populated based on whether your products are classified as default, important (Class I or II), or critical.

Am I in Scope?

The CRA applies to any organization that places products with digital elements on the EU market:
Open source software developed in a non-commercial context is generally excluded. However, if an open source project is used commercially or integrated into a commercial product, the CRA may apply to the integrator as the manufacturer.

Product Classification

The CRA uses a tiered classification for products with digital elements:
Most software products fall into the default category and can use self-assessment. Check Annexes III and IV of the regulation for the complete product lists in each class.

Key Enforcement Dates


Core Requirements in Matproof

Secure by Design

ControlsProducts must be designed and developed with appropriate cybersecurity measures from the start. No known exploitable vulnerabilities at time of release.

Vulnerability Handling

Incidents, ControlsManufacturers must identify and remediate vulnerabilities throughout the product’s expected lifetime (minimum 5 years). Provide security updates free of charge.

Technical Documentation

Evidence, PoliciesMaintain documentation covering security architecture, risk assessment, SBOM (Software Bill of Materials), and testing results.

Conformity Assessment

Audit ProgramsComplete the applicable conformity assessment procedure before placing the product on the market. Affix CE marking.

Incident Reporting

IncidentsReport actively exploited vulnerabilities to ENISA within 24 hours of becoming aware. Report severe incidents within 72 hours.

Security Updates

ControlsProvide timely, free security updates for the entire support period. Document your update delivery mechanism.


Penalties


Next Steps