EU CRA Compliance for Secure Software
Prepare for the EU Cyber Resilience Act (Regulation (EU) 2024/2847) with continuous application security, vulnerability management, software supply-chain security, remediation verification, and technical evidence.
Build security in.
Continuously test code, APIs, dependencies, configurations, and application behavior.
Understand supply-chain risk.
Track software composition, vulnerable components, reachability, and remediation.
Manage risk throughout support.
Identify, prioritize, remediate, retest, and document vulnerabilities as products evolve.
Demonstrate what was done.
Maintain technical documentation and security evidence covering testing, findings, remediation, verification, and control effectiveness.
What is EU CRA compliance?
EU CRA compliance means meeting the applicable cybersecurity requirements and obligations of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) for products with digital elements made available on the EU market. Manufacturers must address cybersecurity throughout design, development, production, delivery, maintenance, and vulnerability handling.
Build products with appropriate cybersecurity.
Security requirements are tied to product risk and apply throughout design, development, and production.
Manage vulnerabilities throughout the support period.
Manufacturers need processes to identify, document, address, and remediate vulnerabilities in products and components.
Maintain evidence of cybersecurity decisions.
Cybersecurity risk assessments and the measures used to meet applicable requirements form part of the required technical documentation.
Who must comply with the EU Cyber Resilience Act?
The CRA establishes obligations for economic operators involved in making covered products with digital elements available on the EU market. Responsibilities differ by role and by the applicable provisions of the Regulation.
Build and maintain secure products.
Manufacturers carry primary responsibilities for product cybersecurity, vulnerability handling, technical documentation, and applicable conformity obligations.
Verify applicable requirements.
Importers have obligations to check that relevant CRA requirements have been addressed before placing covered products on the EU market.
Check before making products available.
Distributors also have obligations to verify applicable requirements before making covered products available on the EU market.
What products are covered by the Cyber Resilience Act?
The CRA generally applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, subject to exclusions and special rules in the Regulation.
Software products
Commercial software and other covered software products made available on the EU market.
Hardware products
Connected and digital hardware products within the scope of the Regulation.
Network-connected products
Products whose intended or foreseeable use includes connectivity to a device or network.
Software and hardware components
Covered components placed on the market separately or integrated into products.
When does the EU Cyber Resilience Act apply?
The CRA entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026, while the main CRA provisions apply from 11 December 2027.
The Cyber Resilience Act entered into force.
Reporting obligations for actively exploited vulnerabilities and severe security incidents begin to apply.
The main CRA requirements become applicable.
Key EU Cyber Resilience Act cybersecurity requirements.
The CRA establishes product cybersecurity and vulnerability-handling obligations across the lifecycle. The requirements that apply depend on the product, economic operator, and relevant provisions of the Regulation.
Assess cybersecurity risk.
Identify relevant product cybersecurity risks and account for them throughout planning, design, development, production, delivery, and maintenance.
Build cybersecurity into the product.
Design and develop products to meet applicable essential cybersecurity requirements based on product risk.
Manage vulnerabilities over time.
Identify, document, address, remediate, and disclose vulnerabilities in accordance with applicable CRA requirements.
Understand component risk.
Exercise appropriate diligence when selecting and integrating third-party components into covered products.
Provide security fixes.
Address vulnerabilities and make security updates available in accordance with applicable CRA requirements.
Document cybersecurity measures.
Maintain technical documentation showing how applicable cybersecurity requirements are addressed.
Report qualifying events.
Meet applicable reporting obligations for actively exploited vulnerabilities and severe incidents under Article 14.
Maintain cybersecurity.
Continue vulnerability handling and security maintenance for the applicable support period.
Put EU CRA cybersecurity requirements into practice.
Aptori helps product and security teams continuously test software, identify vulnerable components, prioritize security risk, verify remediation, and maintain evidence of the security work performed throughout the product lifecycle.
Finding a vulnerability is only the beginning.
The CRA makes vulnerability handling a lifecycle responsibility. Aptori helps teams move from discovery to prioritized remediation and verification, while preserving evidence of what changed.
Explore Continuous Vulnerability Management →Know what is inside the product—and which components create real risk.
Identify vulnerable dependencies.
Continuously analyze open-source and third-party software components.
Maintain software inventory.
Generate and use software bills of materials to understand product composition.
Prioritize meaningful exposure.
Determine whether vulnerable components can actually affect the product.
Track component fixes.
Connect dependency risk to ownership, remediation, retesting, and evidence.
Cyber Resilience Act legislation and implementation guidance.
Use the European Union's primary sources for the legal text, implementation guidance, scope, timelines, conformity assessment, and reporting requirements.
EU CRA compliance.
What is EU CRA compliance?
EU CRA compliance means meeting the applicable obligations of Regulation (EU) 2024/2847, the Cyber Resilience Act, for products with digital elements made available on the EU market.
What is the EU Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847. It establishes cybersecurity requirements for covered products with digital elements and obligations for relevant economic operators across the product lifecycle.
Who must comply with the EU Cyber Resilience Act?
The CRA establishes obligations for manufacturers, importers, and distributors involved in making covered products with digital elements available on the EU market. The applicable responsibilities vary by role and product.
What products are covered by the Cyber Resilience Act?
The CRA generally applies to hardware and software products with digital elements made available on the EU market when their intended or reasonably foreseeable use includes a direct or indirect connection to a device or network, subject to exclusions in the Regulation.
When does the Cyber Resilience Act apply?
The CRA entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026, while the main provisions apply from 11 December 2027.
What are the key EU CRA requirements?
Key areas include cybersecurity risk assessment, essential cybersecurity requirements, vulnerability handling, security updates, third-party component diligence, technical documentation, conformity obligations, and applicable vulnerability and incident reporting.
What are the CRA vulnerability handling requirements?
Manufacturers must have processes to handle vulnerabilities effectively during the product support period, including identifying, documenting, addressing, and remediating vulnerabilities in products and their components.
Does the Cyber Resilience Act require an SBOM?
The CRA creates obligations around product and component cybersecurity, vulnerability handling, and technical information. SCA and SBOM practices can help manufacturers understand third-party components, identify vulnerable dependencies, support vulnerability handling, and maintain useful software-component information for CRA processes.
What is the CRA support period?
The CRA requires manufacturers to handle vulnerabilities during the applicable support period. The precise duration and obligations should be determined from the Regulation and applicable implementation guidance for the product.
How does application security support EU CRA compliance?
Application security helps manufacturers build secure-by-design software, identify and remediate vulnerabilities, manage third-party components, validate application and API security, and maintain evidence of cybersecurity activity.
Does Aptori certify Cyber Resilience Act compliance?
No. Aptori helps organizations implement, validate, monitor, and demonstrate software-security practices and controls that can support a broader EU CRA compliance program. Compliance and conformity assessment remain the responsibility of the applicable economic operator.
