EU CRA COMPLIANCE

EU CRA Compliance for Secure Software

Prepare for the EU Cyber Resilience Act (Regulation (EU) 2024/2847) with continuous application security, vulnerability management, software supply-chain security, remediation verification, and technical evidence.

Secure by designVulnerability handlingSoftware supply chainTechnical evidence
Cyber Resilience Act security lifecycleDESIGN → DEVELOP → MAINTAIN → PROVE
DESIGN AND DEVELOP

Build security in.

Continuously test code, APIs, dependencies, configurations, and application behavior.

THIRD-PARTY COMPONENTS

Understand supply-chain risk.

Track software composition, vulnerable components, reachability, and remediation.

VULNERABILITY HANDLING

Manage risk throughout support.

Identify, prioritize, remediate, retest, and document vulnerabilities as products evolve.

TECHNICAL EVIDENCE

Demonstrate what was done.

Maintain technical documentation and security evidence covering testing, findings, remediation, verification, and control effectiveness.

SECURE DEVELOPMENT → VULNERABILITY HANDLING → VERIFIED REMEDIATION → EVIDENCE
CYBER RESILIENCE ACT

What is EU CRA compliance?

EU CRA compliance means meeting the applicable cybersecurity requirements and obligations of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) for products with digital elements made available on the EU market. Manufacturers must address cybersecurity throughout design, development, production, delivery, maintenance, and vulnerability handling.

SECURE BY DESIGN

Build products with appropriate cybersecurity.

Security requirements are tied to product risk and apply throughout design, development, and production.

VULNERABILITY HANDLING

Manage vulnerabilities throughout the support period.

Manufacturers need processes to identify, document, address, and remediate vulnerabilities in products and components.

TECHNICAL DOCUMENTATION

Maintain evidence of cybersecurity decisions.

Cybersecurity risk assessments and the measures used to meet applicable requirements form part of the required technical documentation.

CRA SCOPE

Who must comply with the EU Cyber Resilience Act?

The CRA establishes obligations for economic operators involved in making covered products with digital elements available on the EU market. Responsibilities differ by role and by the applicable provisions of the Regulation.

MANUFACTURERS

Build and maintain secure products.

Manufacturers carry primary responsibilities for product cybersecurity, vulnerability handling, technical documentation, and applicable conformity obligations.

IMPORTERS

Verify applicable requirements.

Importers have obligations to check that relevant CRA requirements have been addressed before placing covered products on the EU market.

DISTRIBUTORS

Check before making products available.

Distributors also have obligations to verify applicable requirements before making covered products available on the EU market.

PRODUCTS WITH DIGITAL ELEMENTS

What products are covered by the Cyber Resilience Act?

The CRA generally applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, subject to exclusions and special rules in the Regulation.

SOFTWARE

Software products

Commercial software and other covered software products made available on the EU market.

HARDWARE

Hardware products

Connected and digital hardware products within the scope of the Regulation.

CONNECTED PRODUCTS

Network-connected products

Products whose intended or foreseeable use includes connectivity to a device or network.

COMPONENTS

Software and hardware components

Covered components placed on the market separately or integrated into products.

CRA TIMELINE

When does the EU Cyber Resilience Act apply?

The CRA entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026, while the main CRA provisions apply from 11 December 2027.

IN FORCE10 Dec 2024

The Cyber Resilience Act entered into force.

ARTICLE 14 REPORTING11 Sep 2026

Reporting obligations for actively exploited vulnerabilities and severe security incidents begin to apply.

MAIN PROVISIONS11 Dec 2027

The main CRA requirements become applicable.

KEY CRA REQUIREMENTS

Key EU Cyber Resilience Act cybersecurity requirements.

The CRA establishes product cybersecurity and vulnerability-handling obligations across the lifecycle. The requirements that apply depend on the product, economic operator, and relevant provisions of the Regulation.

RISK ASSESSMENT

Assess cybersecurity risk.

Identify relevant product cybersecurity risks and account for them throughout planning, design, development, production, delivery, and maintenance.

SECURE BY DESIGN

Build cybersecurity into the product.

Design and develop products to meet applicable essential cybersecurity requirements based on product risk.

VULNERABILITY HANDLING

Manage vulnerabilities over time.

Identify, document, address, remediate, and disclose vulnerabilities in accordance with applicable CRA requirements.

THIRD-PARTY COMPONENTS

Understand component risk.

Exercise appropriate diligence when selecting and integrating third-party components into covered products.

SECURITY UPDATES

Provide security fixes.

Address vulnerabilities and make security updates available in accordance with applicable CRA requirements.

TECHNICAL DOCUMENTATION

Document cybersecurity measures.

Maintain technical documentation showing how applicable cybersecurity requirements are addressed.

REPORTING

Report qualifying events.

Meet applicable reporting obligations for actively exploited vulnerabilities and severe incidents under Article 14.

PRODUCT LIFECYCLE

Maintain cybersecurity.

Continue vulnerability handling and security maintenance for the applicable support period.

HOW APTORI SUPPORTS EU CRA COMPLIANCE

Put EU CRA cybersecurity requirements into practice.

Aptori helps product and security teams continuously test software, identify vulnerable components, prioritize security risk, verify remediation, and maintain evidence of the security work performed throughout the product lifecycle.

EU CRA REQUIREMENT
WHAT IT MEANS FOR SOFTWARE TEAMS
HOW APTORI SUPPORTS IT
Secure by designIdentify and address security weaknesses during development.AI SAST, application security testing, API security, and CI/CD security.
Risk assessmentUnderstand product security risk and relevant attack paths.Determine which vulnerabilities can be exploited and prioritize the risks that matter most.
Third-party componentsExercise due diligence over integrated software components.SCA, SBOM, reachability, EPSS, KEV, and dependency remediation workflows.
Vulnerability handlingIdentify, document, address, and remediate vulnerabilities.Continuous Vulnerability Management connects findings to ownership, fixes, retesting, and evidence.
Technical evidenceMaintain technical documentation and security evidence showing how applicable cybersecurity requirements are addressed.Preserve testing, vulnerability, remediation, and verification records as technical documentation and security evidence.
VULNERABILITY MANAGEMENT THROUGHOUT THE PRODUCT LIFECYCLE

Finding a vulnerability is only the beginning.

The CRA makes vulnerability handling a lifecycle responsibility. Aptori helps teams move from discovery to prioritized remediation and verification, while preserving evidence of what changed.

Explore Continuous Vulnerability Management →
DISCOVERIdentify vulnerabilities.Code, APIs, dependencies, containers, and application behavior.
PRIORITIZEPrioritize the highest risks.Exploitability, reachability, known exploitation, and application impact.
REMEDIATEFix the weakness.Ownership, root cause, developer guidance, and corrective action.
VERIFYVerify the vulnerability is no longer exploitable.Retest the affected software or component and preserve evidence.
DISCOVER → PRIORITIZE → REMEDIATE → VERIFY → DOCUMENT
SOFTWARE SUPPLY CHAIN

Know what is inside the product—and which components create real risk.

SCA

Identify vulnerable dependencies.

Continuously analyze open-source and third-party software components.

SBOM

Maintain software inventory.

Generate and use software bills of materials to understand product composition.

REACHABILITY

Prioritize meaningful exposure.

Determine whether vulnerable components can actually affect the product.

REMEDIATION

Track component fixes.

Connect dependency risk to ownership, remediation, retesting, and evidence.

Explore Software Composition Analysis →

AUTHORITATIVE EU CRA RESOURCES

Cyber Resilience Act legislation and implementation guidance.

Use the European Union's primary sources for the legal text, implementation guidance, scope, timelines, conformity assessment, and reporting requirements.

FAQ

EU CRA compliance.

What is EU CRA compliance?

EU CRA compliance means meeting the applicable obligations of Regulation (EU) 2024/2847, the Cyber Resilience Act, for products with digital elements made available on the EU market.

What is the EU Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847. It establishes cybersecurity requirements for covered products with digital elements and obligations for relevant economic operators across the product lifecycle.

Who must comply with the EU Cyber Resilience Act?

The CRA establishes obligations for manufacturers, importers, and distributors involved in making covered products with digital elements available on the EU market. The applicable responsibilities vary by role and product.

What products are covered by the Cyber Resilience Act?

The CRA generally applies to hardware and software products with digital elements made available on the EU market when their intended or reasonably foreseeable use includes a direct or indirect connection to a device or network, subject to exclusions in the Regulation.

When does the Cyber Resilience Act apply?

The CRA entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026, while the main provisions apply from 11 December 2027.

What are the key EU CRA requirements?

Key areas include cybersecurity risk assessment, essential cybersecurity requirements, vulnerability handling, security updates, third-party component diligence, technical documentation, conformity obligations, and applicable vulnerability and incident reporting.

What are the CRA vulnerability handling requirements?

Manufacturers must have processes to handle vulnerabilities effectively during the product support period, including identifying, documenting, addressing, and remediating vulnerabilities in products and their components.

Does the Cyber Resilience Act require an SBOM?

The CRA creates obligations around product and component cybersecurity, vulnerability handling, and technical information. SCA and SBOM practices can help manufacturers understand third-party components, identify vulnerable dependencies, support vulnerability handling, and maintain useful software-component information for CRA processes.

What is the CRA support period?

The CRA requires manufacturers to handle vulnerabilities during the applicable support period. The precise duration and obligations should be determined from the Regulation and applicable implementation guidance for the product.

How does application security support EU CRA compliance?

Application security helps manufacturers build secure-by-design software, identify and remediate vulnerabilities, manage third-party components, validate application and API security, and maintain evidence of cybersecurity activity.

Does Aptori certify Cyber Resilience Act compliance?

No. Aptori helps organizations implement, validate, monitor, and demonstrate software-security practices and controls that can support a broader EU CRA compliance program. Compliance and conformity assessment remain the responsibility of the applicable economic operator.

EU CRA COMPLIANCE

Build security into the product lifecycle. Demonstrate what you've done.

Discuss EU CRA Compliance ↗