- Cyber Essentials
- 22nd Sep 2026
- 1 min read
What Is the EU Cyber Resilience Act? A UK Compliance Guide
- Written by
In Short..
- UK organisations are in scope: selling a product with digital elements to EU buyers, directly or through an EU subsidiary or distributor, brings you under the CRA – headquarters and incorporation are irrelevant.
- Reporting duties are already live: Article 14 has required manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs since 11 September 2026.
- Full compliance lands 11 December 2027: that's when the essential requirements, technical documentation, SBOM and CE marking obligations apply to every product placed on the EU market.
- Product class determines the route: most products self-assess; those in Annex III (important) or Annex IV (critical) face tougher, sometimes third-party, conformity assessment.
- Penalties are calculated on worldwide turnover: up to €15 million or 2.5% of global annual turnover, not just EU revenue.
The practical takeaway: if your product reaches EU buyers, your reporting obligations already exist, and your compliance programme has fifteen months to be ready for the rest.
Introduction
The EU Cyber Resilience Act (CRA) sets mandatory cybersecurity requirements for products with digital elements sold into the EU, and it already applies to UK organisations that sell there. Adopted on 23 October 2024 and in force since 10 December 2024, Regulation (EU) 2024/2847 covers software, connected hardware and the remote services that support them, from enterprise platforms to smart home devices. Reporting duties under Article 14 are live now; the rest of the regulation applies in full from 11 December 2027. For the reporting mechanics specifically, see our CRA reporting requirements guide.
Most coverage treats this as an EU-only concern, which misreads how far the regulation reaches. The CRA applies to any organisation, anywhere, that places a product with digital elements on the EU market. A UK manufacturer selling into the EU carries the same duties as one based in Berlin or Paris – incorporation and headquarters don’t factor into it. The regulation asks one question: is a product with digital elements being placed on the EU market?
For UK compliance and risk teams, that distinction matters. The UK has no domestic equivalent to the CRA, so a compliance programme has to be built directly from the EU requirements themselves. This guide covers what the CRA is, who it binds, what it requires, and what it means for UK organisations selling into the EU.
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What Our Experts Say About Closing the UK's CRA Gap
"Most manufacturers we talk to have a NIS2 or GDPR programme, but nothing that maps to the CRA’s product obligations. Article 14’s reporting deadlines catch that gap first, well before 2027. Building it now, while the stakes are lower, beats waiting for the deadline to force it." |
What the CRA Is and Why It Was Introduced
The Cyber Resilience Act is the EU's first horizontal cybersecurity law for products: it cuts across every sector and product category rather than targeting one industry. Earlier EU cybersecurity legislation, such as the NIS2 Directive, regulates operators of essential services. The CRA regulates the products those services run on.
The problem it addresses is largely structural: for decades, manufacturers of connected products had no legal obligation to build security in from the start. Cybersecurity was often treated as an afterthought, patched in later if at all; devices and software shipped with known vulnerabilities, default passwords, and no mechanism for receiving security updates. The European Commission's 2022 proposal cited the scale of the problem: global cybercrime cost an estimated €5.5 trillion in 2021, according to the figures it was working from at the time.
The CRA changes that model. Security is mandatory at the design stage now: manufacturers have to build it in, document it, maintain it through the product's lifecycle, and report when things go wrong. The regulation covers the full value chain, not just manufacturers but importers and distributors too.
What Article 1 Covers
Article 1 sets out four things: rules for placing products with digital elements on the EU market, essential cybersecurity requirements for how they're designed and built, obligations on manufacturers to handle vulnerabilities for as long as a product stays in use, and the market surveillance and enforcement mechanics behind all of it. CE marking under the CRA signals that a product meets those requirements, and it's what keeps EU market access open – from 11 December 2027, only a product carrying it can lawfully be placed on the EU market.
Who the CRA Applies To
The CRA applies to three categories of economic operators, each with distinct obligations.
|
Role |
Definition |
Core duties |
|
Manufacturer |
Designs, develops or produces a product with digital elements and places it on the EU market under its own name or trademark |
Essential requirements, conformity assessment, CE marking, technical documentation, vulnerability handling, reporting |
|
Importer |
An EU-established party placing on the market a product bearing the name or trademark of someone established outside the EU |
Verify manufacturer compliance before placing on market; stop non-compliant products |
|
Distributor |
Anyone in the supply chain making a product available on the EU market, other than the manufacturer or importer |
Check CE marking and documentation; act with due care; notify authorities of non-compliance |
UK organisations usually fall into the manufacturer category. If your company develops a product and makes it available to EU buyers under your own name or trademark, you're the manufacturer, and you carry the full set of duties.
Routing sales through an EU importer adds a second regulated party; the duties themselves stay with you. The EU importer has to verify that you, as manufacturer, have completed the conformity assessment, drawn up the technical documentation and affixed CE marking before they can lawfully place the product on the market. Skip that work, and your EU distribution channel stops.
Three Scenarios Where the CRA Binds a UK Organisation
- Direct sale to EU customers: the UK company is the manufacturer and carries all obligations.
- Sale via an EU subsidiary under the UK parent's brand: the EU entity is likely an importer with its own verification duties; the UK parent remains the manufacturer.
- White-label or marketplace routes: if a distributor or marketplace takes a UK product across the EU border under any arrangement, CRA obligations attach at that point.
The only UK organisation outside the CRA is one with no EU sales and no EU distribution arrangements at all.
Products with Digital Elements: What Counts
The CRA's scope turns on the concept of a “product with digital elements” (PDE): any software or hardware product, and its remote data processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. In practice, that covers most modern technology. If it connects, it's generally in scope.
What Is Included
- Enterprise and consumer software applications
- Operating systems and embedded software
- Mobile applications
- Cloud-connected hardware (routers, smart devices, industrial controllers)
- Security tools (VPNs, firewalls, identity management software, SIEM systems)
- IoT devices (smart home products, wearables, connected industrial equipment)
- Software components placed on the market separately
What Is Excluded
The CRA carves out categories where sectoral legislation already applies or the public interest justifies different treatment:
- Medical devices and in vitro diagnostic devices (covered by EU MDR/IVDR)
- Motor vehicles and civil aviation products
- Marine equipment
- Products developed or modified exclusively for national security or defence purposes
- Free and open-source software developed and supplied outside a commercial activity, though a lighter regime applies to commercial open-source stewards
The exclusions are narrower than most organisations assume. A product sold commercially that happens to use open-source components remains in scope. If in doubt, the default position is that the product falls within it.
The Three Product Classes
Products face different levels of scrutiny depending on their class. The CRA creates three product classes, each with a different conformity assessment route, and the class a product falls into determines how much independent verification is needed before CE marking can be applied.
Default Products
Most products with digital elements fall here. Manufacturers can self-assess conformity against the essential requirements in Annex I, draw up the technical documentation, affix CE marking, and issue an EU declaration of conformity. No third-party assessment is required.
Important Products: Class I and Class II (Annex III)
Annex III products are considered higher risk because of their function or how widely they're used. They face enhanced conformity assessment, which can involve a notified body.
Class I includes, among others: identity management and privileged access management (PAM) software, browsers and password managers, VPN products, network management and SIEM systems, operating systems, routers, modems and switches intended for internet connection, smart home security products such as door locks, cameras and alarms, and internet-connected toys.
Class II covers a narrower, higher-risk tier: hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, and tamper-resistant microprocessors and microcontrollers. (Full Annex III classification breakdown.)
Critical Products (Annex IV)
A small number of products are designated critical. These require mandatory third-party conformity assessment by a notified body and, where required, a European Cybersecurity Certificate at assurance level “substantial” or above. Current Annex IV categories include hardware devices with security boxes and smart meter gateways.
If your product appears in Annex III or IV, the conformity route is more demanding and the lead time for certification is longer. Identifying your product class is the first step in any CRA readiness programme; our CRA requirements guide covers the conformity assessment routes in more detail.
Core Obligations: What the CRA Actually Requires
The CRA's substantive obligations fall into three areas: secure design and development, vulnerability handling, and documentation. All three sit in Annex I of the regulation and apply throughout the product's entire lifecycle.
Secure by Design (Annex I, Part I)
Manufacturers have to ensure products are designed, developed and produced with a level of cybersecurity appropriate to the risks. The specific requirements include:
- No known exploitable vulnerabilities at the point of market placement
- Secure by default configuration, including the ability to reset to original state
- Protection of confidentiality through encryption of data at rest and in transit
- Protection of data integrity against unauthorised manipulation
- Minimal data collection: only data that's adequate, relevant and necessary for the intended purpose
- Resilience against denial-of-service attacks
- Appropriate access controls, including authentication and identity management
- A minimum support period of five years (or the expected product lifetime if shorter), during which security updates must be provided free of charge
Vulnerability Handling (Annex I, Part II)
This is where the operational burden becomes concrete. Manufacturers must:
- Identify and document vulnerabilities and components, including a software bill of materials (SBOM) in a machine-readable format covering at least the top-level dependencies
- Remediate vulnerabilities without delay and provide security updates separately from functionality updates where technically feasible
- Apply regular security testing and reviews throughout the support period
- Publish information about fixed vulnerabilities, including severity and remediation guidance
- Run a coordinated vulnerability disclosure policy and a contact address for reporting
- Distribute security updates automatically where applicable, and always free of charge
Documentation and Conformity
Manufacturers have to maintain technical documentation showing compliance with the Annex I requirements, draw up an EU declaration of conformity, and affix CE marking. Under Article 13, that documentation and the declaration of conformity must stay available to market surveillance authorities for at least ten years after the product is placed on the market, or for as long as the support period runs if that's longer.
That documentation burden is substantial. For organisations without an existing product security programme, building the technical file from scratch – risk assessments, SBOM, test records, vulnerability handling procedures – represents a considerable compliance investment.
Reporting Obligations: The First Live Deadline
The CRA's reporting obligations under Article 14 are already in force. They applied from 11 September 2026, well ahead of the December 2027 compliance deadline, and this is the first point at which non-compliance carries operational consequences.
Manufacturers have to report to ENISA (the EU Agency for Cybersecurity) and the relevant national Computer Security Incident Response Team (CSIRT) in two scenarios.
Actively Exploited Vulnerabilities
When a manufacturer becomes aware that a vulnerability in its product is being actively exploited:
- Within 24 hours: Early warning notification to ENISA and the relevant CSIRT
- Within 72 hours: Detailed assessment of the vulnerability
- Within 14 days: Final report once a corrective or mitigating measure is available
Severe Security Incidents
When a manufacturer becomes aware of a severe incident affecting the security of its product:
- Within 24 hours: Early warning notification
- Within 72 hours: Detailed incident report
- Within one month: Final report after the 72-hour notification
These timelines apply to products already on the EU market, not just new releases; existing products get the same treatment as new ones, with no phase-in period. A UK manufacturer with a product already in EU distribution was subject to these reporting obligations from 11 September 2026, regardless of when the product first reached the market.
The 24-hour window is demanding to run in practice. Manufacturers need established processes to identify whether a vulnerability is being actively exploited, engage technical and legal teams, and submit a compliant notification before the clock runs out. For organisations without mature vulnerability management, that's a capability gap to close.
What the CRA Means for UK Businesses Selling into the EU
The CRA creates a compliance asymmetry UK organisations need to understand clearly: the EU now has a detailed, binding product cybersecurity regime that the UK has yet to match. That gap has direct commercial consequences.
No Domestic Equivalent to Benchmark Against
The UK's Cyber Security and Resilience Bill, introduced in November 2025, is still moving through Parliament; it reached Report stage in the House of Lords in September 2026, with Royal Assent still pending. It focuses on operators of essential services and their supply chains, leaving product cybersecurity outside its scope, so its obligations diverge sharply from the CRA's product-level requirements (our guide to the Bill covers its own scope and timelines). UK manufacturers selling into the EU are building compliance programmes directly against the EU requirements, calibrated against that framework alone.
EU Market Access Is Conditional from December 2027
From 11 December 2027, every product with digital elements placed on the EU market for the first time has to comply with the CRA's essential requirements and carry CE marking. Products already on the market before that date are exempt from the substantive requirements retrospectively, though they remain caught by the Article 14 reporting obligations that took effect in September 2026.
Every new unit, new version and substantial modification placed after 11 December 2027 has to comply in full. Organisations that delay compliance are accepting that their EU market access ends on that date.
Penalties
Non-compliance carries significant financial exposure:
- Up to €15 million or 2.5% of worldwide annual turnover (whichever is higher) for breach of the essential requirements, conformity assessment obligations, or reporting duties
- Up to €10 million or 2% for other manufacturer, importer and distributor obligations
- Up to €5 million or 1% for supplying incorrect or misleading information to authorities
- Market surveillance authorities can require withdrawal or recall of products from the EU market
The fines are calculated against a company's entire worldwide turnover, including revenue earned well outside the EU. A UK company with modest EU sales but considerable global revenue faces exposure calibrated to its full commercial scale.
The Relationship with NIS2 and DORA
The CRA sits alongside the NIS2 Directive and DORA rather than replacing either. NIS2 applies to operators of essential services; DORA applies to financial entities; the CRA applies to product manufacturers. Many organisations will find themselves subject to more than one regime at once, so mapping where they overlap and where they diverge matters for avoiding duplicated effort and compliance gaps. Our CRA vs NIS2 and DORA comparison works through the mapping in detail.
CRA Timeline: Key Dates at a Glance
The CRA's obligations switch on in stages. Knowing which deadline applies to which obligation matters for sequencing a compliance programme.
|
Date |
What Applies |
Who It Affects |
|
10 Dec 2024 |
Regulation enters into force; the clock starts |
All organisations in scope |
|
11 Jun 2026 |
Notified body framework applies; Member States designate notifying authorities |
Products needing third-party assessment (Class I, II, critical) |
|
11 Sep 2026 |
Article 14 reporting obligations: actively exploited vulnerabilities and severe incidents must be reported to ENISA and national CSIRTs |
All manufacturers with products on the EU market |
|
11 Dec 2027 |
Full application: essential requirements, Annex I, SBOM, technical documentation, CE marking, conformity assessment, support period |
Every product placed on the EU market from this date |
The September 2026 reporting deadline has already passed. UK manufacturers with products on the EU market are now working under live reporting obligations, with the December 2027 deadline for full compliance fifteen months away. For a fuller breakdown of each milestone and how to sequence a readiness programme against it, see our CRA compliance timeline guide.
Where to Start: Mapping Your Obligations
Understanding the CRA is the first step. Acting on it is the next. For most UK organisations, the practical starting point is a structured scoping exercise across three questions.
- Are any of your products with digital elements placed on the EU market? This includes direct sales, sales via EU subsidiaries under your brand, and products distributed through EU partners under your trademark.
- What is your role? Manufacturer, importer or distributor. The answer determines your obligation set and, critically, whether you carry the full burden of conformity assessment or a verification duty.
- What product class are your products? Default, Class I, Class II or critical. The class determines the conformity assessment route and the lead time required.
From those three answers, a compliance roadmap becomes workable. The Article 14 reporting obligations are already live, so vulnerability management and incident response processes should be the immediate priority; the full Annex I requirements, technical documentation, SBOM and CE marking programme need to be in place before 11 December 2027.
SureCloud's Compliance Management module gives your team a structured, auditable place to build out a CRA framework mapping, track obligations against the requirements you've identified, and pull evidence together as your programme develops, rather than reconstructing it in a spreadsheet every time an auditor asks.
Build Your CRA Readiness Without Starting from a Blank Spreadsheet
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Let Gracie get the work done.
Gracie drafts summaries, evidence requests and audit narratives across your programme — you stay in control.
See Gracie in action or book a full platform demo →See what SureCloud costs
A short form, no sales call. Pricing built around your GRC estate.
Get PricingIDC names SureCloud the industry's first cross-domain agentic GRC platform"
Read the independent analyst view on how SureCloud is redefining risk and compliance.
Download for freeFAQ’s
Does the CRA apply to UK companies after Brexit?
Yes. The CRA applies to any organisation that places products with digital elements on the EU market, regardless of where that organisation is incorporated or headquartered. Brexit removed the UK from the EU's internal market; UK companies selling into the EU remain within its regulatory reach regardless.
Does the CRA apply to software as well as hardware?
Yes. The CRA covers software products, hardware products, and remote data processing solutions that connect directly or indirectly to a device or network. Standalone software applications, operating systems, mobile apps and SaaS products with a device-side component all fall within scope. Pure cloud services with no device-side element sit outside it, though hybrid architectures need careful analysis.
What counts as a “substantial modification” that triggers re-compliance?
A substantial modification is one that affects a product's cybersecurity properties or changes its intended purpose. Routine security patches and minor bug fixes don't count. Significant new features, architectural changes, or modifications that introduce new connectivity do, and any substantial modification made after 11 December 2027 requires the product to be treated as newly placed on the market.
Are open-source products exempt?
Partially. Free and open-source software developed and supplied outside a commercial activity sits outside the CRA's scope. Once an organisation commercially distributes, monetises or provides paid support for open-source software, though, it's likely to be treated as a manufacturer and subject to the full obligations, with a lighter regime available for open-source stewards who contribute without placing products on the market under their own name.
What happens if a UK manufacturer hasn’t complied by December 2027?
Products placed on the EU market for the first time after 11 December 2027 without CE marking and a completed conformity assessment remain barred from EU sale. Market surveillance authorities can require withdrawal or recall of non-compliant products and impose fines of up to €15 million or 2.5% of worldwide annual turnover. The Article 14 reporting obligations already apply, though, so non-compliance there is actionable today, well ahead of the 2027 deadline.
Does the CRA overlap with GDPR, NIS2 or DORA?
Yes, and the overlaps are intentional. Where GDPR governs the processing of personal data, the CRA governs the security of the product handling that data; where NIS2 governs operators of essential services, the CRA governs the products those services use; and where DORA imposes ICT risk management on financial entities, the CRA applies to the software and hardware components in their ICT supply chains. For organisations subject to more than one regime, a single product can need compliance mapping against several frameworks at once.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
Esavian House 181A High Holborn, London, WC1V 7QX, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
