Articles tagged: EU CRA
6 articles on EU CRA from the Top Floor insights library.
2026-08-25
Do You Need a Notified Body Under the CRA?
Only if your product's core functionality is an important or critical category and, for class I, no harmonised standard covers the risks of that core functionality. The Commission's guidance turns both of those into tests you can run.
2026-08-25
How Long Does EU CRA Conformity Take?
About fifteen months to the main obligations, weeks to the reporting duties, and a conformity route whose duration nobody can quote yet, because the product-specific standards are still in approval and the notified body listing is still marked once available. What you control, what you do not, and the sequence that survives both.
2026-08-20
The EU CRA Reporting Clock: 24 Hours, 72 Hours, Then a Final Report
Article 14 obliges manufacturers to report actively exploited vulnerabilities and severe incidents on a 24-hour, 72-hour and final-report clock, from 11 September 2026. It is the first CRA obligation to bind, and it reaches products you shipped years ago and have not touched since.
2026-08-16
Does the EU Cyber Resilience Act Apply to Your Product?
If you place hardware or software on the EU market and it connects to anything, assume yes and work backwards. The scoping traps are remote data processing, the Annex III important classes, and products already on the market.
2026-08-16
What the EU Cyber Resilience Act Requires in an SBOM
Annex I Part II makes a machine-readable software bill of materials a legal requirement, with top-level dependencies as the floor. It is documentation you hold and produce on request, not a file you publish.
2026-08-16
Is Your Product Important Under the CRA? Annex III and the Conformity Routes
Most products self-assess. Annex III class I products self-assess only if they apply harmonized standards in full, class II and critical products cannot. Which list you land on decides your budget and your timeline.