Skip to content

    01 / EU Cyber Resilience Act

    All Services

    EU Cyber Resilience Act

    Product Security and SBOM Readiness

    The Cyber Resilience Act, Regulation (EU) 2024/2847, is an EU regulation setting binding cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on December 10, 2024. Its Article 14 duties to report actively exploited vulnerabilities and severe incidents apply from September 11, 2026, and its main obligations, including the Annex I essential requirements and conformity assessment, apply from December 11, 2027.

    The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on December 10, 2024 and puts binding cybersecurity requirements on products with digital elements sold into the EU. It applies on a staged timeline: the rules for notifying conformity assessment bodies in Chapter IV from June 11, 2026, the Article 14 reporting duties from September 11, 2026, and the main obligations from December 11, 2027.

    The scope is broader than most teams assume. A product with digital elements is any software or hardware product, plus its remote data processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Annex I sets essential requirements in two parts: product properties, including being placed on the market with no known exploitable vulnerabilities and a secure by default configuration, and vulnerability handling, which is where the CRA makes a machine-readable software bill of materials a legal requirement rather than a customer preference. Article 13(8) sets a support period of at least five years unless the product is expected to be in use for less.

    Top Floor builds the product security program that stands behind those requirements: scoping which of your products are in scope and which fall into the Annex III important classes, the vulnerability handling process Annex I Part II describes, SBOM generation and maintenance, a coordinated vulnerability disclosure policy, and the 24-hour reporting track Article 14 demands. We do not act as a notified body and we do not issue conformity assessments or CE marks. We get the technical file, the process, and the evidence into a state where the conformity route you choose is defensible.

    Frameworks: EU CRA (Regulation (EU) 2024/2847), IEC 62443, ISO 27001, NIST SSDF (SP 800-218), NIS2

    Who This Is For

    • Hardware and software manufacturers placing products with digital elements on the EU market, including companies headquartered outside Europe.
    • Connected device and IoT companies that have never held a product security program separate from their IT security program.
    • Software vendors whose products fall into an Annex III important class, such as identity and access management, VPNs, network management, SIEM, or operating systems.
    • Engineering organizations that need SBOM generation and maintenance wired into a build pipeline rather than produced by hand once a year.
    • Product and security teams that must be able to file an Article 14 early warning within 24 hours from September 11, 2026, including for products already on the market.

    What You Get

    • CRA scoping assessment: which products are in scope, which fall under Annex III class I or class II, and which are excluded by sectoral legislation
    • Gap assessment against Annex I Part I product requirements and Annex I Part II vulnerability handling requirements
    • Software bill of materials program: format selection (SPDX or CycloneDX), build pipeline integration, and the maintenance cadence
    • Coordinated vulnerability disclosure policy and the contact channel Annex I Part II requires
    • Article 14 reporting runbook covering the 24-hour early warning, the 72-hour notification, and the final report, mapped to the CSIRT coordinator and ENISA single reporting platform
    • Support period determination and the security update distribution process behind it
    • Technical documentation structure and conformity route analysis, including where a notified body becomes unavoidable
    • Product security testing program aligned to the vulnerability handling requirements
    • Alignment of the CRA reporting track with existing GDPR, NIS2, and customer notification workflows so one incident does not trigger three uncoordinated triages

    Frequently Asked Questions

    Strengthen Your EU Cyber Resilience Act Compliance with Penetration Testing

    Validate your security controls with real-world attack simulation. Our OSCP-certified practitioners conduct manual, methodology-driven testing across seven disciplines: network (internal and external), web application, API, cloud infrastructure, social engineering, wireless, and physical security assessments.

    Explore Penetration Testing

    Ready to Get Started?

    Schedule a free consultation to discuss your EU Cyber Resilience Act needs.

    Schedule a Consultation