Regulation (EU) 2024/2847 / Reporting from 11 Sep 2026

Cyber Resilience Act Readiness for Software and Device Makers

Product classification, Annex I gap analysis, SBOM, technical file and the 24-hour reporting playbook, delivered by people who test software for a living. Then a named PSIRT seat so the reporting duty has an owner. New to the law? Start with our plain-language guide to the CRA regulation.

Gap assessment EUR 8,900. Readiness from EUR 26,000. PSIRT seat EUR 2,300 per month. Fixed.

Every product classified in writingReporting drilled before the deadlineSBOM built into your pipeline
Cyber Resilience Act readiness service for software, firmware and connected device manufacturers

Why Manufacturers Are Starting Now

The reporting clock starts before the rest of the law

From 11 September 2026 every manufacturer must report an actively exploited vulnerability to ENISA within 24 hours, with a 72-hour notification and a 14-day final report. That obligation arrives fifteen months before the essential requirements, and it hits companies that have not started any conformity work.

Nobody can tell you which class your product is in

Default products self-assess. Important class I products self-assess only if harmonised standards exist, and none are cited yet. Class II needs a notified body, and as of June 2026 none has been designated. You need a route for both outcomes, decided now.

Security debt becomes strict liability

The revised Product Liability Directive applies to products placed on the market from 9 December 2026. Software is a product, a missing security update is a defect, and CRA non-conformity is prima facie evidence of one. The SBOM and the update policy stop being paperwork and become the defence.

Cyber Resilience Act dates: 11 June 2026, 11 September 2026, 9 December 2026 and 11 December 2027
Cyber Resilience Act fines of up to EUR 15 million or 2.5 percent of worldwide turnover

What the CRA Requires of a Product

Annex I sets the security properties the product must have and the vulnerability handling process the manufacturer must run. Annex II sets what users must be told. Annex VII sets the technical documentation. Together they are a security programme for the product, not a certificate, and they apply for as long as the product is supported.

Annex I security requirements
Secure by default, no known exploitable vulnerabilities at release, access control, encryption, minimised attack surface
Vulnerability handling
Identification, remediation, testing and free security updates for the support period, at least five years
SBOM
A software bill of materials of top-level dependencies for every product version, in the technical documentation
Technical file and conformity
Annex VII documentation, risk assessment, EU declaration of conformity and CE marking route
Article 14 reporting
Playbook, decision authority, ENISA Single Reporting Platform account and drills against the 24-hour clock
Disclosure and point of contact
Coordinated vulnerability disclosure policy and the single point of contact users and researchers can reach
Annex I essential cybersecurity requirements of the Cyber Resilience Act
Cyber Resilience Act vulnerability handling process including SBOM and coordinated disclosure
Cyber Resilience Act Article 14 reporting clock: 24 hours, 72 hours, 14 days

The 24-Hour Clock Starts on 11 September 2026

Article 14 requires an early warning to the ENISA Single Reporting Platform within 24 hours of becoming aware of an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days. Severe incidents follow the same shape with a one-month final report. The platform routes the report to the CSIRT of the country where you have your main establishment.

Twenty-four hours is not enough time to decide who decides. The playbook we deliver names the person who classifies, the person who files, the evidence they need and the wording of each report, and we drill it with your engineers against a real vulnerability from your own backlog.

If you do not want to staff that seat, we hold it: the single point of contact under Article 13(17), the ENISA account and the on-call decision, on a fixed monthly fee.

Who the CRA Binds

SaaS vendors that ship agents, connectors, on-premise components or mobile apps alongside the cloud service
IoT, embedded and industrial device makers, including firmware and the companion app
Software vendors selling downloadable or on-premise products into the EU, wherever they are based
Companies building commercial products on open-source components that now need an SBOM and a support commitment
Importers and distributors who must verify the manufacturer did the work before placing product on the EU market
Cyber Resilience Act product classes and the conformity assessment route for each

Compared With the Usual Offer

Atlant SecurityTypical offer
Honesty about classesWe tell you when a notified body is unavoidable and plan for itA checklist that assumes self-assessment for everything
EvidenceFindings from the code, pipeline and a penetration testA policy pack with the word CRA inserted
ReportingThe 24-hour clock drilled before September 2026, decision rights agreedA template in a folder
After the projectA named single point of contact and PSIRT seat on a monthly feeConsultant gone, reporting duty unowned
PricingPublished, fixed, per product familyQuoted after the free consultation

How CRA Readiness Works

1

Scope and classify

Every product with digital elements listed, placed into default, important class I or II, or critical, with the conformity route and the notified-body question answered for each.

2

Gap analysis

Annex I requirements and Annex II information duties assessed against the product and the development process, with evidence from the code, the build pipeline and a security test, not from a questionnaire.

3

Remediation and documentation

SBOM generation in the build, secure update mechanism, coordinated disclosure policy, support period statement, risk assessment and the technical file assembled in the Annex VII structure.

4

Reporting readiness and hand-off

ENISA platform account, the 24-hour playbook drilled with your engineers, then either your own PSIRT runs it or we hold the single point of contact seat for you.

The four step Cyber Resilience Act readiness process

Pricing

Fixed prices per product family, scoped in writing before we start. Notified body fees, where a class II product needs one, are charged by the body and are separate.

Gap Assessment and Reporting Playbook

Three weeks. Answers the classification question and makes you ready for 11 September 2026.

EUR 8,900fixed
  • Product inventory and written classification
  • Annex I and II gap report, graded
  • Article 14 reporting playbook and decision rights
  • ENISA Single Reporting Platform onboarding
  • One reporting drill with your engineers
Book Classification Call
Most common

Full CRA Readiness

One product family, from scoping to the technical file and declaration of conformity.

From EUR 26,000per product family
  • Everything in the gap assessment
  • Security test of the product and its update mechanism
  • SBOM generated in the build pipeline
  • Coordinated disclosure policy and support statement
  • Annex VII technical file and declaration of conformity
  • Notified body preparation where required
Book Classification Call

PSIRT and Single Point of Contact Seat

The reporting duty, owned. 12-month term, quarterly exit.

EUR 2,300per month
  • Named single point of contact under Article 13(17)
  • Vulnerability triage and the 24-hour classification decision
  • ENISA reports drafted and filed
  • Disclosure handling with researchers and customers
  • Quarterly vulnerability handling report to management
Book Classification Call

Know Your Class Before the Clock Starts

A free classification call tells you which of your products are in scope, which class they fall into and what 11 September 2026 means for you. Thirty minutes, no slides.

Book the Classification Call

Schedule Your Free Classification Call

Cyber Resilience Act FAQ

What is the Cyber Resilience Act and who does it apply to?
Regulation (EU) 2024/2847 sets cybersecurity requirements for products with digital elements placed on the EU market: hardware and software, including firmware, mobile and desktop applications and their remote data processing components. It binds manufacturers wherever they are based, and importers and distributors in the EU. Products already on the market before 11 December 2027 are only caught by the reporting obligations unless substantially modified.
Does the CRA apply to SaaS?
Mostly no. A pure cloud service is governed by NIS 2, not the CRA. The CRA does apply to anything you ship that runs on the customer side, such as agents, connectors, mobile apps, browser extensions and on-premise components, and to remote data processing that a product depends on to function. Most SaaS companies have at least one in-scope component and do not know it.
What are the dates?
The notified body chapter has applied since 11 June 2026. Reporting of actively exploited vulnerabilities and severe incidents starts 11 September 2026. Everything else, including the essential requirements, conformity assessment and CE marking, applies from 11 December 2027. The Radio Equipment Directive cybersecurity rules are repealed by the CRA on the same date.
What exactly must be reported, and where?
Any actively exploited vulnerability in your product and any severe incident affecting its security. An early warning within 24 hours, a notification within 72 hours with impact and mitigation, and a final report within 14 days for vulnerabilities or one month for incidents, all through the ENISA Single Reporting Platform, which routes to the national CSIRT. You need a registered account and a person who can make the classification decision within hours.
Which products need a notified body?
Important class II products, such as firewalls, hypervisors, tamper-resistant microprocessors and industrial control components, always do. Important class I products, such as password managers, VPNs, routers, operating systems and smart home devices, may self-assess only if they apply harmonised standards in full, and no harmonised standard has been cited yet. Default products, which is most business software, self-assess under Module A. We classify every product in writing during scoping.
What does the SBOM have to contain?
A machine-readable software bill of materials covering at least the top-level dependencies of each product version, kept in the technical documentation and made available to market surveillance authorities on request. We generate it in the build pipeline so it stays current, rather than producing a one-off document.
What are the fines?
Up to EUR 15 million or 2.5 percent of worldwide annual turnover for breaching the essential requirements or the vulnerability handling obligations, up to EUR 10 million or 2 percent for other obligations, and up to EUR 5 million or 1 percent for supplying incorrect information. Products can also be withdrawn from the market.
Can Atlant Security certify our product?
No. Conformity is declared by the manufacturer for default and class I products, and assessed by a notified body for class II and critical products. We do the readiness work, assemble the technical file, run the security testing and the reporting drills, and hold the single point of contact seat afterwards. Where a notified body is needed we prepare you for it and help you choose one once they are designated.
How much does it cost and how long does it take?
The gap assessment and reporting playbook is EUR 8,900 fixed and takes three weeks; it answers the classification question and gets you ready for 11 September 2026. Full readiness for one product family starts at EUR 26,000 and typically runs three to five months, depending on remediation. The PSIRT and single point of contact seat is EUR 2,300 per month on a 12-month term with quarterly exit.

Related Services