The Cyber Resilience Act (CRA) introduces cybersecurity obligations for products with digital elements sold in the EU, including vulnerability reporting duties for manufacturers. The first CRA reporting obligations apply from September 11, 2026, requiring processes to identify, assess, document, and report actively exploited vulnerabilities and severe incidents affecting product security.
This page is being expanded with detailed guidance on CRA implementation timelines and reporting obligations, and how RED cybersecurity readiness under EN 18031 builds the technical backbone for CRA compliance. In the meantime, Cyberexpert can scope your specific product against EN 18031 in about an hour, for free.
Start free assessment