EU Cyber Resilience Act · updated 2026-09-23
The Cyber Resilience Act, explained from the text.
Short guides for people who ship software or devices to the EU. Every claim cites the article or annex it comes from; nothing here is paraphrased from vendor blogs.
- Does the EU Cyber Resilience Act apply to SaaS?
Mostly no: standalone cloud services are outside the CRA and fall under NIS2. But hybrid products with a shipped client component are in. The exact test, with the clauses. - CRA SBOM requirements: what the regulation actually demands
The Cyber Resilience Act makes a software bill of materials mandatory. What it must contain, the format question the EU has not settled, who gets to see it, and where it goes in your technical file. - Article 14 of the Cyber Resilience Act: the 24-hour reporting duty, explained
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and their CSIRT within 24 hours. What triggers it, the 24/72/14 clock, and who is exempt from what. - Cyber Resilience Act deadlines: 11 September 2026 and 11 December 2027
The CRA has two application dates that do very different things. Which obligations start when, what is grandfathered, the five-year support period, and the fines behind each date.
Two free tools that apply this to your case: the 2-minute applicability check (does the CRA apply to you, with the clauses) and the SBOM generator (CycloneDX + SPDX from your manifest, signed). No signup for either.
Sources, primary only: Regulation (EU) 2024/2847 — EUR-Lex · European Commission — CRA summary · European Commission — CRA reporting · ENISA — Single Reporting Platform. Not legal advice; the regulation text controls.
← All explainers