The Cyber Resilience Act makes product security a condition of selling in the EU. ZeroRisk assesses your own CRA readiness, drafts the controls and policies you are missing, and continuously checks that the suppliers inside your products meet the same bar.
Regulation (EU) 2024/2847 — the Cyber Resilience Act — requires hardware and software sold in the EU to be secure by design, supported with free security updates through a defined support period, and backed by real vulnerability handling. Reporting obligations apply from 11 September 2026; the full requirements from 11 December 2027. For the complete picture, read what the Cyber Resilience Act is — this page covers how you comply.
The CRA binds the whole supply chain of a product with digital elements, with the heaviest duties on whoever brands the product.
Apps, platforms sold as products, developer tools, commercial libraries — secure development, documentation and vulnerability handling fall on you.
Routers, sensors, wearables, industrial devices — the device, its firmware and its companion services are one product under the CRA.
You may only place compliant products on the EU market — and must verify the manufacturer has done its part before you do.
Due care before selling: CE marking present, documentation available, and a duty to act when a product turns out non-conforming.
Foundations and non-profits supporting open-source components get a lighter, tailored regime — but a regime nonetheless.
Seven areas of obligation, running from design to end of support.
Security by design and by default, across the product's lifecycle.
Identify, remediate and disclose vulnerabilities for the whole support period.
Actively exploited vulnerabilities and severe incidents, reported on a 24-hour clock from 11 September 2026.
Clear security information, intended use and support commitments for the buyer.
Assessment matched to product class, technical documentation, and the mark that opens the market.
A documented cybersecurity risk assessment covering the product and the components inside it.
Free security updates through the support period — at least five years for most products.
Reporting obligations apply: actively exploited vulnerabilities and severe incidents must be reported — early warning within 24 hours. See what changes on 11 September 2026.
The main obligations apply: essential requirements, conformity assessment and CE marking. Products that cannot show conformity stop being placeable on the EU market.
Your product is only as compliant as the components and services inside it. ZeroRisk continuously monitors your suppliers against the CRA and the frameworks behind it — evidence collected, clause by clause, re-checked every 24 hours — so when a market surveillance authority asks how you assure your supply chain, the answer is a report, not a scramble. The vendor library covers 10,000+ pre-monitored vendors.
The agent maps the CRA's requirements to your organization, pre-fills the assessment from what it can already see, drafts the controls and policies you are missing, and hands you sign-off rather than homework. Every verdict is evidence-backed and signed by a named person — the audit trail authorities expect.
Market surveillance runs on records: the risk assessment for the product, the technical documentation, proof of vulnerability handling and update delivery, and the reports filed when something went wrong. ZeroRisk keeps those as living records with named sign-offs — exportable the day someone asks, current as of that day. Transparent pricing, no per-seat licenses.
The free gap report maps your current state against the Cyber Resilience Act and the other frameworks that apply to you.