Solutions / Cyber Resilience Act

Build and prove CRA compliance — for your products and your suppliers.

The Cyber Resilience Act makes product security a condition of selling in the EU. ZeroRisk assesses your own CRA readiness, drafts the controls and policies you are missing, and continuously checks that the suppliers inside your products meet the same bar.

Book a demo Get the free gap report

What the CRA is

Regulation (EU) 2024/2847 — the Cyber Resilience Act — requires hardware and software sold in the EU to be secure by design, supported with free security updates through a defined support period, and backed by real vulnerability handling. Reporting obligations apply from 11 September 2026; the full requirements from 11 December 2027. For the complete picture, read what the Cyber Resilience Act is — this page covers how you comply.

Who needs to comply

The CRA binds the whole supply chain of a product with digital elements, with the heaviest duties on whoever brands the product.

Software manufacturers

Apps, platforms sold as products, developer tools, commercial libraries — secure development, documentation and vulnerability handling fall on you.

Hardware and connected device makers

Routers, sensors, wearables, industrial devices — the device, its firmware and its companion services are one product under the CRA.

Importers

You may only place compliant products on the EU market — and must verify the manufacturer has done its part before you do.

Distributors

Due care before selling: CE marking present, documentation available, and a duty to act when a product turns out non-conforming.

Open-source stewards

Foundations and non-profits supporting open-source components get a lighter, tailored regime — but a regime nonetheless.

What the CRA requires

Seven areas of obligation, running from design to end of support.

1

Secure design and product properties

Security by design and by default, across the product's lifecycle.

2

Vulnerability handling

Identify, remediate and disclose vulnerabilities for the whole support period.

3

Incident and vulnerability reporting

Actively exploited vulnerabilities and severe incidents, reported on a 24-hour clock from 11 September 2026.

4

User information and instructions

Clear security information, intended use and support commitments for the buyer.

5

Conformity and CE marking

Assessment matched to product class, technical documentation, and the mark that opens the market.

6

Risk assessment and supply chain

A documented cybersecurity risk assessment covering the product and the components inside it.

7

Support period and updates

Free security updates through the support period — at least five years for most products.

The deadlines

11 September 2026

Reporting obligations apply: actively exploited vulnerabilities and severe incidents must be reported — early warning within 24 hours. See what changes on 11 September 2026.

11 December 2027

The main obligations apply: essential requirements, conformity assessment and CE marking. Products that cannot show conformity stop being placeable on the EU market.

Proving supplier CRA compliance

Your product is only as compliant as the components and services inside it. ZeroRisk continuously monitors your suppliers against the CRA and the frameworks behind it — evidence collected, clause by clause, re-checked every 24 hours — so when a market surveillance authority asks how you assure your supply chain, the answer is a report, not a scramble. The vendor library covers 10,000+ pre-monitored vendors.

Assessing your own CRA readiness

The agent maps the CRA's requirements to your organization, pre-fills the assessment from what it can already see, drafts the controls and policies you are missing, and hands you sign-off rather than homework. Every verdict is evidence-backed and signed by a named person — the audit trail authorities expect.

What authorities ask for

Market surveillance runs on records: the risk assessment for the product, the technical documentation, proof of vulnerability handling and update delivery, and the reports filed when something went wrong. ZeroRisk keeps those as living records with named sign-offs — exportable the day someone asks, current as of that day. Transparent pricing, no per-seat licenses.

See where you stand on the CRA — in 10 minutes

The free gap report maps your current state against the Cyber Resilience Act and the other frameworks that apply to you.

Get the free gap report Book a demo