EU Cyber Resilience Act: Everything Software Companies Need to Know Before 2027

The European Union's Cyber Resilience Act entered into force in December 2024, establishing mandatory cybersecurity requirements for virtually any product containing software components sold in the EU market. This is not a sector-specific regulation like the FDA's medical device guidance or DORA for financial entities — it is a horizontal requirement that applies to consumer electronics, industrial equipment, enterprise software, IoT devices, and commercial applications alike.

Scope: What Products Are Covered

The CRA applies to "products with digital elements" — a broad category that covers any product whose intended purpose includes data processing, storage, or transmission. This includes: IoT devices (smart home, industrial sensors, wearables), operating systems and general purpose software, browsers and communication applications, virtual private networks, network and security devices, smart meters, connected vehicles components, and nearly any other connected hardware or software. The regulation explicitly exempts open source software developed without commercial intent in some circumstances, though commercially-distributed open source is generally covered.

Key Technical Requirements

The CRA imposes several technical obligations that directly require SBOM capabilities. Manufacturers must: maintain a Software Bill of Materials for all software components; report actively exploited vulnerabilities to ENISA (European Union Agency for Cybersecurity) within 24 hours of learning of the exploitation; provide security updates and patches for the product's expected lifetime (at minimum 5 years unless the product's typical lifetime is shorter); ensure the product is delivered with a secure default configuration; and ensure all components sourced from third parties maintain adequate security levels.

Conformity Assessment and CE Marking

The CRA introduces a cybersecurity conformity assessment framework analogous to the CE marking system for product safety. Higher-risk products (categorized as "important" or "critical" — including security software, industrial control systems, and network products) require third-party conformity assessment. Most general-purpose software can self-assess. Compliant products may affix the CE mark for cybersecurity, and non-compliant products cannot be sold in the EU market.

The Timeline and Implementation Strategy

The CRA entered into force December 2024. Vulnerability reporting obligations begin in September 2026. Full product compliance is required by December 2027. This three-year implementation window sounds generous, but building the infrastructure required for compliance — SBOM programs, vulnerability disclosure processes, security update pipelines, conformity documentation — typically takes 18-24 months for organizations starting from scratch. Companies that wait until 2026 to begin will face significant pressure.

Geographic Scope: Who Must Comply

The CRA applies to any manufacturer or importer placing products on the EU market — regardless of where the manufacturer is headquartered. U.S., Asian, and other non-EU companies that sell products in Europe are subject to the same requirements as European manufacturers. This makes CRA compliance a global concern for any company with material EU revenue.

// Recommended Tool

Prepare for EU CRA Compliance with Fossity

Fossity — Fossity gives you the SBOM generation, vulnerability monitoring, and compliance documentation capabilities required by the EU Cyber Resilience Act. Start building your CRA compliance infrastructure now — before the 2026 and 2027 deadlines arrive. Our team has helped organizations across Europe and globally prepare for the CRA requirements.

Visit Fossity.com →
// Author: Esteban C.