Appearance
Cyber Resilience Act (CRA)
The Cyber Resilience Act (the CRA) is Regulation (EU) 2024/2847, the European Union's horizontal cybersecurity law for products with digital elements made available on the Union market. It reaches hardware and software products alike: if a product's intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, the CRA applies unless an Article 2 exclusion covers it. Manufacturers must build products to the essential cybersecurity requirements of Annex I, handle vulnerabilities throughout a declared support period, document conformity, affix the CE marking, and, from 11 September 2026, report actively exploited vulnerabilities and severe incidents through the EU single reporting platform.
Modulos positions the framework for AI-enabled products with digital elements: an AI-enabled product is in scope where it is made available on the EU market, the data-connection test is met, and no Article 2 exclusion applies, and the CRA's product-security duties run alongside the EU AI Act's requirements, with Article 12 of the CRA connecting the two conformity regimes for high-risk AI systems. Modulos models the Regulation as two paired templates, MFF-26 for per-product execution and OFF-26 for the organization and its economic-operator roles. This page orients you on what the Regulation covers, how the templates are structured, and where to go next.
Quick decision — is this framework for you?
- You make hardware or software products with digital elements available on the EU market → this is your framework. Start with Scope, classification, and conformity to record the applicability decision and product boundary.
- You build AI-enabled products → AI features do not take a product out of CRA scope; they are part of it. The cybersecurity risk assessment determines how each Annex I property applies to the AI-enabled parts, and Article 12 governs the interplay with the EU AI Act's high-risk regime. See Scope, classification, and conformity.
- You already run ISO 27001, NIS2, or DORA programs in Modulos → most of the CRA control estate is shared with those frameworks. Your existing work counts; what is new is the product-security layer. See Operationalizing the CRA in Modulos.
- You import or distribute products, act as an authorized representative, or steward open-source software → the organization framework carries a conditional requirement for each role that activates only where you hold it. See Reporting and economic operators.
- You are waiting for a harmonized standard → none has been cited in the Official Journal yet, and compliance work must anchor directly to Annex I in the meantime. The templates do exactly that, with watch-markers for the pending standards and implementing acts.
TL;DR
- The CRA (Regulation (EU) 2024/2847) sets horizontal cybersecurity requirements for products with digital elements on the EU market: secure-by-design duties (Annex I, Part I), vulnerability-handling processes (Annex I, Part II), a support period of at least five years in the standard case, user information (Annex II), technical documentation (Annex VII), conformity assessment, and CE marking.
- Dates: in force since 10 December 2024. The Article 14 reporting duties apply from 11 September 2026 to all in-scope products, including products already on the market. The remaining manufacturer duties apply from 11 December 2027; products placed on the market before that date are caught only on substantial modification (Article 14 excepted).
- Roles: duties attach to the manufacturer, and conditionally to authorized representatives, importers, distributors, deemed manufacturers (Articles 21 and 22), and open-source software stewards (Article 24).
- No harmonized standard is cited in the Official Journal yet — the Modulos requirements anchor directly to the Regulation's text rather than to any standard.
- Modulos models the CRA as two templates with the Regulation label (templates 1.0.28):
MFF-26(AI application, 26 requirements,MRF-450–MRF-475) andOFF-26(organization, 15 requirements,ORF-468–ORF-482), mapped to 109 distinct controls (22 new, 87 reused). Three tag categories — CRA Role, CRA Product Category, CRA Phase — support scoping and navigation.
Primary source
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), OJ L, 20 November 2024: EUR-Lex. Always verify claims against the current published text.
Key facts
Legislator
European Union
Instrument
Regulation (EU) 2024/2847 (Regulation label in Modulos)
In force
10 December 2024
Applies
Article 14 reporting from 11 September 2026; general application 11 December 2027
Covers
Products with digital elements: hardware and software with a data connection to a device or network
Modulos templates
MFF-26 (application) + OFF-26 (organization): 41 requirements, 109 controls
What the Regulation covers
The CRA's obligations cluster around the product on one side and the actors in the supply chain on the other. The table groups them the way the Modulos templates do.
| CRA provisions | What they hold |
|---|---|
| Articles 2–3 — Scope and definitions | Which products are in scope (the data-connection test), the sectoral exclusions, and the defined terms the rest of the Regulation depends on: product with digital elements, remote data processing, placing on the market, making available on the market, substantial modification, support period. |
| Articles 6–8, 12, 32 — Classification and conformity routes | The default category and the important (Annex III, class I and II) and critical (Annex IV) categories, the conformity assessment procedures each one allows, and the Article 12 interplay with the EU AI Act for high-risk AI systems. |
| Article 13, Annex I Part I — Manufacturer duties and product security | The cybersecurity risk assessment, the secure-by-design outcome, and the thirteen product-security properties (points (2)(a) through (m)): no known exploitable vulnerabilities when made available on the market, secure defaults, security updates, access control, confidentiality, integrity, data minimization, availability, connected-service availability, attack-surface limitation, exploitation mitigation, security logging, and secure data removal. Each applies where applicable on the basis of the risk assessment. |
| Article 13, Annex I Part II — Vulnerability handling | The SBOM, coordinated vulnerability disclosure, regular testing, remediation without delay and free security updates during the support period, advisories, and public disclosure of fixed vulnerabilities. |
| Article 13, Annex II, Annex VII — Support period, information, documentation | The support-period determination (at least five years in the standard case), the end-date disclosure at purchase, the Annex II user information and instructions, and the Annex VII technical documentation kept for at least 10 years or the support period, whichever is longer. |
| Article 14 — Reporting | Notification of actively exploited vulnerabilities and severe incidents to the coordinator CSIRT and ENISA via the single reporting platform: 24-hour early warning, 72-hour notification, and a final report on each track. Applies from 11 September 2026. |
| Articles 18–24 — Economic operators | Authorized representatives, importers, distributors, deemed manufacturers (Articles 21 and 22), and the tailored duties of open-source software stewards (Article 24). |
| Articles 27–30, Annexes V–VI — Conformity and CE marking | The EU declaration of conformity, the simplified declaration, and the CE marking rules. |
| Articles 52–58 — Market surveillance | Corrective action, cooperation with market surveillance authorities, and the formal non-compliance procedures. |
How Modulos models it
Modulos splits the Regulation into per-product execution (MFF-26) and organization-level capabilities and roles (OFF-26). Both templates carry the Regulation label.
| Template | Project type | Holds | Requirements |
|---|---|---|---|
MFF-26 — Cyber Resilience Act | AI application | Scoping and product boundary, classification and conformity route, the cybersecurity risk assessment, the thirteen Annex I product-security properties, component and remote-solution assurance, support period, SBOM, testing, remediation and advisories, user information, technical documentation, declaration and CE marking, continuous conformity | 26 (MRF-450–MRF-475) |
OFF-26 — Cyber Resilience Act | Organization | Role and applicability governance, secure-product governance, support-period governance, component and SBOM operations, security-update operations, testing program, coordinated vulnerability disclosure, user communication, Article 14 reporting, corrective action and authority cooperation, records and traceability, and the conditional authorized-representative, importer, distributor, and open-source steward roles | 15 (ORF-468–ORF-482) |
One MFF-26 project assesses one AI-enabled product with digital elements; it does not model every non-AI product in scope. The organization framework's four role requirements are conditional: they activate only for the capacities the organization actually holds, and a documented non-applicability justification is a completed outcome, not a gap. The same rule runs through the thirteen Annex I properties on the application side: each applies where applicable on the basis of the documented cybersecurity risk assessment, and a linked justification of non-applicability satisfies the requirement.
The 41 requirements group into four coverage domains, each with its own topic page.
1. Scope, classification, and conformity
The applicability decision and product boundary including remote data processing and the deemed-manufacturer rules (MRF-450), product category and the conformity route with the Article 12 high-risk-AI interplay (MRF-451), technical documentation (MRF-473), the EU declaration of conformity and CE marking (MRF-474), and continuous conformity with corrective action (MRF-475).
→ Deep dive: Scope, classification, and conformity.
2. The risk assessment and the Annex I security properties
The Article 13 cybersecurity risk assessment that drives everything else (MRF-452), the risk-based security outcome (MRF-453), the thirteen Annex I, Part I product-security properties (MRF-454–MRF-466), and component and remote-solution assurance (MRF-467).
→ Deep dive: Risk assessment and Annex I.
3. Vulnerability handling and the support period
The support-period determination and disclosure (MRF-468), the SBOM and vulnerability record (MRF-469), security testing (MRF-470), remediation, update delivery, and advisories (MRF-471), and product identity, user information, and instructions (MRF-472).
→ Deep dive: Vulnerability handling and the support period.
4. Reporting and economic operators
Role and applicability governance (ORF-468), the manufacturer's repeatable capabilities (ORF-469–ORF-475), the Article 14 reporting duties with the 24-hour, 72-hour, and final-report ladders (ORF-476), post-market corrective action and authority cooperation (ORF-477), records and traceability (ORF-478), and the conditional authorized-representative, importer, distributor, and open-source steward roles (ORF-479–ORF-482).
→ Deep dive: Reporting and economic operators.
How Modulos operationalizes the CRA
The two templates are designed to run together: OFF-26 establishes the organization's roles, reporting readiness, and repeatable product-security capabilities once, and each MFF-26 project produces the per-product evidence that a given AI-enabled product meets the essential cybersecurity requirements.
MFF-26— Cyber Resilience Act — one AI-application project per in-scope product. 26 requirements (MRF-450–MRF-475), mapped to 71 distinct controls.OFF-26— Cyber Resilience Act — one organization project. 15 requirements (ORF-468–ORF-482), mapped to 38 distinct controls.
Across both templates that is 109 distinct controls: 87 reused and 22 new (MCF-670–MCF-683, OCF-372–OCF-379). The reuse is where the effort savings sit: the shared controls come chiefly from the ISO 27001, NIS2, and DORA estates, with further overlap into ISO 42001 and EN 18286. An organization with existing work on those frameworks already operates shared controls covering roughly a third of the CRA estate, and the Evidence attached to those controls counts here from day one; the 22 new controls carry the genuinely new product-security ground, from release-gating on known exploitable vulnerabilities to the two Article 14 reporting ladders.
Framework mapping
Four layers, one reusable column.
Frameworks
EU AI Act
ISO 42001
Requirements
Art. 9.1Risk management
Art. 10.2Data governance
6.1.1Risk assessment
Components
Risk identification
Impact analysis
Evidence
Risk register
Test results
Controls
The reusable column
One control satisfies many requirements across many frameworks, and groups the components and evidence beneath them.
Risk assessment process
Data validation checks
Edge from any layer card crosses into the Controls column — the same control may serve a regulatory article, a standards clause, a downstream component, and the evidence that closes it.
→ Full rollout: Operationalizing the CRA in Modulos: project structure, the requirement mapping tables, the 22 new controls, the reuse numbers, the tag categories, and the evidence model.
Where to go next
Scope, classification, and conformity
The applicability decision, product categories, conformity routes, Article 12, documentation, and CE marking — MRF-450, MRF-451, MRF-473–475
Risk assessment and Annex I
The cybersecurity risk assessment and the thirteen product-security properties — MRF-452–467
Vulnerability handling and the support period
SBOM, testing, remediation and advisories, the support period, and user information — MRF-468–472
Reporting and economic operators
Manufacturer capabilities, Article 14 reporting, and the conditional roles — ORF-468–482
Operationalizing in Modulos
The MFF-26 / OFF-26 rollout: mapping tables, new controls, reuse, and tags
Frequently asked questions about the Cyber Resilience Act
What is the EU Cyber Resilience Act?
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847, the European Union's horizontal cybersecurity law for products with digital elements made available on the Union market. It entered into force on 10 December 2024. It requires manufacturers to meet the essential cybersecurity requirements of Annex I (thirteen product-security properties plus vulnerability-handling processes), determine and disclose a support period, maintain technical documentation, complete a conformity assessment, affix the CE marking, and report actively exploited vulnerabilities and severe incidents. Most manufacturer duties apply from 11 December 2027; the Article 14 reporting duties apply earlier, from 11 September 2026.
Which products are in scope of the CRA?
The CRA applies to products with digital elements made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. That covers hardware and software products alike, including AI-enabled products, and remote data processing solutions that the manufacturer designs or has designed under its responsibility, and without which the product could not perform one of its functions, are treated as part of the product. Article 2 excludes products already covered by certain sectoral regimes (such as medical devices, civil aviation, and motor vehicles), and products developed exclusively for national security or defense purposes are outside scope. Most non-commercial open-source software also falls outside the CRA, because a product is caught only where it is made available on the market in the course of a commercial activity.
When does the Cyber Resilience Act apply?
The CRA entered into force on 10 December 2024 and applies in full from 11 December 2027. Two duties start earlier: the Article 14 reporting obligations (actively exploited vulnerabilities and severe incidents) apply from 11 September 2026, and the Chapter IV provisions on notifying conformity assessment bodies apply from 11 June 2026. Products placed on the market before 11 December 2027 are caught by the general requirements only if they are substantially modified after that date, but Article 14 reporting applies to them regardless.
How does the CRA interact with the EU AI Act for high-risk AI systems?
Article 12 of the CRA connects the two regimes at the conformity-assessment level. A product with digital elements that is also a high-risk AI system under the EU AI Act and that meets the CRA's essential cybersecurity requirements, with the EU declaration of conformity demonstrating it, is deemed to comply with the AI Act's cybersecurity requirement (Article 15 of that Regulation). Article 12(2) then applies the AI Act's Article 43 conformity assessment procedure to those products, and Article 12(3) derogates from that for certain important and critical products where the AI Act's internal-control procedure would otherwise apply. The Modulos framework records this interplay as part of the classification and conformity-route decision in MRF-451.
How does Modulos model the Cyber Resilience Act?
As two paired templates carrying the Regulation label (templates 1.0.28). MFF-26 assesses one AI-enabled product with digital elements across 26 requirements (MRF-450 through MRF-475): scoping and product boundary, classification and conformity route, the cybersecurity risk assessment, the thirteen Annex I product-security properties with risk-based applicability, vulnerability handling and SBOM, the support period, user information, technical documentation, and CE marking. OFF-26 covers the organization across 15 requirements (ORF-468 through ORF-482): manufacturer capabilities, Article 14 reporting, post-market corrective action, records, and the conditional roles of authorized representative, importer, distributor, and open-source software steward. Together the 41 requirements map to 109 distinct controls: 22 new CRA controls and 87 reused from the platform's existing estate. Three tag categories support navigation: CRA Role, CRA Product Category, and CRA Phase.
Is there a harmonized standard for the CRA?
Not yet. No harmonized standard for the Cyber Resilience Act has been cited in the Official Journal of the European Union, so there is currently no standards-based route to presumption of conformity. The Modulos requirements anchor directly to the Regulation's text, Annex I in particular, and carry regulatory watch-markers for the pending events: the citation of CRA harmonized standards and the Article 13(24) implementing act on SBOM formats. The Commission published non-binding practical guidance on CRA implementation (C(2026) 5252) on 27 July 2026.
What are the CRA reporting deadlines?
From 11 September 2026 a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident having an impact on the security of its product, notifies the CSIRT designated as coordinator and ENISA simultaneously through the EU single reporting platform. Each track has three stages: an early warning without undue delay and in any event within 24 hours of becoming aware, a notification within 72 hours, and a final report. Unless the relevant information has already been provided, the final report for an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure is available, and the final report for a severe incident within one month after the 72-hour notification. Reporting and economic operators walks through both ladders.
Source attribution
This page summarizes Regulation (EU) 2024/2847 (Cyber Resilience Act), published in the Official Journal of the European Union on 20 November 2024 (EUR-Lex). Requirement and control codes (MFF-26, OFF-26, MRF-, ORF-, MCF-, OCF-) are Modulos template identifiers, not references used by the Regulation.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. No harmonized standard has been cited in the Official Journal for the Cyber Resilience Act; statements about pending standards, guidance, and implementing acts describe open regulatory events, not settled positions. Always verify against the current published text and consult qualified advisers.