🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
CRACR-CRA-01

Cyber Resilience Act Readiness: What Applies on 11 September 2026

EU Cyber Resilience Act readiness for software products. Product classification, Annex I gap analysis, SBOM guidance, CE marking route. Ahead of Sep 2026 deadline. €539.

Quick Answer

The EU Cyber Resilience Act entered into force on 10 December 2024. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours, with full notification at 72 hours and final reports at 14 days or 1 month. Main compliance obligations apply from 11 December 2027. Fines reach €15 million or 2.5% of global turnover. In scope: products with digital elements placed on the EU market, with exemptions for regulated sectors and genuinely non-commercial open source.

€539
Fixed price, VAT excluded
8 business daysSenior only
Product classification (default / important Class I or II / critical)
Annex I essential cybersecurity requirements gap analysis
Vulnerability handling process review and recommendations (Article 13)
SBOM setup guidance and CE marking readiness report
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-CRA-01

This Service Covers

CRAEU CRA Regulation 2024/2847 — Essential cybersecurity requirements, vulnerability handling, CE marking

What You Get

Complete CRA readiness assessment for one product with digital elements. Product classification (default / important class I or II / critical). Gap analysis against Annex I essential cybersecurity requirements: security-by-design, secure default configuration, vulnerability handling, security updates, data minimisation. Vulnerability handling process review (Article 13). SBOM setup guidance. CE marking readiness and conformity assessment route recommendation.

Who Needs This

  • Software vendors selling products in the EU
  • Hardware/IoT manufacturers with connected devices
  • Open-source product maintainers monetised commercially in the EU
  • Companies whose products fall into 'important' or 'critical' classes
  • Teams that want to be ahead of competitors on the September 2026 deadline

How It Works

  1. 1
    Product Scoping

    We classify your product and identify applicable CRA requirements

  2. 2
    Annex I Gap Analysis

    We assess current security practices against CRA essential requirements

  3. 3
    Vulnerability Process Review

    We review your vulnerability disclosure and patching processes

  4. 4
    Report & Roadmap

    CRA readiness report with CE marking route in 8 days

The 11 September 2026 Deadline: What Exactly Applies

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. It phases in over several years, and 11 September 2026 is the date a specific, narrow obligation goes live — not the full regulation. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements, under CRA Article 14. Nothing else in the CRA becomes enforceable on that date.

The rest of the timeline runs on its own schedule: Chapter IV notified-body provisions started applying on 11 June 2026, the main essential-requirements obligations become fully enforceable on 11 December 2027, and EU type-examination certificates issued before the CRA expire on 11 June 2028 at the latest. Treat 11 September 2026 as a reporting-readiness deadline, not a certification deadline.

Is Your Product in Scope?

  • Your product is software or hardware with a direct or indirect logical or physical data connection to a device or network.
  • It is placed on the EU market — including free products distributed commercially.
  • If you sell SaaS: the CRA applies where your service is a *remote data processing solution* that is integral to a product with digital elements — not to every standalone cloud service. A self-contained SaaS product with no dependent hardware or software component is more commonly in scope under NIS2 instead. This distinction matters and is easy to get wrong — confirm your specific case rather than assuming either way.
  • It is not a medical device, in-vehicle/aviation product, or another product already regulated under sector-specific EU legislation with equivalent cybersecurity requirements — exempt from the CRA, but not from its own sectoral rules.
  • It is not open-source software maintained on a genuinely non-commercial basis — commercially monetised open source, including dual-licensing and paid-support models, is in scope as an 'open-source software steward.'
  • If you can't confidently tick every line above, don't assume you're exempt — CRA scope determinations are frequently wrong in both directions.

Reporting Timeline: 24 Hours, 72 Hours, 14 Days

These are the Article 14 timelines that actually apply from 11 September 2026. There is no fixed "testing frequency" mandated by the CRA — the obligation is to detect, assess and report, not to run a test on a specific schedule.

DeadlineWhat must be submittedTrigger
24 hoursEarly warning notification to your national CSIRT / ENISAFrom the moment you become aware of an actively exploited vulnerability or a severe incident
72 hoursFull notification, including assessment and any corrective or mitigating measures already takenSame trigger as above
14 daysFinal report, submitted after the vulnerability is remediatedVulnerability-related notifications
1 monthFinal report on the incidentSevere-incident notifications

What You Cannot Do Yet

Some of the infrastructure the CRA assumes will exist is not fully in place yet. As of mid-2026: the harmonised standards that would give manufacturers a presumption of conformity have not been published in the Official Journal; no conformity assessment body has been notified under the CRA in the NANDO database; and ENISA's single reporting platform is targeted to be operational by 11 September 2026 itself, which is an uncomfortably tight timeline.

Practical consequence: build your internal vulnerability-handling process now, but understand that third-party conformity assessment for critical-class products is not yet operationally available, because the bodies that would perform it don't exist yet. Anyone offering a finished, notified-body-certified CRA compliance package today is getting ahead of the regulation.

Practical Preparation Checklist

  • Inventory every product with digital elements you place on the EU market, including free tiers and SaaS.
  • Determine your role for each product: manufacturer, importer, or distributor — obligations differ.
  • Classify each product: default, important (Class I or II), or critical, under Annex III.
  • Build or acquire a Software Bill of Materials (SBOM) for each product.
  • Document your vulnerability-handling process end-to-end: intake, triage, fix, disclosure.
  • Identify who in your organisation makes the 24-hour reporting call, and write it down.
  • Draft notification templates now — the 24/72-hour clock shouldn't start with a blank page.
  • Review supplier and component contracts for vulnerability-disclosure and patching commitments.
  • Run a vulnerability assessment or penetration test to establish your current baseline — you can't report what you haven't looked for.

How Security Testing Fits CRA Preparation

The CRA does not say the words "penetration test." But Annex I, Part II, point 3 requires manufacturers to apply effective and regular tests and reviews of the security of the product with digital elements — regular security testing is an explicit obligation here, not an inference. The regulation doesn't prescribe a specific method or frequency, so a penetration test or a vulnerability assessment both qualify; what matters is that the testing is regular, evidenced, and documented.

Separately, the CRA also says you must be able to detect and report actively exploited vulnerabilities within 24 hours of becoming aware of them. Different obligation, same practical requirement: you need to know your product's vulnerabilities before an attacker — or a regulator — finds them for you.

The chain is short: from 11 September 2026 you must report actively exploited vulnerabilities within 24 hours → to report one, you first have to know it exists and that it's being exploited → knowing that requires an up-to-date component inventory (SBOM), a working vulnerability-handling process, and a recent, independent look at where your product's weaknesses actually are → a company that has never tested its own product will reach September 2026 with a legal obligation and no operational way to fulfil it.

A fixed-price Vulnerability Assessment is the minimum viable starting point: a dated, evidenced baseline you can point to, and the fastest way to close the gap between "we have an obligation" and "we have a process."

Penalties

ViolationMaximum fine
Non-compliance with essential cybersecurity requirements or manufacturer obligations (Annex I, Articles 13–14)€15,000,000 or 2.5% of worldwide annual turnover, whichever is higher
Non-compliance with other CRA obligations€10,000,000 or 2% of worldwide annual turnover, whichever is higher
Supplying incorrect, incomplete or misleading information to a notified body or market surveillance authority€5,000,000 or 1% of worldwide annual turnover, whichever is higher

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup (€449) to incident response (€359). No surprises.

Browse Fix Services

Ready to Start?

€539 · 8 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Ready to implement? Browse individual fix services

Learn more

Frequently Asked Questions

Does the CRA apply to SaaS?+
It depends. The CRA applies to SaaS where the service qualifies as a 'remote data processing solution' that is integral to a product with digital elements placed on the EU market — for example, a companion cloud backend for a connected device. A self-contained SaaS product with no dependent hardware or software component is more commonly regulated under NIS2 instead, not the CRA. Don't assume either way — this is one of the most frequently misjudged scope questions and worth confirming for your specific product.
What is a 'product with digital elements'?+
Any software or hardware product whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network — a broad definition covering most commercial software, connected hardware and IoT devices.
What must be reported from 11 September 2026?+
Actively exploited vulnerabilities and severe incidents affecting products with digital elements, under Article 14 — within 24 hours (early warning), 72 hours (full notification), and 14 days or 1 month (final report, depending on the trigger).
Who do I report to?+
Your national CSIRT (Computer Security Incident Response Team) and ENISA, via the single reporting platform ENISA is required to have operational by 11 September 2026.
Do I need an SBOM by September 2026?+
The CRA doesn't set a hard SBOM deadline tied to 11 September 2026, but Annex I, Part II, point 1 requires manufacturers to identify and document components and vulnerabilities in the product, including by drawing up a Software Bill of Materials — and you can't meet the 24-hour reporting obligation without knowing what components your product contains.
Are there notified bodies for the CRA yet?+
Not as of mid-2026. No conformity assessment body has been notified under the CRA in the NANDO database, which means third-party conformity assessment for critical-class products isn't yet operationally available.
Does the CRA require penetration testing?+
Not by name. But Annex I, Part II, point 3 requires manufacturers to apply effective and regular tests and reviews of the security of the product with digital elements — regular security testing is an explicit obligation, not an inference. The regulation does not prescribe a method or a frequency, so a penetration test or a vulnerability assessment both qualify; what matters is that the testing is regular, evidenced and documented.
How does the CRA relate to NIS2?+
NIS2 regulates operators of essential and important services; the CRA regulates products with digital elements placed on the market. The same company can be in scope for both — as an operator under NIS2 and as a manufacturer under the CRA — for different reasons.
What are the maximum fines?+
Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for non-compliance with essential requirements and manufacturer obligations. Lower caps apply to other violations and to providing incorrect information to authorities.

Service page last reviewed 4 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment