The Cyber Resilience Act (CRA) sets cybersecurity requirements for **products with digital elements** placed on the EU market. "Products with digital elements" covers software, not only hardware.

Who is in scope?

The regulation does not require the manufacturer to be established in the EU. If the product enters the EU market, obligations are shared between manufacturer, importer and distributor. In practice: **a software manufacturer established outside the EU is directly in scope if it sells into the EU.**

This differs from DORA, where the obligation sits with the EU financial entity and reaches the supplier through the **contract**. Under the CRA the duty comes straight from the regulation.

Timeline — one duty already applies

The general application date is **11 December 2027**. There are two exceptions: Chapter IV on notified bodies applies from **11 June 2026**, and **Article 14 has applied since 11 September 2026**.

So the clock is already running for actively exploited vulnerabilities and severe incidents: 24 hours for the early warning, 72 hours for the notification, 14 days for the final report.

Are you out of scope?

The regulation does not apply to products covered by the medical device, in vitro diagnostic and motor vehicle regulations, to products certified under civil aviation rules, to marine equipment, to spare parts manufactured to the same specifications as the components they replace, or to products developed exclusively for national security or defence.

Regulation (EU) 2025/327 (European Health Data Space) also amended the CRA: products classified as **EHR systems** demonstrate conformity through the procedure in that regulation. This takes precedence over the product class.

Product class determines the conformity route

Annex III splits important products into two classes (19 items in class I, 4 in class II) and lists 3 critical products. If your product is on none of these lists it counts as "other"; **the Annex I requirements still apply**, only the conformity route is more flexible.

One point to watch: for class I important products, if harmonised standards were not applied or only applied in part, the internal control route closes and a route involving a third party must be used.

Three separate work packages

The CRA asks for three different things at once: the **13 product requirements** in Annex I Part I, the **8 vulnerability handling requirements** in Annex I Part II, and the **8-element technical documentation** in Annex VII. These do not substitute for one another: a secure product without a vulnerability handling process is not conformant.

Support period

The manufacturer must determine a support period and state it clearly to users. The floor is **at least 5 years**, and a security update must remain available for **at least 10 years** after it is issued. The period follows the product's expected lifetime: you cannot go below the floor, and for long-lived products the floor may not be enough.

How Nechh Eco-Report handles it

The Eco-Report CRA module assesses product class, conformity route and support period from data parsed out of the official text; when a question is unanswered it does not guess, it says "cannot decide". The CRA Manufacturer Readiness Kit turns Annexes I, III and VII into working files. Eco-Report is a preparation tool; it does not replace a conformity assessment or CE marking.

Source: Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex; amended by Regulation (EU) 2025/327.

Publication note: This content is general information; it is not legal advice, a conformity assessment or a company-specific compliance evaluation. The final determination rests on the official text and, where needed, legal advice.