What is the Cyber Resilience Act?
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity rules for products with digital elements: hardware and software that connect to a device or network, including their remote data processing. Manufacturers design products to the essential requirements of Annex I, handle vulnerabilities for the whole support period, report serious security events and prove conformity before the CE marking goes on.
When the CRA applies
- 10 December 2024: the Regulation entered into force.
- 11 June 2026: rules for notified bodies (Chapter IV).
- 11 September 2026: reporting of actively exploited vulnerabilities and severe incidents (Article 14), also for products placed on the market before 11 December 2027.
- 11 December 2027: all other obligations, including the essential requirements, conformity assessment and CE marking.
ENISA opened the single reporting platform on 11 September 2026. The Commission described the important and critical product categories in Implementing Regulation (EU) 2025/2392 and published guidance on applying the CRA in July 2026. Source: Regulation (EU) 2024/2847 on EUR-Lex.
Who needs to comply
- Manufacturers of hardware and software placed on the EU market, paid or free of charge, in the course of a commercial activity
- Importers and distributors, who check the CE marking, documentation and contact details before selling
- Anyone who sells a product under their own name or substantially modifies one, who becomes a manufacturer
- Open-source software stewards, with a lighter regime of their own (Article 24)
Product classes and conformity assessment
The test is the product's core functionality. Free and open-source software in Annex III may use internal control when its technical documentation is public.
Article 14 reporting
- Early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
- Notification within 72 hours, with the nature of the exploit or incident and the measures taken.
- Final report no later than 14 days after a fix is available for a vulnerability, or one month after the notification for an incident.
Reports go through the ENISA single reporting platform to the CSIRT designated as coordinator in the Member State of your main establishment. You also inform the users who are affected.
Key CRA controls covered by Dazr
How Dazr helps with the CRA
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. The Cyber Resilience Act is one of its twelve frameworks: 42 recurring controls plus a product module. In practice that means:
- A product register with versions, support period, conformity route, CE marking and declaration status
- A guided classification against Article 2 and Annexes III and IV that shows which conformity procedures are allowed
- SBOM upload (CycloneDX or SPDX JSON) with components, licences and a known-vulnerability check on OSV.dev
- Vulnerabilities with CVE and GHSA identifiers, affected and fixed versions and disclosure status
- Article 14 reports with live 24-hour, 72-hour and final-report clocks, a draft text for each stage and email reminders
- Technical documentation (Annex VII) and the EU declaration of conformity (Annex V) as PDF, plus a coordinated vulnerability disclosure policy to adopt under Policies


A sealed evidence trail
Everything you record in the CRA module becomes an entry in your evidence trail: products, classifications, SBOMs, releases and patches, vulnerabilities, reports and generated documents. Each entry is hashed with SHA-256, carries the hash of the entry before it and is signed by Dazr. Entries are never edited; a correction is a new entry that points to the old one. Change, remove or reorder an entry and verification fails.
- The portal verifies the whole chain and every signature on request
- An evidence bundle holds the entries, the files, the signatures, the public keys, a readable PDF summary and a small verifier that runs offline
- Market surveillance authorities and notified bodies can check the bundle without access to your workspace
Sealed by Dazr means Dazr's signing key confirms content, order and time. It is not a qualified electronic seal or a qualified timestamp under eIDAS.

Verify a seal
Paste a seal, the manifest.jws of an evidence bundle or an entry hash. Dazr checks the signature and confirms whether it issued it. Nothing else is sent or shown.
What market surveillance authorities look for
On a reasoned request, authorities ask for the technical documentation, the EU declaration of conformity and, where needed, the SBOM. They check that the classification and the conformity route fit the product, that vulnerabilities were handled and reported on time, and that the support period is kept. Dazr keeps all of it in one place, for at least ten years or the support period.
Back to the full Dazr Compliance overview › | Sign up free ›