Home › Frameworks › Cyber Resilience Act

Cyber Resilience Act compliance software for manufacturers of connected products.

A product register with Annex III and IV classification, SBOMs with a known-vulnerability check, Article 14 reporting clocks with draft texts, technical documentation and the EU declaration of conformity, all on a sealed evidence trail. Reporting applies since 11 September 2026. Included in Pro, €99 a month.

At a glance

  • Article 13: Risk assessment, secure design, support period of at least five years, SBOM and vulnerability handling.
  • Article 14: Report actively exploited vulnerabilities and severe incidents: 24 hours, 72 hours, final report.
  • Articles 28 to 32: Conformity assessment by product class, technical documentation, EU declaration of conformity and CE marking.
  • Articles 19 to 24: Importers, distributors and open-source software stewards.

On this page

  1. What is the Cyber Resilience Act?
  2. When the CRA applies
  3. Who needs to comply
  4. Product classes and conformity assessment
  5. Article 14 reporting
  6. How Dazr helps with the CRA
  7. A sealed evidence trail
  8. Verify a seal

What is the Cyber Resilience Act?

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity rules for products with digital elements: hardware and software that connect to a device or network, including their remote data processing. Manufacturers design products to the essential requirements of Annex I, handle vulnerabilities for the whole support period, report serious security events and prove conformity before the CE marking goes on.

When the CRA applies

  • 10 December 2024: the Regulation entered into force.
  • 11 June 2026: rules for notified bodies (Chapter IV).
  • 11 September 2026: reporting of actively exploited vulnerabilities and severe incidents (Article 14), also for products placed on the market before 11 December 2027.
  • 11 December 2027: all other obligations, including the essential requirements, conformity assessment and CE marking.

ENISA opened the single reporting platform on 11 September 2026. The Commission described the important and critical product categories in Implementing Regulation (EU) 2025/2392 and published guidance on applying the CRA in July 2026. Source: Regulation (EU) 2024/2847 on EUR-Lex.

Who needs to comply

  • Manufacturers of hardware and software placed on the EU market, paid or free of charge, in the course of a commercial activity
  • Importers and distributors, who check the CE marking, documentation and contact details before selling
  • Anyone who sells a product under their own name or substantially modifies one, who becomes a manufacturer
  • Open-source software stewards, with a lighter regime of their own (Article 24)

Product classes and conformity assessment

Default categoryMost products. Internal control (module A): you assess conformity yourself and keep the technical documentation.
Important, class IAnnex III, for example password managers, VPNs, routers, operating systems and smart home security products. Module A only when harmonised standards, common specifications or a certification scheme are applied in full; otherwise a notified body.
Important, class IIHypervisors and container runtimes, firewalls and intrusion detection, tamper-resistant chips. A notified body (modules B and C or H) or a European cybersecurity certificate.
CriticalAnnex IV: hardware security boxes, smart meter gateways, smartcards and secure elements. A European cybersecurity certificate where a delegated act requires one, otherwise the class II procedures.

The test is the product's core functionality. Free and open-source software in Annex III may use internal control when its technical documentation is public.

Article 14 reporting

  • Early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
  • Notification within 72 hours, with the nature of the exploit or incident and the measures taken.
  • Final report no later than 14 days after a fix is available for a vulnerability, or one month after the notification for an incident.

Reports go through the ENISA single reporting platform to the CSIRT designated as coordinator in the Member State of your main establishment. You also inform the users who are affected.

Key CRA controls covered by Dazr

Article 13Cybersecurity risk assessment, due diligence on open-source components, support period, product identification and user information.
Annex I, Part IEssential requirements: no known exploitable vulnerabilities, secure by default, security updates, access control, data protection, logging, secure deletion.
Annex I, Part IIVulnerability handling: SBOM, remediation without delay, security testing, advisories, coordinated vulnerability disclosure, secure update distribution.
Article 14Reporting of actively exploited vulnerabilities and severe incidents, and informing users.
Articles 28 to 32EU declaration of conformity, CE marking, technical documentation (Annex VII) and the conformity assessment procedure.
Articles 19 to 24Importers, distributors, substantial modification and open-source software stewards.

How Dazr helps with the CRA

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. The Cyber Resilience Act is one of its twelve frameworks: 42 recurring controls plus a product module. In practice that means:

  • A product register with versions, support period, conformity route, CE marking and declaration status
  • A guided classification against Article 2 and Annexes III and IV that shows which conformity procedures are allowed
  • SBOM upload (CycloneDX or SPDX JSON) with components, licences and a known-vulnerability check on OSV.dev
  • Vulnerabilities with CVE and GHSA identifiers, affected and fixed versions and disclosure status
  • Article 14 reports with live 24-hour, 72-hour and final-report clocks, a draft text for each stage and email reminders
  • Technical documentation (Annex VII) and the EU declaration of conformity (Annex V) as PDF, plus a coordinated vulnerability disclosure policy to adopt under Policies
A product in the CRA register: class I classification with the allowed conformity procedures, and its SBOM with known vulnerabilities
Classification, conformity route and SBOM for each product.
An Article 14 report for an actively exploited vulnerability, with the early warning submitted and the notification clock running
Every Article 14 step with its deadline and a draft to submit.

A sealed evidence trail

Everything you record in the CRA module becomes an entry in your evidence trail: products, classifications, SBOMs, releases and patches, vulnerabilities, reports and generated documents. Each entry is hashed with SHA-256, carries the hash of the entry before it and is signed by Dazr. Entries are never edited; a correction is a new entry that points to the old one. Change, remove or reorder an entry and verification fails.

  • The portal verifies the whole chain and every signature on request
  • An evidence bundle holds the entries, the files, the signatures, the public keys, a readable PDF summary and a small verifier that runs offline
  • Market surveillance authorities and notified bodies can check the bundle without access to your workspace

Sealed by Dazr means Dazr's signing key confirms content, order and time. It is not a qualified electronic seal or a qualified timestamp under eIDAS.

The verified evidence trail: each entry with its number, type, product and SHA-256 hash
A verified chain of sealed entries, ready to export.

Verify a seal

Paste a seal, the manifest.jws of an evidence bundle or an entry hash. Dazr checks the signature and confirms whether it issued it. Nothing else is sent or shown.

What market surveillance authorities look for

On a reasoned request, authorities ask for the technical documentation, the EU declaration of conformity and, where needed, the SBOM. They check that the classification and the conformity route fit the product, that vulnerabilities were handled and reported on time, and that the support period is kept. Dazr keeps all of it in one place, for at least ten years or the support period.

Back to the full Dazr Compliance overview › | Sign up free ›

Cyber Resilience Act questions, answered.

When does the Cyber Resilience Act apply?

The Regulation entered into force on 10 December 2024. The rules for notified bodies apply from 11 June 2026, the Article 14 reporting obligations from 11 September 2026 (also for products placed on the market earlier), and all other obligations from 11 December 2027.

Does the CRA cover software?

Yes. A product with digital elements is any software or hardware product placed on the market, including its remote data processing solutions. Software offered only as a service, without a product placed on the market, is generally outside the CRA and may fall under NIS2.

Does Dazr submit our Article 14 reports?

No. Reports go through the ENISA single reporting platform, to the CSIRT designated as coordinator in the Member State of your main establishment. Dazr keeps the 24-hour, 72-hour and final-report clocks, drafts the text for each stage and records when and with which reference you submitted it.

Which SBOM formats can we upload?

CycloneDX 1.2 to 1.6 and SPDX 2.2, 2.3 and 3.0 as JSON. Dazr checks the file, lists the components and licences, and can look up known vulnerabilities on OSV.dev. Only package names and versions are sent, and the lookup can be switched off.

What does sealed by Dazr prove?

That an entry, with exactly this content, was recorded at this position in your evidence trail at the stated time. Each entry is hashed, linked to the previous one and signed by Dazr. It is not a qualified electronic seal or a qualified timestamp under eIDAS.

Which plan includes the CRA module?

Pro (€99 a month, up to 5 users) and Enterprise (€499 a month). Prices exclude VAT, monthly, cancel any time.

Ready for the Cyber Resilience Act?

The CRA module is included in Pro (€99/mo) and Enterprise (€499/mo), self-serve via Mollie, excl. VAT, cancel any time. Free and Basic cover ISO 27001, GDPR and NIS2. Custom is the only tier on a contract, priced on request.