Cyber Resilience Act: what changes for your products
Complete plan
Three short modules for the product, development and support teams of companies that make, import or sell software or connected products in the EU: know whether your products are covered and in which role, report an actively exploited vulnerability on time and inform users, and build the security requirements in from the design stage.
- 8 min
- 3 modules
- 9-question check
- English · Français
- Attestation
You will be able to
- Recognise a product with digital elements: connectable software or hardware, with the online service it cannot work without
- Recognise an actively exploited vulnerability or a severe incident affecting a product's security, and know the duty to report already applies, including for products already on the market
- Ship a product that is secure by default (no shared password, no needless open service, a way back to factory settings) and without known exploitable vulnerabilities
Programme
3 modules · 8 min-
Cyber Resilience Act: does it apply to us? 3 min
- Recognise a product with digital elements: connectable software or hardware, with the online service it cannot work without
- Know what stays out of scope: a purely online service, products covered by their own rules (medical devices, vehicles, civil aviation, marine equipment), products designed solely for defence, open-source software developed outside any commercial activity
- Identify your role (manufacturer, importer, distributor) and know that you become the manufacturer by selling under your own brand or substantially modifying a product
-
Exploited flaw: who reports, and when? 3 min
- Recognise an actively exploited vulnerability or a severe incident affecting a product's security, and know the duty to report already applies, including for products already on the market
- Know the clock: early warning within twenty-four hours, notification within seventy-two hours, then a final report, through ENISA's single reporting platform, and inform affected users
- Escalate at once, without waiting to be sure, and know who in your company decides and submits (a named owner and a reachable deputy)
-
Secure out of the box: five CRA requirements 2 min
- Ship a product that is secure by default (no shared password, no needless open service, a way back to factory settings) and without known exploitable vulnerabilities
- Plan free security updates for the whole support period, automatic by default where applicable, with a way to switch them off, and announce the end date of support
- Keep each product's software bill of materials (SBOM) up to date and publish a contact point with a coordinated vulnerability disclosure policy
-
Knowledge check
9 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Version 1 · updated October 6, 2026