EU CRA Compliance

If your connected product sells into Europe, the EU Cyber Resilience Act applies to you. Full enforcement lands in December 2027, with the first reporting duties from September 2026. We help you reach conformity before it gates your access to the market.

What the EU CRA Means for You

The EU Cyber Resilience Act sets mandatory cybersecurity rules for any product with digital elements sold in the EU, from vehicles and ECUs to telematics units and IoT gateways. Full enforcement begins in December 2027, with vulnerability and incident reporting duties starting earlier, in September 2026.

Getting it wrong is expensive. It can mean market restrictions, plus fines up to €15 million or 2.5% of global annual turnover, whichever is higher. And the work to comply, from SBOMs to a vulnerability-handling process to conformity evidence, takes months. So the deadline is closer than it looks.

What the EU CRA Requires

Security by Design & Default

Your product has to be secure out of the box, backed by a documented risk assessment.

SBOM (Software Bill of Materials)

A maintained list of every component, so vulnerabilities can be tracked and disclosed.

Vulnerability Handling

A working process to find, fix and disclose vulnerabilities across the product's whole life.

Conformity Assessment

Proof of conformity, self-assessed or third-party depending on your product's risk class, so you can CE-mark it.

Ongoing Updates

Security updates across the support period you commit to.

How We Deliver EU CRA Conformity

EU CRA gap assessment

We start with an EU CRA gap assessment against your product, then help you close the gaps: continuous SBOM/HBOM scanning through vulnerability.core, a working vulnerability-handling process, and the conformity documentation you need to CE-mark your product and stay in the market.

What you get

An EU CRA gap report · an SBOM maintained in vulnerability.core · a vulnerability-handling process · a conformity evidence pack.

Common Questions

If your product has digital elements and is sold or made available in the EU, it almost certainly does, and that includes vehicles, ECUs, telematics units and IoT devices. A gap assessment confirms it quickly.
Full enforcement begins in December 2027, but the vulnerability and incident reporting duties start earlier, in September 2026. Given how much work is involved, it's wise to start now.
A Software Bill of Materials lists every component in your product, so known vulnerabilities can be tracked and disclosed, which is a core EU CRA expectation.
It depends on your product's risk class. We help you work out the right route and prepare the evidence either way.

Start Your EU CRA Assessment

December 2027 is a deadline, not a suggestion, and the September 2026 reporting duties arrive sooner still. A gap assessment tells you exactly what the EU CRA requires of your product, and how to get there in time.