The Cyber Resilience Act, Regulation (EU) 2024/2847, reads as sixty articles and eight annexes. For a small manufacturer of a product with digital elements it reduces to twelve things, in an order that matters because the early ones decide the later ones. Two are due now; the rest by 11 December 2027, or earlier if you place a new product on the market after that date.
This is the list. Each step links to the piece that gives the text behind it.
Now: the two things that have applied since 11 September 2026
1. Decide whether you are in scope, and write it down. Installed or downloadable software, apps, libraries, firmware and devices are in; pure software as a service is out and under NIS2; remote processing a product cannot work without is back in. Article 2(1), Article 3(1) and (2), Recital 12. The text that decides it, and six questions that produce the one-page determination. If your company is under NIS2 as well, that is a separate determination.
2. Set up Article 14 reporting. Since 11 September 2026, an actively exploited vulnerability or a severe incident in a product in scope starts a 24-hour clock, for products already on the market too. That means: the two triggers written into your procedure as the Regulation defines them; your member state's CSIRT named; a filer and a deputy registered on ENISA's single reporting platform with EU Login and two-factor authentication; an agreed meaning of "became aware"; and the three deadlines with their real anchors, which most write-ups get wrong. The deadlines page computes them.
Before the file: the decisions that shape it
3. Find your tier. Default, important class I or II, or critical. The Annex III and IV lists, verbatim, and the Article 32 route each tier allows: self-assessment for default products, a notified body for most of the rest.
4. Know who enforces. The market surveillance authority of your member state, if it has registered one; on the day Article 14 applied, seven of 27 had. Write down which, or the date you checked and found none.
5. Determine the support period. At least five years, or the expected time in use if shorter, with the reasoning; the end date shown at purchase, month and year. Article 13(8) and the three retention clocks that hang off it.
By 11 December 2027: the product and the file
6. Meet the 22 essential requirements of Annex I. Fourteen product properties in Part I, thirteen of them "where applicable" on the basis of your risk assessment, and eight vulnerability-handling requirements in Part II that always apply. The table, with which may be excluded and why.
7. Do the cybersecurity risk assessment. Article 13(2), and Annex VII point 3: the document that decides which Part I requirements apply to your product and justifies every exclusion. Start here; everything after depends on it.
8. Write the four operating documents Part II presumes exist. A coordinated vulnerability disclosure policy, a public contact for reporting vulnerabilities, a way to distribute security updates securely and free of charge, and an SBOM procedure that produces one per product per version.
9. Assemble the technical file. Annex VII's eight points, and the eleven documents they turn into: kept ten years or the support period, whichever is longer, updated as the product changes. Before the product is placed on the market.
10. Run the conformity assessment. For a default product, the internal control procedure of Annex VIII module A, on your own responsibility. For important and critical products, the notified body or certification route from step 3.
11. Sign the EU declaration of conformity and affix the CE mark. Article 28 and Annex V for the declaration; Article 30 for where the mark goes on software: on the declaration, or on a consumer-reachable section of the product's website, before placing on the market.
12. Put the user information in place. Annex II: who you are, the vulnerability contact and where the disclosure policy is, the support period's end date, how to install updates, how to decommission securely, and where the declaration can be found. Kept available for ten years or the support period.
What the order buys you
Steps 1 and 2 are due today and take an afternoon; a company that has done them can answer the two questions an authority or a customer asks first. Steps 3 to 5 are decisions, not documents, and they determine whether the file in step 9 is a self-assessment or a notified-body engagement, and for how long it has to be kept. Steps 6 to 12 are the December 2027 work, and step 7 is where to begin it, because the risk assessment is the argument the rest of the file makes.
None of this requires a consultant to read the Regulation for you; every step above cites the article, and the articles are short. What it requires is that the answers are written down, dated and kept, which is the part that goes missing between a good intention and an audit.
Sources
- Regulation (EU) 2024/2847, Articles 2, 3, 13, 14, 28, 30, 31, 32, 52, 64, 69 and 71(2); Recital 12; Annexes I, II, III, IV, V, VII and VIII. Read from the Official Journal text on EUR-Lex on 11 September 2026. Each linked article carries its own references.
This is not legal advice. It is the reading order, with the text one click away at each step.