Cyber Resilience Act: all tools and articles
Regulation (EU) 2024/2847, Articles 2, 3 and 24
You write software that ships inside someone else's product. What does the CRA ask of you?
- In scope?
- Yes. A component placed on the market separately is a product with digital elements in its own right.
- Which class?
- Default for firmware, drivers and libraries. Operating systems and boot managers are listed.
- Due when?
- Reporting since 11 September 2026; everything else from 11 December 2027.
What do you supply?
There is no open-source exemption
Article 2 lists what the Regulation does not apply to: medical devices, in vitro diagnostics, motor vehicles, products certified for aviation, marine equipment, spare parts made to the same specifications, and national security. Free and open-source software is not on that list. The boundary is the definition instead: making available on the market is the supply of a product for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.
An open-source software steward is a legal person, other than a manufacturer, that systematically supports the development of free and open-source software intended for commercial activities and ensures its viability. Article 24 gives it its own, lighter duties rather than the manufacturer's.
Where software alone is listed
| Point | Class | As the Regulation words it |
|---|---|---|
| III.I.2 | Class I | Standalone and embedded browsers |
| III.I.3 | Class I | Password managers |
| III.I.4 | Class I | Software that searches for, removes, or quarantines malicious software |
| III.I.7 | Class I | Security information and event management (SIEM) systems |
| III.I.8 | Class I | Boot managers |
| III.I.9 | Class I | Public key infrastructure and digital certificate issuance software |
| III.I.11 | Class I | Operating systems |
| III.II.1 | Class II | Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments |
Regulation (EU) 2024/2847, Annex III, read from the Official Journal with its corrigenda; reporting duties apply since 11 September 2026.
Two ways to be ready
CRA readiness, €1,500, 10 working days
We scope your product, list the gaps against Annex I, set up the reporting path and draft the technical file with you.
See what it coversCRA technical file pack, €2,000
The same file, written by you from our template and product record, with no engagement.
See the packQuestions people ask
- We supply firmware to one manufacturer under contract. Is that placing it on the market?
- Making available on the market is supply for distribution or use in the course of a commercial activity, whether in return for payment or free of charge. Firmware supplied commercially to an integrator is supplied for use, so you are the manufacturer of that component.
- Our customer CE marks the device. Does that cover our component?
- No. Their declaration covers their product. Article 13(5) requires them to exercise due diligence on the components they integrate, so your compliance becomes a condition of their purchase rather than something absorbed by it.
- Who reports a vulnerability in our library, us or the integrator?
- Both have a duty. Under Article 13(6) a manufacturer who identifies a vulnerability in an integrated component, including an open-source component, reports it to whoever maintains that component. Your own Article 14 duty covers your product.
- What is actually due now, before 11 December 2027?
- The reporting duty. Since 11 September 2026 an actively exploited vulnerability or a severe incident has to be notified, first within 24 hours and then within 72.