Cyber Resilience Act: all tools and articles
Regulation (EU) 2024/2847, Articles 2 and 30, and Recital 12
Your customers install your software. Does the CRA make you CE mark it?
- In scope?
- Yes, if they install it. A product with digital elements can be software alone.
- Which law?
- The CRA if they install it. If they only log in, Recital 12 points to NIS2 instead.
- Due when?
- Reporting since 11 September 2026; everything else from 11 December 2027.
How do customers get it?
A CE mark on software goes on the declaration or the website
Article 30 is explicit: for products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity or on the website accompanying the software product. No sticker, no hardware, and it goes on before the product is placed on the market.
The same company, read under two laws
Which law
If they install it: Regulation (EU) 2024/2847, the Cyber Resilience Act
If they only log in: Directive (EU) 2022/2555, as your member state transposed it
What you are
If they install it: The manufacturer of a product with digital elements
If they only log in: A cloud computing service provider, essential or important by size
Marking and evidence
If they install it: CE marking, an EU declaration of conformity, and technical documentation kept ten years
If they only log in: No marking. The Article 21 risk-management measures, and your entity details on the national list
Reporting a problem
If they install it: An actively exploited vulnerability or a severe incident: early warning within 24 hours, notification within 72
If they only log in: A significant incident: early warning 24 hours, notification 72 hours, final report within 1 month
Regulation (EU) 2024/2847 and Directive (EU) 2022/2555, read from the Official Journal with their corrigenda. The boundary between them is Recital 12 of the Cyber Resilience Act, which is the Union's reading of its own scope rather than an operative provision.
Two ways to be ready
CRA readiness, €1,500, 10 working days
We scope your product, list the gaps against Annex I, set up the reporting path and draft the technical file with you.
See what it coversCRA technical file pack, €2,000
The same file, written by you from our template and product record, with no engagement.
See the packQuestions people ask
- We sell on-premise software and no hardware at all. Do we really CE mark it?
- Yes. A product with digital elements is a software or hardware product, and Article 30 says where the marking goes for software: on the EU declaration of conformity, or on the website accompanying the product.
- We are SaaS only. Are we simply out of the CRA?
- Largely, and into NIS2 instead. Recital 12 names cloud service models such as SaaS as Directive (EU) 2022/2555 territory. The exception is a cloud that supports a product you make, which is a remote data processing solution and comes back into the CRA with that product.
- We ship an installed product and a hosted one. Do we owe both?
- Yes, and the duties do not substitute for each other. You are a manufacturer under the CRA for what is installed and a service provider under NIS2 for what is hosted, with separate reporting paths and separate authorities.
- What is actually due now, before 11 December 2027?
- The reporting duty. Since 11 September 2026 an actively exploited vulnerability or a severe incident has to be notified, first within 24 hours and then within 72.