Cyber Resilience Act: all tools and articles

Regulation (EU) 2024/2847, Articles 2 and 30, and Recital 12

Your customers install your software. Does the CRA make you CE mark it?

In scope?
Yes, if they install it. A product with digital elements can be software alone.
Which law?
The CRA if they install it. If they only log in, Recital 12 points to NIS2 instead.
Due when?
Reporting since 11 September 2026; everything else from 11 December 2027.

How do customers get it?

A CE mark on software goes on the declaration or the website

Article 30 is explicit: for products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity or on the website accompanying the software product. No sticker, no hardware, and it goes on before the product is placed on the market.

The same company, read under two laws

  • Which law

    If they install it: Regulation (EU) 2024/2847, the Cyber Resilience Act

    If they only log in: Directive (EU) 2022/2555, as your member state transposed it

  • What you are

    If they install it: The manufacturer of a product with digital elements

    If they only log in: A cloud computing service provider, essential or important by size

  • Marking and evidence

    If they install it: CE marking, an EU declaration of conformity, and technical documentation kept ten years

    If they only log in: No marking. The Article 21 risk-management measures, and your entity details on the national list

  • Reporting a problem

    If they install it: An actively exploited vulnerability or a severe incident: early warning within 24 hours, notification within 72

    If they only log in: A significant incident: early warning 24 hours, notification 72 hours, final report within 1 month

Regulation (EU) 2024/2847 and Directive (EU) 2022/2555, read from the Official Journal with their corrigenda. The boundary between them is Recital 12 of the Cyber Resilience Act, which is the Union's reading of its own scope rather than an operative provision.

Two ways to be ready

CRA readiness, €1,500, 10 working days

We scope your product, list the gaps against Annex I, set up the reporting path and draft the technical file with you.

See what it covers

CRA technical file pack, €2,000

The same file, written by you from our template and product record, with no engagement.

See the pack

Questions people ask

We sell on-premise software and no hardware at all. Do we really CE mark it?
Yes. A product with digital elements is a software or hardware product, and Article 30 says where the marking goes for software: on the EU declaration of conformity, or on the website accompanying the product.
We are SaaS only. Are we simply out of the CRA?
Largely, and into NIS2 instead. Recital 12 names cloud service models such as SaaS as Directive (EU) 2022/2555 territory. The exception is a cloud that supports a product you make, which is a remote data processing solution and comes back into the CRA with that product.
We ship an installed product and a hosted one. Do we owe both?
Yes, and the duties do not substitute for each other. You are a manufacturer under the CRA for what is installed and a service provider under NIS2 for what is hosted, with separate reporting paths and separate authorities.
What is actually due now, before 11 December 2027?
The reporting duty. Since 11 September 2026 an actively exploited vulnerability or a severe incident has to be notified, first within 24 hours and then within 72.

This page in:DeutschFrançaisNederlandsEspañolDansk