Cyber Resilience Act FAQ
Practical guide for manufacturers and developers
Everything you need to know about CRA compliance - from scope and open source to reporting obligations. Explained with practical examples from the EU Commission Guidance.
At a Glance: Essential CRA Facts
11 June 2024
11 June 2028
Products with digital elements
5 years
EUR 15M / 3% turnover
Risk assessment, conformity, vulnerabilities
Scope & Placing on the Market
When does the CRA apply to your product? What does placing on the market mean for software, hardware, and combined systems?
Free and Open-Source Software (FOSS)
When is FOSS considered commercial? How do donations, support, and monetization affect CRA obligations?
Substantial Modifications & Spare Parts
When is an update considered a substantial modification? How are spare parts and repairs treated?
Support Period
How long must you provide security updates and support for your products?
Product Classification & Conformity Assessment
Is your product "important" or "critical"? How does conformity assessment work?
Cybersecurity Risk Assessment
How do you conduct a CRA-compliant risk assessment? What applies to integrated components?
Remote Data Processing Services (RDPS) & Cloud
Which cloud services qualify as RDPS? How do IaaS, PaaS, and SaaS differ in the CRA context?
Vulnerability Reporting & Incident Handling
When must you report vulnerabilities? What are the deadlines and obligations?
Obligations of Economic Operators
What are the duties of manufacturers, importers, and distributors under the CRA?
Exemptions & Existing Products
Which products are exempt from the CRA? How are existing products treated?
Consequences & Recommendations
What penalties apply for non-compliance? What should companies do now?
Common Misconceptions
Widespread misunderstandings about the Cyber Resilience Act — and what actually applies.
Vulnerability Handling in Detail
SBOM obligations, security updates, coordinated disclosure, and the complete vulnerability lifecycle under the CRA.
Interaction with Other Legislation
How does the CRA interact with vehicle regulations, the Radio Equipment Directive, and other EU regulations?
Legal References
The full legal text of the Cyber Resilience Act in the Official Journal of the EU.
Draft Commission Communication with practical examples and interpretive guidance (feedback deadline: 31 March 2026).
Official EU Commission information page on the Cyber Resilience Act.
Implementing regulation for the classification of important and critical products.
Ready for CRA Compliance?
Kunnus supports you in achieving complete CRA compliance - from risk assessment and SBOM management to vulnerability tracking. Reduce costs and effort by up to 70%.
Request a DemoThis FAQ is based on the European Commission's draft Communication providing guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act). It is for informational purposes only and does not constitute legal advice. The authoritative interpretation of the CRA may only be given by the Court of Justice of the European Union. A case-by-case assessment is always required.