EU Regulation (EU) 2024/2847

Cyber Resilience Act FAQ

Practical guide for manufacturers and developers

Everything you need to know about CRA compliance - from scope and open source to reporting obligations. Explained with practical examples from the EU Commission Guidance.

At a Glance: Essential CRA Facts

Entry into Force

11 June 2024

Compliance Deadline

11 June 2028

Scope

Products with digital elements

Minimum Support

5 years

Max. Penalty

EUR 15M / 3% turnover

Core Obligations

Risk assessment, conformity, vulnerabilities

Scope & Placing on the Market

When does the CRA apply to your product? What does placing on the market mean for software, hardware, and combined systems?

Free and Open-Source Software (FOSS)

When is FOSS considered commercial? How do donations, support, and monetization affect CRA obligations?

Substantial Modifications & Spare Parts

When is an update considered a substantial modification? How are spare parts and repairs treated?

Support Period

How long must you provide security updates and support for your products?

Product Classification & Conformity Assessment

Is your product "important" or "critical"? How does conformity assessment work?

Cybersecurity Risk Assessment

How do you conduct a CRA-compliant risk assessment? What applies to integrated components?

Remote Data Processing Services (RDPS) & Cloud

Which cloud services qualify as RDPS? How do IaaS, PaaS, and SaaS differ in the CRA context?

Vulnerability Reporting & Incident Handling

When must you report vulnerabilities? What are the deadlines and obligations?

Obligations of Economic Operators

What are the duties of manufacturers, importers, and distributors under the CRA?

Exemptions & Existing Products

Which products are exempt from the CRA? How are existing products treated?

Consequences & Recommendations

What penalties apply for non-compliance? What should companies do now?

Common Misconceptions

Widespread misunderstandings about the Cyber Resilience Act — and what actually applies.

Vulnerability Handling in Detail

SBOM obligations, security updates, coordinated disclosure, and the complete vulnerability lifecycle under the CRA.

Interaction with Other Legislation

How does the CRA interact with vehicle regulations, the Radio Equipment Directive, and other EU regulations?

Legal References

Ready for CRA Compliance?

Kunnus supports you in achieving complete CRA compliance - from risk assessment and SBOM management to vulnerability tracking. Reduce costs and effort by up to 70%.

Request a Demo

This FAQ is based on the European Commission's draft Communication providing guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act). It is for informational purposes only and does not constitute legal advice. The authoritative interpretation of the CRA may only be given by the Court of Justice of the European Union. A case-by-case assessment is always required.