Frequently Asked Questions

Cyber Resilience Act (CRA)

Does the CRA apply to my product?

1

CRA applies to any organization that manufactures, imports, distributes, or places products with digital elements on the EU market, including hardware vendors, IoT companies, embedded software teams, and digital product manufacturers.

Software-only products fall under the CRA if they have direct or indirect connectivity or are necessary for a product to operate securely, though cloud-only SaaS platforms are generally excluded unless they ship an installable or connectable component.


What if I’m not in the EU… but my customers are?

2

Even if your company is based outside the EU, the CRA applies if you sell or distribute products with digital elements to customers in the EU, including both finished products and embedded components.


When do I need to comply by?

3

The CRA entered into force on December 10, 2024, with vulnerability handling reporting obligations applying as September 11, 2026.

Main obligations apply from December 11, 2027.


If we use open source software (OSS) or components in our products, how does CRA impact us?

4

When manufacturers integrate open source components into a CRA regulated products, the responsibility shifts and the liability transfers to the manufacturer not the upstream developer.

Whenever open source software (OSS) becomes part of a commercial product or service, it is in scope for vulnerability handling, updates, and documentation just like first-party code.

Projects that are "openly shared and freely accessible, usable, modifiable and redistributable" and supplied free of charge without commercial activity remain exempt from CRA.

So, if you are contributing to others' open source software projects, or just publishing your open source code in your own repository and you are not trying to monetize it, you can breathe easier.