EU CRA enforcement begins 11 September 2026

Manufacturers must be fully compliant — fines of up to €15 million or 2.5% of global turnover.

CRA Compliance
Made Simple

The EU Cyber Resilience Act creates mandatory cybersecurity requirements for all products with digital elements. CRAReady helps manufacturers assess, manage and report — before the deadline.

Time remaining until enforcement

00
Days
00
Hours
00
Minutes
00
Seconds

11 September 2026 · Article 14 vulnerability & incident reporting deadline

Core CRA obligations for manufacturers

Vulnerability disclosure and handling
Security updates for minimum 5 years
Technical documentation preparation
Conformity assessment (self or third-party)
CE marking and EU Declaration of Conformity
Early warning within 24–72 hours of incidents

Platform

Complete Compliance Solution

Four integrated modules covering the full CRA compliance lifecycle.

CRA Assessment

Live

Guided questionnaire to determine if the CRA applies, your product classification (Default / Important / Critical), and your conformity route.

Incident Reporting

Phase 2

ENISA-compliant early warning notifications and Article 14 detailed reporting workflows with automated deadline tracking.

SBOM Generation

Phase 3

Automated CycloneDX SBOM creation from GitHub repositories or ZIP uploads, with version tracking and diff analysis.

Vulnerability Scanning

Phase 3

Continuous scanning against NVD, EUVD, OSV and GitHub Advisory databases with VEX statement generation.

Regulatory Timeline

Key Dates & Deadlines

Vulnerability & Incident Reporting11 Sep 2026

Article 14 obligations begin — early warning within 24h of exploited vulnerabilities

Full CRA Compliance Required11 Dec 2027

All in-scope products must meet essential cybersecurity requirements and carry CE marking

Ready to Get CRA Compliant?

Start with our free CRA applicability assessment — no account required. Understand your obligations in under 2 minutes.