EU Cyber Resilience Act

Get CRA-ready, without losing the overview.

The Cyber Resilience Act makes cybersecurity mandatory for every product with digital elements. The SwissGRC® Platform brings your CRA processes together in one place, so you stay ready to provide evidence at any time.

Timeline

Two 2026 deadlines that matter now

Many assume everything happens in 2027. Wrong. The first obligation takes effect in September 2026, and it applies to every manufacturer.

11 Jun 2026
Mainly Class I and II

Notified bodies are designated

EU member states designate accredited conformity assessment bodies. No immediate action is needed for standard-category products that use self-declaration. Manufacturers of Class I and II products should make contact now to get ahead of capacity bottlenecks.

11 Sep 2026
Applies to all manufacturers

Reporting obligations for vulnerabilities and incidents

The central and most immediate obligation. Actively exploited vulnerabilities and severe security incidents must be reported to the national CSIRT authority and ENISA within strict deadlines:

  • 24 hearly warning to CSIRT and ENISA
  • 72 hmore detailed follow-up report
  • 14 daysfinal report after update or workaround
  • 30 daysfinal report for severe incidents

The full timeline at a glance

10. Dez. 2024
CRA enters into forceThe transition period begins.
11 Jun 2026
Notified bodies activeMainly relevant for Class I and II.
11 Sep 2026
Reporting obligations for vulnerabilities and incidentsAll manufacturers affected. Reporting processes must work.
11 Dec 2026
Sufficient notified bodies in the EUCapacity planning for certification.
11 Dec 2027
Full application of all CRA requirementsCE marking becomes mandatory.

Classification

The four product categories

The CRA classifies products by risk. The category determines whether self-declaration is enough or a notified body has to assess.

01

Standard category

approx. 90% of all products

Ordinary business software, consumer electronics and standard IoT devices.

Manufacturer self-declaration (Module A)
02

Class I: important products

Elevated risk

Password managers, antivirus software, VPNs, firewalls, browsers.

Stricter conformity assessment required
03

Class II: critical products

High risk

Network management systems, industrial controls, smart meter gateways.

Certification by a notified body mandatory
04

Critical core products

Highest tier

A very small group with the strictest requirements.

Mandatory external assessment

Unsure which category your products fall into? Take our free CRA gap analysis further down this page. Six questions give you an initial read on your readiness, anonymous and with no sign-up.

Requirements

The core technical obligations

The CRA requires cybersecurity to be built in and evidenced across the entire product lifecycle. Five obligations are central.

01

Security by design and default

Security from the start: secure default settings, no universal passwords, minimal attack surfaces, encrypted data.

02

Vulnerability management

Security updates for at least five years, plus a PSIRT process that handles vulnerabilities across the lifecycle.

03

Software Bill of Materials

A complete, current inventory of all software components per product, including third-party and open source.

04

Technical documentation and CE

From the end of 2027, affected products need an EU declaration of conformity and CE marking. Without them, no EU import.

05

Resilience and incident containment

Products must withstand attacks. Manufacturers must contain incidents quickly and inform users.

Whitepaper

Cyber Resilience Act: what Swiss manufacturers must do now

A hands-on guide from Swiss Infosec AG and Swiss GRC. All deadlines, the four product categories and a concrete roadmap up to September 2026.

10 pages All deadlines and reporting duties Roadmap for development teams
Free. The download appears at once and is also sent by email. The whitepaper is in German.

Free gap analysis

How CRA-ready is your product security?

A self-assessment based on the ENISA maturity model for SMEs: 25 questions across five areas. You get a maturity level per area and overall right away, anonymous and with no sign-up.

Based on the ENISA SME Cyber Resilience Maturity Assessment Model. A self-assessment that does not replace a product-specific risk assessment, legal analysis or formal CRA conformity assessment.

25 questions 5 areas 5 minutes

For each question, pick the description closest to your current practice. There is no right or wrong, just an honest baseline.

Question 1 / 25

0out of 5

Ergebnis

Request the detailed report and action checklist

Optional. We send a structured evaluation with your per-area maturity and a prioritised action checklist to your email. Your answers stay anonymous until you request the report.

    Thank you. Your report is on its way and will arrive in your inbox shortly.

    Request a demo

    The gap analysis is a non-binding self-assessment based on the ENISA maturity model and does not replace a product-specific risk assessment, legal analysis or formal CRA conformity assessment.

    The platform's role

    Structure and evidence for your CRA compliance

    The CRA requires not only a secure product but also robust processes and complete evidence. This is exactly where the SwissGRC® Platform comes in.

    01

    Applicability and scoping

    Capture your portfolio, assign each product to a risk class, record the action needed. The analysis becomes a trackable action plan.

    02

    Risk management and ISMS

    Assess and manage product risks in an integrated data model. Many CRA requirements map to ISO 27001 controls you already cover here.

    03

    Vulnerabilities and reporting

    Map your PSIRT process and manage the tight reporting deadlines (24h, 72h, 14 days) with clear roles and a complete history.

    04

    SBOM at governance level

    Link your SBOM to products and risks. When a component becomes vulnerable, you see at once which products are affected.

    05

    Technical documentation

    Risk analyses, measures and conformity records in one place, versioned and retrievable at any time.

    06

    CRA, NIS2 and DORA combined

    CRA, NIS2 and DORA in one platform. You produce evidence once, not three times.

    Frequently asked questions

    Understanding the CRA

    The key questions on the Cyber Resilience Act, with a particular focus on Swiss manufacturers and the upcoming national legislation.

    What is the Cyber Resilience Act (CRA)?
    The CRA (Regulation (EU) 2024/2847) is the first horizontal EU law to set binding cybersecurity requirements for all products with digital elements. It complements frameworks like the NIS2 Directive and the GDPR, but addresses product manufacturers directly and reaches along the entire supply chain. It entered into force on 10 December 2024 and applies in full from 11 December 2027.
    Does the CRA also apply to Swiss companies?
    Yes. The CRA is an EU market regulation: anyone placing products with digital elements on the EU market must meet the requirements, regardless of company location. This affects manufacturers selling into the EU, importers, distributors and, under certain conditions, Swiss cloud providers. Swiss companies without an EU establishment must also appoint an authorised representative in the EU.
    What deadlines apply in 2026 and 2027?
    Three dates are central: from 11 June 2026, notified conformity assessment bodies are designated (mainly relevant for Class I and II). From 11 September 2026, the reporting obligations for actively exploited vulnerabilities and severe incidents apply, and they apply to all manufacturers. From 11 December 2027, the CRA is fully applicable, including CE marking and conformity assessment.
    What are the reporting deadlines for vulnerabilities and incidents?
    From 11 September 2026, actively exploited vulnerabilities and severe security incidents must be reported within tight deadlines: an early warning to the national CSIRT authority and ENISA within 24 hours, a more detailed follow-up within 72 hours, a final report within 14 days after an update or workaround, and within 30 days for severe incidents. Reporting runs through a central ENISA platform.
    Which product category does my product fall into?
    The CRA has four tiers: the standard category (about 90 percent of all products, self-declaration is enough), Class I (important products such as password managers, VPNs, firewalls), Class II (critical products such as industrial controls, network management systems) and critical core products with the strictest requirements. Class I, II and core products need a stricter or external conformity assessment. A gap analysis clarifies the classification.
    What are the penalties for non-compliance?
    For serious violations, market surveillance authorities can impose fines of up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. For less serious violations, the ceiling is 10 million euros or 2 percent. Authorities can also ban sales, order recalls or withdraw products from the market.
    Is Switzerland introducing its own law?
    Yes, that is emerging. The Federal Council has tasked the Federal Office for Cybersecurity (BACS) with drafting a consultation proposal for Swiss legislation on the cyber resilience of digital products by autumn 2026, explicitly modelled on the EU CRA. Swiss manufacturers should therefore expect a regulatory double wave: the EU CRA now, and a Swiss counterpart expected from 2027 or 2028. Whoever implements the CRA logic today is well positioned for both.
    How does the SwissGRC® Platform support CRA compliance?
    The platform brings structure and evidence to the organisational CRA obligations: applicability analysis and scoping, risk management and ISMS, vulnerability and reporting processes with the tight deadlines, SBOM at governance level, and audit-ready technical documentation. Because CRA, NIS2 and DORA are mapped in one platform, evidence only has to be produced once. Security by design in the product itself remains a development task, where Swiss GRC and its partner Swiss Infosec AG support you.

    11 September 2026 is coming. Prepare in a structured way.

    See how you manage applicability, vulnerabilities, reporting processes and technical documentation with the SwissGRC® Platform. Or start with the whitepaper from Swiss Infosec AG and Swiss GRC.