# The EU Cyber Resilience Act — Compliance Guide

- **Source:** https://www.ketryx.com/assets/eu-cyber-resilience-act-compliance-guide
- **Type:** White Paper
- **Regulation:** REGULATION (EU) 2024/2847

A compliance guide for manufacturers of products with digital elements — what the regulation requires, when it applies, and how to build the evidence to prove it.

## Key figures

- **€15M** — max penalty, or 2.5% of global revenue
- **Dec 2027** — main requirements start to apply
- **22** — essential requirements across Annex I
- **€9.22T** — estimated global cost of cybercrime by 2024, up from €1.16T in 2019. The pressure behind the CRA.

## What's inside

1. From regulation to reality
2. Who and what is in scope
3. The timeline and the stakes
4. Annex I requirements
5. How Ketryx helps
6. In practice
7. How to get started

---

## At a glance

The Cyber Resilience Act makes cybersecurity a condition of access to the EU market for any product with digital elements. Here is what matters most for decision-makers — and where the real work lies.

1. **Security is now a market-access requirement.** Any product with digital elements must meet the CRA's cybersecurity rules to be sold in the EU.
2. **It is a lifecycle obligation.** Conformity must be built in at design and sustained through updates and vulnerability handling — not certified once.
3. **The clock is running.** Reporting duties start 11 Sep 2026; full compliance is required for all products by 11 Dec 2027.
4. **The penalties are material.** Up to €15M or 2.5% of global annual turnover, plus withdrawal from the EU market.
5. **Evidence is the hard part.** You must prove and continuously maintain conformity under audit — the burden Ketryx is built to carry.

---

## 01 From regulation to reality

The Cyber Resilience Act reshapes how connected products are designed, built, and maintained for the European market. As cyber threats grow and device ecosystems expand, the EU has made security a condition of market access — not an optional feature. Any product with digital elements (PDE), from IoT sensors and industrial controllers to smart appliances and the software that ships with them, must meet strict obligations across its entire lifecycle.

At its core, the CRA makes a simple promise: only secure products belong on the EU market. Article 6 sets the foundation — products must meet the essential cybersecurity requirements in Annex I, Part I, and manufacturers must run processes that satisfy Annex I, Part II.

In other words, the CRA is not only about how a device is built; it is about how it is supported and protected for its entire lifespan. That dual focus is what makes compliance an ongoing commitment rather than a one-time certification event.

> **Regulatory definition · Article 6**
> "Products with digital elements shall be made available on the market only where: (a) they meet the essential cybersecurity requirements set out in Part I of Annex I, provided that they are properly installed, maintained, used for their intended purpose or under conditions which can reasonably be foreseen, and, where applicable, the necessary security updates have been installed; and (b) the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I."

### What the CRA aims to achieve

- Raise the baseline of cybersecurity for all connected products.
- Protect consumers and businesses from devices that introduce network risk.
- Replace fragmented national rules with one harmonized market standard.
- Make security-by-design a competitive advantage, not a cost center.

---

## 02 Who and what is in scope

The CRA casts a broad net. It applies to any EU or non-EU manufacturer that places products with digital elements on the European market — whenever the product's intended or foreseeable use includes a direct or indirect data connection to a device or network.

### Applicability check

- Do you place a product with digital elements on the EU market?
- Does its use include a logical or physical data connection to a device or network?
- Is it outside the exception list (medical, automotive, aviation, etc.)?

If yes → **The CRA applies — you need to act.**

### Typically covered

- IoT & embedded devices — home, health, industry
- Industrial control & automation equipment
- Consumer electronics — appliances, wearables
- Software & firmware that ships with devices

### Notable exceptions

Products already covered by sector regulation — medical devices (MDR/IVDR), motor vehicles, civil aviation, and marine equipment. Also outside scope: software-as-a-service that is not part of an integral remote data processing solution, spare parts made to the same specifications to replace identical components, products for national-security or defence use, and free and open-source software supplied outside a commercial activity.

> Even a simple sensor counts. A connected thermostat or smart sensor falls under the CRA if it transmits or processes data in a networked environment. When in doubt, run a formal applicability assessment.

---

## 03 The timeline and the stakes

The CRA is already law, and its deadlines are close. Manufacturers must align product development and support processes now — full compliance leaves little room to retrofit evidence later.

### Penalties scale with the obligation

| Penalty | Applies to |
| --- | --- |
| **€15M / 2.5%** | Non-compliance with the essential cybersecurity requirements and core manufacturer obligations (Articles 13, 14). |
| **€10M / 2%** | Non-compliance with certain other obligations — including importer and distributor duties, the declaration of conformity, and conformity assessment (Article 64(3)). |
| **€5M / 1%** | Supplying incorrect, incomplete, or misleading information to authorities or notified bodies. |

Fines are the higher of the fixed amount or the stated percentage of worldwide annual turnover for the preceding financial year. Products already on the market fall under the essential requirements only if substantially modified after 11 Dec 2027; Article 14 reporting (from Sep 2026) covers actively exploited vulnerabilities and severe incidents on a 24-hour / 72-hour basis.

### Beyond fines

- **Blocked market access** — Non-compliant products can be withdrawn from the EU market.
- **Mandatory remediation** — Regulators can require costly redesign or field remediation.
- **Reputational damage** — Public vulnerability exposure erodes customer trust.

### Timeline

- **Sep 2022** — Commission presents the proposal
- **10 Dec 2024** — CRA enters into force
- **11 Jun 2026** — Notified-body provisions apply (Chapter IV)
- **11 Sep 2026** — Reporting obligations begin — Art. 14 (~21 mo)
- **11 Dec 2027** — Main requirements start to apply (~36 mo)

---

## 04 Annex I — the 22 essential requirements

Annex I splits into two parts: Part I governs how the product is designed, built, and deployed; Part II governs how vulnerabilities are managed across the lifecycle.

### Part I — Design & deployment · 14

- I.1 — Secure by design, based on risk
- I.2a — No known exploitable vulnerabilities
- I.2b — Secure-by-default configuration
- I.2c — Timely security updates
- I.2d — Protection from unauthorized access
- I.2e — Confidentiality of data (encryption)
- I.2f — Integrity of data & commands
- I.2g — Data minimization
- I.2h — Availability of essential functions
- I.2i — Minimize impact on other networks
- I.2j — Attack surface reduction
- I.2k — Incident impact mitigation
- I.2l — Security event monitoring & logging
- I.2m — Secure data deletion & transfer

### Part II — Vulnerability management · 8

- II.1 — SBOM & component tracking
- II.2 — Rapid vulnerability remediation
- II.3 — Regular security testing
- II.4 — Public vulnerability disclosure
- II.5 — Coordinated disclosure policy
- II.6 — Share potential vulnerability info
- II.7 — Secure update distribution
- II.8 — Timely, free security updates

> **The thread that ties it together.** Most Part II obligations start with a software bill of materials. You cannot remediate, disclose, or update against vulnerabilities in components you have not inventoried.

Beyond Annex I, manufacturers must also prepare technical documentation (Annex VII) and user information and instructions (Annex II), draw up the EU declaration of conformity (Annex V), and complete the applicable conformity assessment (Article 32; Annex VIII) before CE marking. Important (Annex III) and critical (Annex IV) products face stricter routes — Class II important and critical products must undergo third-party conformity assessment.

---

## 05 How Ketryx supports CRA compliance

The CRA turns cybersecurity into a lifecycle obligation with an evidentiary burden — you must not only be secure, but be able to prove and sustain it under audit. Ketryx is the application lifecycle and compliance platform that becomes your system of record for that evidence: requirements, risks, tests, SBOMs, and approvals, all traced to the regulation and kept continuously current.

| CRA obligation | How Ketryx helps | Maps to |
| --- | --- | --- |
| Secure by design, based on risk | Structured risk management with hazards, controls, and requirements traced end-to-end — the same rigor teams use for ISO 14971. | I.1 |
| SBOM & known vulnerabilities | Generate a machine-readable SBOM and monitor components for new CVEs, flagging affected products as disclosures land. | I.2a, II.1 |
| Vulnerability handling & remediation | Track each vulnerability through triage, remediation, verification, and controlled release — with change control and a complete audit trail. | II.2 |
| Testing & verification evidence | Manage security tests and reviews, link results to requirements and risks, and keep a live traceability matrix ready for inspection. | II.3 |
| Disclosure & reporting processes | Enforce a coordinated-disclosure policy as a controlled workflow with approvals and e-signatures, producing defensible records for reporting. | II.4–6 |
| Technical documentation & conformity | Assemble the technical file and declaration of conformity from live artifacts, so CE evidence is generated, not reconstructed. | Annex V, VII, VIII |

> **Ketryx Intelligence.** Draft requirements and risk controls directly from the regulation text. You review and approve each one before it becomes part of the record — the human stays in the loop.

> **Stays manufacturer-owned.** Executing security tests, publishing disclosures, and securing the device at runtime remain your responsibility. Ketryx gives them structure, traceability, and proof.

---

## 06 In practice: two CRA scenarios

Manufacturers face different CRA pressures depending on what they build. Two representative scenarios show where the evidentiary work concentrates — and where Ketryx fits.

### Networking & infrastructure — Enterprise networking vendor

**Scenario.** A vendor ships routers, switches, and firewalls with embedded firmware into the EU — long-lived infrastructure squarely in CRA scope.

**Challenges.**
- Firewalls and network management rank as important products (Annex III), triggering third-party conformity assessment.
- Large open-source and third-party software stacks make SBOM accuracy and CVE response hard at scale.

**How Ketryx helps.**
- Maintain a machine-readable SBOM per product line and monitor dependencies for new CVEs across long support windows.
- Trace secure-by-design requirements, tests, and risks into evidence a notified body can review.

**Outcome.** Conformity evidence and vulnerability response scale across a broad, long-lived product portfolio.

### Consumer electronics — Smart-home device maker

**Scenario.** A company makes smart thermostats and cameras for the EU — digital elements, updates, and connectivity.

**Challenges.**
- Products must ship with no known exploitable vulnerabilities and secure-by-default settings.
- Consumer privacy requires strict data minimization.

**How Ketryx helps.**
- Verify "no known vulnerabilities" with SBOM scanning gated before each release.
- Document secure-default and data-minimization decisions as traceable requirements and risks.

**Outcome.** A defensible conformity record and CE technical file that support smooth EU market entry.

> **The common thread.** Ketryx does not secure the device at runtime — it makes the conformity behind every device provable, traceable, and durable enough to withstand an audit years later.

---

## 07 How to get started

CRA readiness is a program, not a project. These six steps move you from "are we in scope?" to a defensible, continuously maintained compliance posture.

1. **Applicability assessment** — Confirm whether the CRA applies to each product and where it sits.
2. **Categorize & gap-assess** — Classify products and benchmark current processes against Annex I.
3. **Bring into compliance** — Run risk assessment and close gaps against the essential requirements.
4. **Prepare documentation** — Assemble the technical file and user instructions from live evidence.
5. **Conformity & CE marking** — Complete the assessment, declaration of conformity, and CE marking.
6. **Continuous monitoring** — Sustain reporting, vulnerability handling, and update obligations.

**Ready to build CRA evidence that lasts?** ketryx.com

Ketryx powers faster, safer product development. Its continuous-compliance, AI-native platform automates documentation and compliance across existing tools, cutting manual work by 90% and accelerating high-quality, audit-ready releases. Learn more at ketryx.com.

> **About this guide.** This document is an educational overview of Regulation (EU) 2024/2847 and does not constitute legal advice. Refer to the official regulation text for authoritative requirements.
>
> Ketryx helps regulated and safety-critical teams turn compliance into a living system of record — traced, auditable, and always current.
