The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal cybersecurity law covering all products with digital elements placed on the EU market — hardware, software, and their remote data-processing solutions. Its timeline is already running, and it’s closer than it looks:
● 11 June 2026 — the regime for designating conformity assessment bodies (Chapter IV) becomes applicable
● 11 September 2026 — reporting obligations for actively exploited vulnerabilities apply
● 11 December 2027 — the Regulation applies in its entirety
The real and the most structuring question is: which category do your products and services actually fall into?
A four-tier classification — and an entry point that isn’t always obvious
The CRA distinguishes four product categories, each carrying its own set of obligations: a “default” category covering the majority of digital products, and three heightened-risk categories — Important Class I, Important Class II, and Critical — which together cover more than twenty explicitly listed product types (identity management systems, SIEM systems, hypervisors, firewalls, hardware security modules, to name just a few).
What determines the category isn’t a product’s commercial name, or even its perceived complexity: it’s its core functionality, assessed objectively. And that’s exactly where many organizations get it wrong — in both directions:
● some assume the ‘Default’ category applies without genuinely testing that assumption against the Regulation’s technical criteria;
● others overestimate their obligations and commit to costly, unnecessary certification processes;
● many discover too late that the way their solution is deployed — hosted SaaS, on-premise, with or without a local component — fundamentally changes the scope analysis, regardless of what the product itself does.
Why this classification changes everything
Once the category is determined, the resulting compliance pathway is far from neutral. Depending on the classification, an organization will either carry out a self-assessment under its own responsibility, or undergo mandatory third-party audit by a notified body — with direct implications for cost, timeline, and the technical documentation that must be produced and retained.
And regardless of which category applies, once a product falls within CRA scope, the vulnerability-reporting clock starts ticking: an early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days for actively exploited vulnerabilities. These reporting obligations (Article 14) apply from 11 September 2026.
The real starting point: a rigorous inventory, not an assumption
At Axon Advisory & Consulting, we support organizations to establish inventory of the products and services placed on the EU market, a defensible classification against the CRA’s technical criteria, and a clear rationale for the certification pathway that follows. Where self-assessment applies, we can carry the exercise through with you end to end — technical file, risk assessment and declaration of conformity included. Where a third-party audit is required instead, our role is to get you there fully prepared: closing documentation gaps and building the technical file and vulnerability-handling policy the audit will expect.
If your organization develops, distributes or integrates products with digital elements, the question is no longer whether the CRA applies to you, but precisely how.
Let’s talk. The Axon Advisory & Consulting team can help you inventory, classify, and prepare your CRA compliance pathway.
#CyberResilienceAct #CRA #Cybersecurity #EURegulation #RiskManagement #Compliance #AxonAdvisory