Kilde › Guides › EU Cyber Resilience Act guides: the 20…

EU Cyber Resilience Act guides: the 2026 reporting duty and all 26 listed categories

Current to 26 August 2026 · updates land in the changelog.

Since 11 September 2026, the EU Cyber Resilience Act's first live obligation has been in force: the Article 14 reporting duty — a 24-hour early warning, a 72-hour notification and a final report for actively exploited vulnerabilities and severe incidents, covering the whole in-scope installed base. Full application, with conformity assessment and CE marking, follows on 11 December 2027. These guides map the regime page by page: the law's own words, plain-language readings, and what to prepare.

Start here

The duty, stage by stage — and around it

Is your product “important” or “critical”? All 26 listed categories

Annex III and Annex IV list the product categories with elevated conformity treatment — read verbatim from the Official Journal text, one guide per category:

Important — Class I (19 categories)Identity Management & PAM Products, Standalone & Embedded Browsers, Password Managers, Anti-Malware & Malware-Removal Software, VPN Products, Network Management Systems, SIEM Systems, Boot Managers, PKI & Certificate-Issuance Software, Physical & Virtual Network Interfaces, Operating Systems, Routers, Modems & Switches, Microprocessors With Security Functionality, Microcontrollers With Security Functionality, ASICs & FPGAs With Security Functionality, Smart Home Virtual Assistants, Smart Locks, Cameras, Baby Monitors & Alarms, Internet-Connected Toys, Health Wearables & Children's Wearables
Important — Class II (4)Hypervisors & Container Runtimes, Firewalls & Intrusion Detection/Prevention Systems, Tamper-Resistant Microprocessors, Tamper-Resistant Microcontrollers
Critical — Annex IV (3)Hardware Devices With Security Boxes, Smart Meter Gateways & Advanced-Security Devices, Smartcards & Secure Elements

Not listed? The product is default tier — self-assessed conformity, but the same reporting clocks. Scope questions (software, SaaS, open source, exclusions) are covered in the scope guide.

What's free here — and what the pack adds

These guides (free)The duties, clocks, definitions and all 26 listed categories — verbatim where the law speaks, dated readings where it doesn't.
The CRA Reporting-Ready Pack (US$390)The execution layer: the staged 24h/72h/final runbook with drills, report templates mapped to the platform's field matrix, the triage and CSIRT-routing worksheets, the CVD policy, the evidence log, the platform onboarding runbook, the guidance crosswalk, and the paid update tracker.

The guides carry the rules, dates and definitions — kept current, no signup. The pack carries the documents you would otherwise build from scratch. See the shape first: free 4-page sample (PDF) · full contents.

Quick answers

What is the first Cyber Resilience Act deadline?
11 September 2026 — the Article 14 reporting duty: a 24-hour early warning, 72-hour notification and final report for actively exploited vulnerabilities and severe incidents, covering in-scope products already on the market as well as new ones.
Does the CRA apply to products sold before 2027?
For the reporting duty, yes: Article 69(3) applies Article 14 to all in-scope products placed on the market before 11 December 2027. The full requirements apply to such products only upon substantial modification.
Which products count as important or critical under the CRA?
Annex III lists 19 important Class I and 4 Class II categories (browsers, password managers, VPN products, operating systems, firewalls, hypervisors and more); Annex IV lists 3 critical categories (security boxes, smart meter gateways, smartcards and secure elements).
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com