Kilde › Guides › EU Cyber Resilience Act guides: the 20…
EU Cyber Resilience Act guides: the 2026 reporting duty and all 26 listed categories
Current to 26 August 2026 · updates land in the changelog.
Since 11 September 2026, the EU Cyber Resilience Act's first live obligation has been in force:
the Article 14 reporting duty — a 24-hour early warning, a 72-hour notification and a final report
for actively exploited vulnerabilities and severe incidents, covering the whole in-scope installed
base. Full application, with conformity assessment and CE marking, follows on 11 December 2027.
These guides map the regime page by page: the law's own words, plain-language readings, and what to
prepare.
Start here
The duty, stage by stage — and around it
- The CRA 24-hour early warning: what goes in it, and when the clock starts
- The CRA 72-hour notification: what stage two must contain
- The CRA final report: 14 days or one month — measured from when?
- “Actively exploited vulnerability” vs “severe incident”: the two triggers, precisely
- Legacy products under the CRA: why the whole installed base reports from 11 September 2026
- The CRA timeline: what starts 11 September 2026, and what waits for 2027
- Who reports under the CRA — and which CSIRT receives it
- The CRA single reporting platform: registration, status, and what to pre-stage
- Notifying users under Article 14(8): the duty beyond the authorities
- CRA penalties: where Article 14 sits in the fine structure
- CRA scope: software, SaaS, open source and the exclusions
- CRA conformity routes by class — and the Class I gap nobody prices in
- The CRA support period: the five-year floor and the ten-year tail
- CRA vulnerability handling: the Annex I Part II duties, mapped
- The CRA essential requirements: the 2027 set, mapped for planning
- The CRA's SBOM requirement: what it demands, and the two things it doesn't
- The CRA's paperwork layer: which annex holds what, and what's still missing
- Substantial modification: the rule that decides when your old products re-enter the CRA
- Open source under the CRA: where the commercial line runs, and what stewards get
Is your product “important” or “critical”? All 26 listed categories
Annex III and Annex IV list the product categories with elevated conformity treatment — read
verbatim from the Official Journal text, one guide per category:
| Important — Class I (19 categories) | Identity Management & PAM Products, Standalone & Embedded Browsers, Password Managers, Anti-Malware & Malware-Removal Software, VPN Products, Network Management Systems, SIEM Systems, Boot Managers, PKI & Certificate-Issuance Software, Physical & Virtual Network Interfaces, Operating Systems, Routers, Modems & Switches, Microprocessors With Security Functionality, Microcontrollers With Security Functionality, ASICs & FPGAs With Security Functionality, Smart Home Virtual Assistants, Smart Locks, Cameras, Baby Monitors & Alarms, Internet-Connected Toys, Health Wearables & Children's Wearables |
|---|
| Important — Class II (4) | Hypervisors & Container Runtimes, Firewalls & Intrusion Detection/Prevention Systems, Tamper-Resistant Microprocessors, Tamper-Resistant Microcontrollers |
|---|
| Critical — Annex IV (3) | Hardware Devices With Security Boxes, Smart Meter Gateways & Advanced-Security Devices, Smartcards & Secure Elements |
|---|
Not listed? The product is default tier — self-assessed conformity, but the
same reporting clocks. Scope questions (software,
SaaS, open source, exclusions) are covered in the
scope guide.
What's free here — and what the pack adds
| These guides (free) | The duties, clocks, definitions and all 26 listed categories — verbatim where the law speaks, dated readings where it doesn't. |
| The CRA Reporting-Ready Pack (US$390) | The execution layer: the staged 24h/72h/final runbook with drills, report templates mapped to the platform's field matrix, the triage and CSIRT-routing worksheets, the CVD policy, the evidence log, the platform onboarding runbook, the guidance crosswalk, and the paid update tracker. |
The guides carry the rules, dates and definitions — kept current, no signup. The pack carries the
documents you would otherwise build from scratch. See the shape first:
free 4-page sample (PDF) ·
full contents.
Quick answers
- What is the first Cyber Resilience Act deadline?
- 11 September 2026 — the Article 14 reporting duty: a 24-hour early warning, 72-hour notification and final report for actively exploited vulnerabilities and severe incidents, covering in-scope products already on the market as well as new ones.
- Does the CRA apply to products sold before 2027?
- For the reporting duty, yes: Article 69(3) applies Article 14 to all in-scope products placed on the market before 11 December 2027. The full requirements apply to such products only upon substantial modification.
- Which products count as important or critical under the CRA?
- Annex III lists 19 important Class I and 4 Class II categories (browsers, password managers, VPN products, operating systems, firewalls, hypervisors and more); Annex IV lists 3 critical categories (security boxes, smart meter gateways, smartcards and secure elements).
Be reporting-ready before 11 September 2026.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook
and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment
worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation
and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390
Free 4-page sample (PDF)
Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment.
Whether a specific product falls in a listed category is decided against the binding technical
descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are
ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX
32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research.
© 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com