Kilde › Guides › CRA › The CRA essential requirements: the 20…

The CRA essential requirements: the 2027 set, mapped for planning

Current to 26 August 2026 · updates land in the changelog.

From 11 December 2027, in-scope products placed on the EU market must meet the essential requirements of Annex I Part I — the engineering half of the CRA. Where the 2026 reporting duty is procedural readiness, this set is product work, sized in quarters — which is why the planning window is now.

The requirements, grouped for planning

Alongside Part I sits Part II's vulnerability-handling process set — SBOM, CVD policy, disclosure, free security patches — which is continuous rather than at-placement.

How the requirements meet conformity

The essential requirements are what conformity assessment assesses against: default products self-assess, Class I needs harmonised standards for the self-route (none cited yet — the paperwork guide covers what that means for documentation), Class II always sees a notified body. The requirements are identical across classes; classification changes who checks, not what is checked.

Sequencing from here

Three orderings that survive contact with reality: run the gap assessment against the requirement list before committing the 2027 roadmap; treat “no known exploitable vulnerabilities at placement” as a release-process change (it needs a gate, not a policy); and let the SBOM and component work start first, because everything else consumes its output. Products already in the field are governed by the substantial-modification rule rather than retroactivity.

Related guides

Quick answers

When do the CRA's essential requirements apply?
From 11 December 2027, for products with digital elements placed on the EU market — with pre-2027 products pulled in only upon substantial modification. The Article 14 reporting duty applies much earlier (11 September 2026) and independently.
Can a product ship with known vulnerabilities under the CRA?
Products must be made available without known exploitable vulnerabilities at placement — pre-release triage becomes a compliance gate, not just good practice.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com