← Back to feed
Policy & RegulationEmerging1 sourceJul 30, 2026 · 14:26via Mend.io Blog

EU CRA explained: requirements, timeline, and compliance

Brief

What is the EU Cyber Resilience Act (EU CRA)?

The EU Cyber Resilience Act (CRA) is a sweeping regulation that mandates security by design and uniform cybersecurity standards for all hardware and software products with digital elements sold in the European Union.

The CRA officially entered into force in December 2024, with compliance enforcement phased in over the coming years:

  • September 11, 2026: Mandatory vulnerability and incident reporting obligations take effect for manufacturers.
  • December 11, 2027: Full compliance becomes mandatory, requiring CE markings, technical documentation, and detailed risk assessments for all covered products.

Under the EU CRA, manufacturers, importers, and distributors are responsible for making sure their products comply with these cybersecurity requirements before being made available in the EU.

Read more on Mend.io Blog→