How an AI product complies with the Cyber Resilience Act
Cyber Resilience Act (EU) 2024/2847
- Status
- Phasing in
- Binding
- Yes
- Object analysed
- Digital product
- Requirements
- 5
- Next milestone
- Dec 11, 2027
In short
Cybersecurity requirements for products with digital elements, including AI systems. A high-risk system meeting the CRA is presumed compliant with AI Act Art. 15.
Steps to compliance
- Qualify each AI systemAxes to decide: Product class.
- Determine your roleDuties vary by role: Manufacturer and Importer.
- Apply the 5 requirementsThey focus on: Cybersecurity, Post-deployment monitoring, Incidents & corrective action and Quality & conformity.
- Prove it with checks9 checks to document, 8 of which also serve AI Act, PL 2338 and ISO 42001.
- Track the deadlinesNext milestone: Dec 11, 2027, Full application (set in the text).
Scope and penalties
- Kind
- Regulation
- Scope
- Manufacturers, importers, distributors of digital products.
- Territorial reach
- Products placed on the EU market.
- Penalties
- Up to €15M or 2.5% of worldwide turnover.
- Jurisdiction
- European Union
Timeline
Qualifying a system
Classification axes and possible verdicts
Product class
Requirements
5 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| CRA-I.1 | Annex I part I | Essential requirements: secure by design, no known exploitable vulnerabilities | ||
| CRA-I.2 | Annex I part II | Vulnerability handling: SBOM, updates over the support period | ||
| CRA-14 | Art. 14 | Report actively exploited vulnerabilities and severe incidents (24h / 72h / 14d) | ||
| CRA-28 | Art. 28, 30, 32 | Conformity assessment, EU declaration, CE marking | ||
| CRA-31 | Art. 31, Annex VII | Technical documentation and user information |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-009-F-04 | Resilience to adversarial attacks tested | Model | ||
| NEW-CRA-01 | System SBOM maintained proposed | System | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| VER-024-F-01 | Conformity assessment procedure performed (Annex VI or VII) | System | ||
| VER-AUTO-03 | EU declaration of conformity drafted | System | ||
| VER-016-F-01 | CE marking affixed in accordance with Art. 48 | System | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | System | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | System |
Themes covered
Frequently asked questions
Who is in scope of CRA?
Manufacturers, importers, distributors of digital products. Products placed on the EU market.
What penalties does CRA carry?
Up to €15M or 2.5% of worldwide turnover.
When do the CRA obligations apply?
Jun 11, 2026: Conformity assessment bodies; Sep 11, 2026: Reporting obligations (vulnerabilities, incidents); Dec 11, 2027: Full application.
Is CRA binding?
Yes. Kind: regulation. Status: phasing in.
How does CRA relate to other regulations?
The same checks serve several texts. Shared checks: AI Act (8), PL 2338 (4) and ISO 42001 (3).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.