EUEuropean UnionPhasing inCRA

How an AI product complies with the Cyber Resilience Act

Cyber Resilience Act (EU) 2024/2847

Status
Phasing in
Binding
Yes
Object analysed
Digital product
Requirements
5
Next milestone
Dec 11, 2027

In short

Cybersecurity requirements for products with digital elements, including AI systems. A high-risk system meeting the CRA is presumed compliant with AI Act Art. 15.

Steps to compliance

  1. Qualify each AI systemAxes to decide: Product class.
  2. Determine your roleDuties vary by role: Manufacturer and Importer.
  3. Apply the 5 requirementsThey focus on: Cybersecurity, Post-deployment monitoring, Incidents & corrective action and Quality & conformity.
  4. Prove it with checks9 checks to document, 8 of which also serve AI Act, PL 2338 and ISO 42001.
  5. Track the deadlinesNext milestone: Dec 11, 2027, Full application (set in the text).

Scope and penalties

Kind
Regulation
Scope
Manufacturers, importers, distributors of digital products.
Territorial reach
Products placed on the EU market.
Penalties
Up to €15M or 2.5% of worldwide turnover.
Jurisdiction
European Union

Timeline

Dec 10, 2024Entry into force
Jun 11, 2026Conformity assessment bodies
Sep 11, 2026Reporting obligations (vulnerabilities, incidents)
Release
Dec 11, 2027Full applicationSet in the text
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Product class

CriticalImportant class IIImportant class IDefault

Requirements

5 requirements

CodeArticleRequirementApplies toChecks
CRA-I.1Annex I part IEssential requirements: secure by design, no known exploitable vulnerabilities
Manufacturer
CRA-I.2Annex I part IIVulnerability handling: SBOM, updates over the support period
Manufacturer
CRA-14Art. 14Report actively exploited vulnerabilities and severe incidents (24h / 72h / 14d)
Manufacturer
CRA-28Art. 28, 30, 32Conformity assessment, EU declaration, CE marking
Manufacturer
CRA-31Art. 31, Annex VIITechnical documentation and user information
Manufacturer

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-009-F-04Resilience to adversarial attacks testedModel
NEW-CRA-01System SBOM maintained proposedSystem
—
VER-022-F-01Risk and incident response procedureOrganisation
VER-024-F-01Conformity assessment procedure performed (Annex VI or VII)System
VER-AUTO-03EU declaration of conformity draftedSystem
VER-016-F-01CE marking affixed in accordance with Art. 48System
VER-005-01Complete technical documentation compliant with Annex IVSystem
VER-007-01Instructions for use complete and compliant with Art. 13System

Themes covered

Frequently asked questions

Who is in scope of CRA?

Manufacturers, importers, distributors of digital products. Products placed on the EU market.

What penalties does CRA carry?

Up to €15M or 2.5% of worldwide turnover.

When do the CRA obligations apply?

Jun 11, 2026: Conformity assessment bodies; Sep 11, 2026: Reporting obligations (vulnerabilities, incidents); Dec 11, 2027: Full application.

Is CRA binding?

Yes. Kind: regulation. Status: phasing in.

How does CRA relate to other regulations?

The same checks serve several texts. Shared checks: AI Act (8), PL 2338 (4) and ISO 42001 (3).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo