The Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity rules for hardware and software products sold in the EU. Reporting obligations have applied since 11 September 2026, and the rest applies from 11 December 2027. Teddy's agents classify your products, map the essential requirements and keep vulnerability handling and reporting ready.

The CRA is an EU regulation and applies directly. It covers products with digital elements made available on the EU market, from connected devices to installable software. Most duties fall on manufacturers, with further duties for importers and distributors. Here is what it asks for and where it lives in Teddy.
Check which products are in scope and whether each is a default, important (class I or II) or critical product. The class decides the conformity route.
Each product is designed, developed and produced on the basis of a cybersecurity risk assessment and meets the essential requirements, such as secure defaults and protection against unauthorised access.
An SBOM covering at least top-level dependencies, a coordinated vulnerability disclosure policy and security updates provided free of charge during the support period.
Manufacturers set a support period that reflects how long the product is expected to be used, generally at least five years, and handle vulnerabilities effectively during it.
Actively exploited vulnerabilities and severe incidents are reported through ENISA's single reporting platform to the coordinating CSIRT and ENISA: an early warning within 24 hours, a notification within 72 hours, then a final report.
Technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking before a product is placed on the market.
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. From December 2027, every product placed on the market has to meet the essential requirements.
Teddy classifies every product and shows how it has to be assessed.
One named owner and a tested process for reports via the ENISA platform.
Risk assessment, list of software components (SBOM) and update period, tracked for each release.
An exploited vulnerability hits the gateway firmware, product says security owns it, security says legal files reports, and the SBOM is a spreadsheet from last year. ChatGPT can explain Art. 14, but it does not know your products. Teddy maps each product to its obligations and runs the reporting process with named owners.
Kai · FirmwareA flaw in our TLS library is being exploited. Do we report?
Lea · ProductIsn’t that security’s job?
Sabine · LegalWho registered us on the ENISA platform?
Erik · SalesA customer asks for our support period.
Nadine · CEOIs our router an important product?
Teddy's agents classify, map and track per product. Product and security teams decide, and a compliance engineer is there for classification questions and notified bodies.
Teddy builds the product inventory and proposes a class for each product with the reasoning, so product and legal can confirm it.
Each product is checked against Annex I. Controls you already run for ISO 27001, such as secure development and incident handling, count where they apply.
The Evidence Agent collects SBOMs from connected repositories and watches for vulnerabilities in the components you ship.
The Policy Agent drafts the Art. 14 process with roles, criteria and templates, so everyone knows who decides and who files.
Risk assessment, Annex I mapping, SBOM and support period come together as the technical documentation for your conformity assessment.
Ask in plain language whether a vulnerability is reportable or which class a product has. Teddy answers from your live product inventory. For notified bodies and authorities, our compliance engineers are at your side.
Ask TeddyIs this reportable? Which class is our product? Teddy knows the CRA and your products.
Agents do the workClassification, Annex I mapping, SBOM tracking and report templates, each with its source.
Our team backs you upCompliance engineers help with product classification, notified bodies and reporting.
Pure SaaS is generally outside the CRA. Remote data processing that a product needs to perform its functions is in scope as part of that product. Teddy checks each product and its cloud components.
The reporting obligations under Art. 14 have applied since 11 September 2026, also for products placed on the market earlier. The essential requirements and the CE marking apply to products placed on the market from 11 December 2027.
It depends on the class. Default products can use internal control. Important class I products can too if they apply harmonised standards or certification schemes in full. Class II and critical products need a third-party assessment or a European certification scheme.
Your ISMS covers organisational controls such as incident handling, secure development and supplier security. The CRA adds duties per product: risk assessment, SBOM, support period, technical documentation and CE marking.
Start with a product inventory and a gap audit against Annex I.
Reviewed by Sven Moritz, former CISO · October 2026
Fewer than half of manufacturers expect to be fully compliant by December 2027. Awareness is high, readiness stays low.
Products classified, Annex I mapped, SBOMs and support periods tracked and an Art. 14 reporting process in place, well before December 2027.
The reporting duties have applied since September 2026, more than a year before full application. They also continue after a product's support period ends.
Registration on the platform takes time, and reporting is a manual workflow for now. Register only when it happens, and the first hours go to setup instead of the report.
It decides how long you must handle vulnerabilities and ship updates. Agree on it with the teams who have to deliver, before you publish it.