Agentic compliance for the CRA

The Cyber Resilience Act, from product inventory to CE marking.

The Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity rules for hardware and software products sold in the EU. Reporting obligations have applied since 11 September 2026, and the rest applies from 11 December 2027. Teddy's agents classify your products, map the essential requirements and keep vulnerability handling and reporting ready.

24 hoursEarly warning via ENISA’s reporting platform, prepared
Per productSecurity requirements checked
One overviewProduct class, components and update period
What the CRA asks for

Six obligations for manufacturers.
Each one has a home in Teddy.

The CRA is an EU regulation and applies directly. It covers products with digital elements made available on the EU market, from connected devices to installable software. Most duties fall on manufacturers, with further duties for importers and distributors. Here is what it asks for and where it lives in Teddy.

Art. 7 and 8, Annexes III and IVScope and product class

Check which products are in scope and whether each is a default, important (class I or II) or critical product. The class decides the conformity route.

In TeddyProduct inventory with a class per product
Art. 13, Annex I Part ISecurity by design

Each product is designed, developed and produced on the basis of a cybersecurity risk assessment and meets the essential requirements, such as secure defaults and protection against unauthorised access.

In TeddyRequirements mapped per product, with evidence
Annex I Part IIVulnerability handling

An SBOM covering at least top-level dependencies, a coordinated vulnerability disclosure policy and security updates provided free of charge during the support period.

In TeddySBOM and disclosure process tracked
Art. 13(8)Support period

Manufacturers set a support period that reflects how long the product is expected to be used, generally at least five years, and handle vulnerabilities effectively during it.

In TeddySupport periods recorded per product
Art. 14Reporting

Actively exploited vulnerabilities and severe incidents are reported through ENISA's single reporting platform to the coordinating CSIRT and ENISA: an early warning within 24 hours, a notification within 72 hours, then a final report.

In TeddyReporting process and templates, with named owners
Art. 28 and 30, Annex VIIConformity and CE marking

Technical documentation, a conformity assessment, the EU declaration of conformity and the CE marking before a product is placed on the market.

In TeddyTechnical documentation assembled from your evidence
10 Dec 2024In forceRegulation (EU) 2024/2847
11 Sep 2026Reporting appliesArt. 14, also for products already on the market
11 Dec 2027Full applicationEssential requirements and CE marking
Per productSupport periodGenerally at least five years
The problem

Reporting duties are live.
Product rules follow in 2027.

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. From December 2027, every product placed on the market has to meet the essential requirements.

01The class of each product

Teddy classifies every product and shows how it has to be assessed.

02Who reports a vulnerability

One named owner and a tested process for reports via the ENISA platform.

03Documentation per product

Risk assessment, list of software components (SBOM) and update period, tracked for each release.

04Product teams, a ticking clock and an AI chat. Still no owner.

An exploited vulnerability hits the gateway firmware, product says security owns it, security says legal files reports, and the SBOM is a spreadsheet from last year. ChatGPT can explain Art. 14, but it does not know your products. Teddy maps each product to its obligations and runs the reporting process with named owners.

How it works

From a product list to products you can place on the market

Teddy's agents classify, map and track per product. Product and security teams decide, and a compliance engineer is there for classification questions and notified bodies.

01 Gap Audit Agent

Classify every product

Teddy builds the product inventory and proposes a class for each product with the reasoning, so product and legal can confirm it.

Product inventory · Acme Inc.Draft
Acme Gateway · routerImportant, class I
Acme Desktop AgentDefault
Acme AppDefault
Teddy: Routers are listed in Annex III, class I. Without a harmonised standard applied in full, a third-party assessment is needed.
02 Gap Audit Agent

Essential requirements per product

Each product is checked against Annex I. Controls you already run for ISO 27001, such as secure development and incident handling, count where they apply.

Annex I · Acme GatewayGap audit
Part I requirements met11 of 13
SBOM, top-level dependenciesPartial
Coordinated disclosure policyMissing
03 Evidence Agent

SBOM and vulnerabilities from your repositories

The Evidence Agent collects SBOMs from connected repositories and watches for vulnerabilities in the components you ship.

Acme GatewayFirmware 4.2
gateway-firmware · SBOMCollected
Known exploited vulnerabilities1 open
Support period5 years
Teddy: The TLS library in gateway-firmware has an actively exploited vulnerability. This may be reportable under Art. 14.
04 Policy Agent

A reporting process with owners

The Policy Agent drafts the Art. 14 process with roles, criteria and templates, so everyone knows who decides and who files.

Art. 14 reportingENISA platform
Early warning · 24 hoursTemplate ready
Notification · 72 hoursTemplate ready
Final reportTemplate ready
Teddy: Security decides whether a vulnerability is actively exploited. Legal submits through the ENISA platform.
05 Certification Agent

From evidence to technical documentation

Risk assessment, Annex I mapping, SBOM and support period come together as the technical documentation for your conformity assessment.

Technical documentationAnnex VII
Cybersecurity risk assessmentApproved
Annex I mappingLinked
EU declaration of conformityDraft
Never stuck

Is this exploited vulnerability reportable? Ask Teddy, then report.

Ask in plain language whether a vulnerability is reportable or which class a product has. Teddy answers from your live product inventory. For notified bodies and authorities, our compliance engineers are at your side.

1

Ask TeddyIs this reportable? Which class is our product? Teddy knows the CRA and your products.

2

Agents do the workClassification, Annex I mapping, SBOM tracking and report templates, each with its source.

3

Our team backs you upCompliance engineers help with product classification, notified bodies and reporting.

TeddyAcme Inc. · CRA
Is the exploited TLS flaw in our gateway reportable?
Likely yes. An actively exploited vulnerability in a product on the EU market is reportable under Art. 14, also if the product was placed on the market before December 2027.
  • Early warningWithin 24 hours
  • NotificationWithin 72 hours
  • Final report14 days after a fix
Shall I start the early warning and alert Legal?
Start early warningAsk our team
CEYour compliance engineer helps with classification and notified bodies.
FAQ

Questions about the CRA

Does the CRA apply to SaaS?

Pure SaaS is generally outside the CRA. Remote data processing that a product needs to perform its functions is in scope as part of that product. Teddy checks each product and its cloud components.

What applies before December 2027?

The reporting obligations under Art. 14 have applied since 11 September 2026, also for products placed on the market earlier. The essential requirements and the CE marking apply to products placed on the market from 11 December 2027.

Do we need a notified body?

It depends on the class. Default products can use internal control. Important class I products can too if they apply harmonised standards or certification schemes in full. Class II and critical products need a third-party assessment or a European certification scheme.

We have ISO 27001. How much counts?

Your ISMS covers organisational controls such as incident handling, secure development and supplier security. The CRA adds duties per product: risk assessment, SBOM, support period, technical documentation and CE marking.

Every product mapped. Every report on time.

Start with a product inventory and a gap audit against Annex I.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long CRA readiness takes, and how Teddy cuts it to weeks

TypicalYears, not months

Fewer than half of manufacturers expect to be fully compliant by December 2027. Awareness is high, readiness stays low.

With TeddyWithin weeks

Products classified, Annex I mapped, SBOMs and support periods tracked and an Art. 14 reporting process in place, well before December 2027.

  • Products already on the market: the product rules generally reach them only after a substantial modification. The reporting duties apply to them now.
  • Fines for reporting breaches: up to €15 million or 2.5% of worldwide turnover.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

Where manufacturers get the CRA wrong

  1. “The CRA is a 2027 problem.”

    The reporting duties have applied since September 2026, more than a year before full application. They also continue after a product's support period ends.

  2. The reporting account is set up during the first incident.

    Registration on the platform takes time, and reporting is a manual workflow for now. Register only when it happens, and the first hours go to setup instead of the report.

  3. The support period is set by marketing, not by engineering.

    It decides how long you must handle vulnerabilities and ship updates. Agree on it with the teams who have to deliver, before you publish it.