The Regulation uses a broad definition of a product with digital elements, covering software, hardware and their remote data processing solutions. The manufacturer must meet the Annex I essential requirements, carry out and document a risk assessment, complete conformity assessment, draw up an EU declaration of conformity, affix the CE marking and state a support period of at least five years at the point of sale. Actively exploited vulnerabilities and severe incidents go to the coordinating CSIRT and ENISA within 24 hours. (As of July 2026)
Manufacturers selling into the EU
A company established in Türkiye is the manufacturer and carries the Article 13 and Article 14 duties itself.
Software and firmware suppliers
Components placed on the market separately are in scope; open-source software supplied outside a commercial activity is not.
Connected hardware producers
Routers, smart home devices and firewalls fall into the Annex III classes and may require third-party assessment.
- 01Carry out a risk assessment under Article 13(2)–(3) and document it in the technical file; the Annex I requirements build on it.
- 02Complete conformity assessment and CE marking before placing the product on the market; a notified body is mandatory for Class II and critical products.
- 03Report under Article 14 with an early warning within 24 hours, notification within 72 hours and a final report on the prescribed timetable.
- 04Declare and honour a support period of at least five years, disclosed at the point of sale, with security updates available for at least ten years.
Overview
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847 — a Regulation, directly applicable in the Member States, so no national transposition is awaited. It requires products with digital elements to meet defined cybersecurity requirements before being placed on the market and to remain secure across their lifecycle. It entered into force on 10.12.2024, with obligations phased.
Scope and product classes
Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. The definition is deliberately broad: standalone software, firmware, connected hardware and manufacturer-designed remote components all fall within it. Free and open-source software supplied outside a commercial activity is out of scope.
Conformity runs in four tiers. Default products self-assess (Module A). Annex III Class I important products — password managers, VPNs, boot managers, routers, smart home assistants — may self-assess only where harmonised standards or an EU cybersecurity certification scheme are fully applied; otherwise third-party assessment is required. Annex III Class II products (firewalls, hypervisors, tamper-resistant microcontrollers and microprocessors) always require third-party assessment, and Annex IV critical products (hardware security modules, smart meter gateways, smartcards) face the strictest regime. Classification must be carried out against the technical definitions in Implementing Regulation (EU) 2025/2392, not the Annex headings.
Key obligations
The manufacturer must carry out a cybersecurity risk assessment (Article 13(2)–(3)), satisfy the Annex I essential requirements, compile technical documentation, complete the applicable conformity route (Module A, B+C or H), draw up an EU declaration of conformity and affix the CE marking. The support period must be at least five years (Article 13(8)), or the expected use time if shorter, and its end date must be stated clearly and understandably at the time of purchase (Article 13(19)). Security updates must remain available for at least ten years or the remainder of the support period, whichever is longer (Article 13(9)).
Article 14 creates two reporting streams, both to the coordinating CSIRT and ENISA through the single platform (Article 16). For an actively exploited vulnerability: early warning within 24 hours, notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident affecting product security the same 24-hour and 72-hour steps apply, with a final report within one month of notification.
What this means for Turkish companies
The CRA’s position differs structurally from the trade instruments a Turkish exporter is used to: it binds manufacturers wherever established; the trigger is placing a product with digital elements on the EU market. A company in Türkiye that places its own branded product on that market is the manufacturer and carries the full weight of Articles 13 and 14 itself. These duties cannot be passed to the EU importer, whose role under Article 19 is to verify the conformity assessment, technical documentation, CE marking and declaration of conformity and to retain that declaration for ten years or the support period — so contractual verification and information requests will arrive well before 2027.
The critical point for Turkish exporters
Products placed on the market before 11.12.2027 need no CE marking unless they undergo a substantial modification (Article 69) — but the Article 14 reporting obligations apply to the existing installed base. From 11.09.2026 a manufacturer must report actively exploited vulnerabilities in products already sold into the EU on a 24-hour clock. This is the nearest deadline and the point most often missed.
On authorised representatives, no general answer is correct: Article 18 permits a manufacturer to appoint one but does not require it. However, most connected and wireless products fall simultaneously under the Radio Equipment Directive 2014/53/EU, which does require a responsible person established in the Union. The position is product-specific and must be settled product by product.
The sequence we recommend: classify every product against Implementing Regulation (EU) 2025/2392; before 11.09.2026 stand up a vulnerability-handling and incident process able to meet a 24-hour clock, with access to the ENISA platform; before 11.12.2027 complete Annex I compliance, a documented risk assessment, technical documentation, SBOM-level component tracking, conformity assessment, the EU declaration of conformity, CE marking and a declared support period disclosed at the point of sale.
Timeline
Entry into force 10.12.2024; Implementing Regulation (EU) 2025/2392 adopted 28.11.2025 and in force from 21.12.2025; Chapter IV on the notification of conformity assessment bodies (Articles 35 to 51) from 11.06.2026; Article 14 reporting from 11.09.2026; full application 11.12.2027. As of July 2026 the CEN and CENELEC harmonised standards underpinning Annex I are still in development; their availability will decide whether Class I self-assessment is workable. No proposal to reopen the CRA timetable exists.
Enforcement and penalties
Article 64 sets fines on a whichever-is-higher basis: breaches of the Annex I essential requirements and of Articles 13 and 14 attract up to EUR 15,000,000 or 2.5% of worldwide annual turnover; breaches of Articles 18 to 23, 28, 30(1)–(4), 31(1)–(4), 32(1)–(3), 33(5), 39, 41, 47, 49 and 53 up to EUR 10,000,000 or 2%; and incorrect, incomplete or misleading information to notified bodies or market surveillance authorities up to EUR 5,000,000 or 1%. Under Article 64(10) micro and small enterprises are exempt from fines for missing the Article 14(2)–(4) deadlines, and open-source software stewards are exempt from administrative fines entirely.
Related content
Read it with the NIS2 record for organisational cybersecurity duties, and the EU Artificial Intelligence Act record for the additional layer that applies where a product contains AI. General product safety sits in the GPSR record; incident response and vulnerability handling are addressed in our Cybersecurity focus area.
Entry into force & amendment history
- 11.12.2027
Full application begins
The Annex I essential requirements, conformity assessment and CE marking become mandatory.
- 11.09.2026
Article 14 reporting applies
Vulnerability and incident reporting begins, including for products already on the market.
- 11.06.2026
Chapter IV became applicable
Articles 35 to 51 on the notification of conformity assessment bodies took effect.
- 10.12.2024
Regulation entered into force
Published in the Official Journal, with obligations tied to a phased timetable.
Official Sources
Regulation text · EUR-Lex eur-lex.europa.euImplementing Regulation (EU) 2025/2392 · EUR-Lex eur-lex.europa.euCRA summary · European Commission digital-strategy.ec.europa.eu


