Legislation · European Union · EU Directive & Regulation (Regulation (EU) 2024/2847)

EU Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) imposes binding cybersecurity requirements across the EU on every product with digital elements. It binds the manufacturer wherever established, so a company in Türkiye that places a product on the EU market is directly liable in its own right. The obligations are phased: the Article 14 reporting regime applies from 11.09.2026 and full compliance, including CE marking, from 11.12.2027.

In progressIn force · 10.12.2024 (phased; full application 11.12.2027)Source · OJ L 2024/2847, 20.11.2024Threshold · Anyone placing products with digital elements on the EU market
In summary

The Regulation uses a broad definition of a product with digital elements, covering software, hardware and their remote data processing solutions. The manufacturer must meet the Annex I essential requirements, carry out and document a risk assessment, complete conformity assessment, draw up an EU declaration of conformity, affix the CE marking and state a support period of at least five years at the point of sale. Actively exploited vulnerabilities and severe incidents go to the coordinating CSIRT and ENISA within 24 hours. (As of July 2026)

Who does it affect?

Manufacturers selling into the EU

A company established in Türkiye is the manufacturer and carries the Article 13 and Article 14 duties itself.

Software and firmware suppliers

Components placed on the market separately are in scope; open-source software supplied outside a commercial activity is not.

Connected hardware producers

Routers, smart home devices and firewalls fall into the Annex III classes and may require third-party assessment.

Key Obligations
  • 01Carry out a risk assessment under Article 13(2)–(3) and document it in the technical file; the Annex I requirements build on it.
  • 02Complete conformity assessment and CE marking before placing the product on the market; a notified body is mandatory for Class II and critical products.
  • 03Report under Article 14 with an early warning within 24 hours, notification within 72 hours and a final report on the prescribed timetable.
  • 04Declare and honour a support period of at least five years, disclosed at the point of sale, with security updates available for at least ten years.

Overview

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847 — a Regulation, directly applicable in the Member States, so no national transposition is awaited. It requires products with digital elements to meet defined cybersecurity requirements before being placed on the market and to remain secure across their lifecycle. It entered into force on 10.12.2024, with obligations phased.

Scope and product classes

Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. The definition is deliberately broad: standalone software, firmware, connected hardware and manufacturer-designed remote components all fall within it. Free and open-source software supplied outside a commercial activity is out of scope.

Conformity runs in four tiers. Default products self-assess (Module A). Annex III Class I important products — password managers, VPNs, boot managers, routers, smart home assistants — may self-assess only where harmonised standards or an EU cybersecurity certification scheme are fully applied; otherwise third-party assessment is required. Annex III Class II products (firewalls, hypervisors, tamper-resistant microcontrollers and microprocessors) always require third-party assessment, and Annex IV critical products (hardware security modules, smart meter gateways, smartcards) face the strictest regime. Classification must be carried out against the technical definitions in Implementing Regulation (EU) 2025/2392, not the Annex headings.

Key obligations

The manufacturer must carry out a cybersecurity risk assessment (Article 13(2)–(3)), satisfy the Annex I essential requirements, compile technical documentation, complete the applicable conformity route (Module A, B+C or H), draw up an EU declaration of conformity and affix the CE marking. The support period must be at least five years (Article 13(8)), or the expected use time if shorter, and its end date must be stated clearly and understandably at the time of purchase (Article 13(19)). Security updates must remain available for at least ten years or the remainder of the support period, whichever is longer (Article 13(9)).

Article 14 creates two reporting streams, both to the coordinating CSIRT and ENISA through the single platform (Article 16). For an actively exploited vulnerability: early warning within 24 hours, notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident affecting product security the same 24-hour and 72-hour steps apply, with a final report within one month of notification.

What this means for Turkish companies

The CRA’s position differs structurally from the trade instruments a Turkish exporter is used to: it binds manufacturers wherever established; the trigger is placing a product with digital elements on the EU market. A company in Türkiye that places its own branded product on that market is the manufacturer and carries the full weight of Articles 13 and 14 itself. These duties cannot be passed to the EU importer, whose role under Article 19 is to verify the conformity assessment, technical documentation, CE marking and declaration of conformity and to retain that declaration for ten years or the support period — so contractual verification and information requests will arrive well before 2027.

The critical point for Turkish exporters

Products placed on the market before 11.12.2027 need no CE marking unless they undergo a substantial modification (Article 69) — but the Article 14 reporting obligations apply to the existing installed base. From 11.09.2026 a manufacturer must report actively exploited vulnerabilities in products already sold into the EU on a 24-hour clock. This is the nearest deadline and the point most often missed.

On authorised representatives, no general answer is correct: Article 18 permits a manufacturer to appoint one but does not require it. However, most connected and wireless products fall simultaneously under the Radio Equipment Directive 2014/53/EU, which does require a responsible person established in the Union. The position is product-specific and must be settled product by product.

The sequence we recommend: classify every product against Implementing Regulation (EU) 2025/2392; before 11.09.2026 stand up a vulnerability-handling and incident process able to meet a 24-hour clock, with access to the ENISA platform; before 11.12.2027 complete Annex I compliance, a documented risk assessment, technical documentation, SBOM-level component tracking, conformity assessment, the EU declaration of conformity, CE marking and a declared support period disclosed at the point of sale.

Timeline

Entry into force 10.12.2024; Implementing Regulation (EU) 2025/2392 adopted 28.11.2025 and in force from 21.12.2025; Chapter IV on the notification of conformity assessment bodies (Articles 35 to 51) from 11.06.2026; Article 14 reporting from 11.09.2026; full application 11.12.2027. As of July 2026 the CEN and CENELEC harmonised standards underpinning Annex I are still in development; their availability will decide whether Class I self-assessment is workable. No proposal to reopen the CRA timetable exists.

Enforcement and penalties

Article 64 sets fines on a whichever-is-higher basis: breaches of the Annex I essential requirements and of Articles 13 and 14 attract up to EUR 15,000,000 or 2.5% of worldwide annual turnover; breaches of Articles 18 to 23, 28, 30(1)–(4), 31(1)–(4), 32(1)–(3), 33(5), 39, 41, 47, 49 and 53 up to EUR 10,000,000 or 2%; and incorrect, incomplete or misleading information to notified bodies or market surveillance authorities up to EUR 5,000,000 or 1%. Under Article 64(10) micro and small enterprises are exempt from fines for missing the Article 14(2)–(4) deadlines, and open-source software stewards are exempt from administrative fines entirely.

Related content

Read it with the NIS2 record for organisational cybersecurity duties, and the EU Artificial Intelligence Act record for the additional layer that applies where a product contains AI. General product safety sits in the GPSR record; incident response and vulnerability handling are addressed in our Cybersecurity focus area.

Entry into force & amendment history

  • 11.12.2027

    Full application begins

    The Annex I essential requirements, conformity assessment and CE marking become mandatory.

  • 11.09.2026

    Article 14 reporting applies

    Vulnerability and incident reporting begins, including for products already on the market.

  • 11.06.2026

    Chapter IV became applicable

    Articles 35 to 51 on the notification of conformity assessment bodies took effect.

  • 10.12.2024

    Regulation entered into force

    Published in the Official Journal, with obligations tied to a phased timetable.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
03

How We Help on This Matter

We structure compliance with this instrument across both the Türkiye and DACH sides of your business.

Product Classification

Classifying the portfolio against Implementing Regulation (EU) 2025/2392 and identifying the applicable conformity route.

Vulnerability and Incident Reporting

Building an internal process, escalation matrix and record system capable of meeting the 24-hour clock.

Contracts and Supply Chain

Drafting conformity, documentation and support-period provisions in EU importer and distributor agreements.

Technical File and Declaration

Legal support for the technical documentation, risk assessment and EU declaration of conformity set.

All our services
Legislation · European Union

EU Cyber Resilience Act (CRA) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.