Manufacturer — default class.
What this means for you
Self-assessment (Module A): Annex I Parts I and II, technical documentation (Annex VII), Declaration of Conformity and CE marking, a defined support period, Article 14 reporting. If Q2 = d: the cloud part necessary for the product's functions is part of the product.
Your first 5 steps
- Define the support period and list your products.
- Generate an SBOM from your current build.
- Set up a vulnerability-reporting channel and a CVD policy.
- Decide who monitors vulnerabilities and who files reports (EU Login + registration on ENISA's Single Reporting Platform).
- Start the technical documentation per Annex VII.
Deadlines
Article 14 reporting applies to you from 11 September 2026. The full Annex I requirements apply only if the product is substantially modified after 11 December 2027 (Article 69). Recommendation: sort out your SBOM and reporting channel now — you will need them for your first report.
Key facts
- The Cyber Resilience Act is Regulation (EU) 2024/2847; obligations phase in over time.
- From 11 September 2026: report actively exploited vulnerabilities and severe incidents (24 h / 72 h / 14 days) via ENISA's Single Reporting Platform.
- From 11 December 2027: no product with digital elements on the EU market without CE marking and the Annex I security requirements.
- Penalties up to €15 million or 2.5 % of worldwide annual turnover.
Source: EUR-Lex (Regulation (EU) 2024/2847); European Commission guidance of 27 July 2026.
Informational tool based on Regulation (EU) 2024/2847 and the European Commission's guidance as of 27 July 2026. Not legal advice and not a conformity assessment; borderline cases (especially SaaS, open source and custom development) should be reviewed with a professional.