Regulatory Playbook

EU Cyber Resilience Act (CRA) Compliance Playbook

Understand the CRA timeline, the SBOM and reporting duties, CE marking, and exactly what OT and connected-product makers must do before the 2027 deadline. A free, practical playbook.

2024/2847Regulation
11 Sep 2026Reporting live
11 Dec 2027Full obligations
EUR 15MMax fine
Compliance Playbook
EU Cyber Resilience Act (CRA) Compliance Playbook
  • The CRA timeline and your real deadlines for 2026 and 2027
  • How to scope and classify products with digital elements
  • Essential cybersecurity requirements and secure-by-design
  • SBOM, technical documentation, and CE marking checklist
  • The 24-hour and 72-hour incident reporting duties
  • IEC 62443 mapping for OT manufacturers
Free Download

The EU Cyber Resilience Act, Regulation (EU) 2024/2847, is the first law anywhere to make cybersecurity a condition of placing a product on the market. It covers every product with digital elements, hardware and software alike, and that squarely includes the industrial controllers, gateways, sensors, and connected OT components that run modern plants. If your organization makes, integrates, imports, or distributes such products into the EU, the CRA applies to you, and the clock is already running. The reporting obligations took effect on 11 September 2026, and the full requirements apply from 11 December 2027. This playbook turns the regulation into a clear, staged plan so you know what to do, and by when.

What Is Inside the Playbook

The playbook breaks the CRA into the areas your team must act on, each explained in plain language with a practical checklist:

01
TIMELINE & DEADLINES
The four CRA dates that matter:
What is already in force, what is coming on 11 December 2027, and how these milestones affect your duties. Learn when the reporting obligations and full compliance requirements hit.
02
SCOPE & PRODUCT CLASSES
Are your products in scope?
How to determine if the CRA applies, and how your obligations change depending on whether your products are classified as default, important, or critical. Understand what each classification means for compliance.
03
ESSENTIAL REQUIREMENTS & SECURE-BY-DESIGN
Security, by default and by design:
The mandatory security features every product must have, and the vulnerability handling process you must keep running for the product’s full support period.
04
SBOM, DOCUMENTATION & CE MARKING
What evidence is required?
The software bill of materials (SBOM), technical documentation, and EU declaration of conformity you must prepare—which together allow you to apply the CE mark and place your product on the market.
05
REPORTING DUTIES
What and when to report:
The 24-hour early warning and 72-hour notification requirements for actively exploited vulnerabilities and severe incidents. How to report through the ENISA platform and what triggers reporting.

Who This Playbook Is For

  • Manufacturers of industrial and OT products with digital elements sold into the EU
  • System integrators and OEMs who build connected products or bundle components
  • Importers and distributors placing products with digital elements on the EU market
  • Product security, compliance, and engineering leaders preparing for the 2027 deadline
  • OT operators who need to understand CRA obligations flowing through their supply chain

Why Use This Playbook

  • Know your real deadlines. The reporting duties are already live as of September 2026. The playbook makes clear what applies now and what applies in 2027.
  • Scope your products correctly. Getting the product class right determines how heavy your conformity path is. The playbook helps you classify.
  • Build the evidence CE marking needs. Technical documentation, SBOM, and a declaration of conformity are not optional. The playbook lists what to prepare.
  • Written with OT in mind. Most CRA guidance is generic. This playbook speaks to the realities of industrial and OT products, from long support periods to legacy components.

Why the CRA Matters for OT

The CRA is often discussed as a consumer and IT software law, but its reach into operational technology is direct. Industrial controllers, remote terminal units, gateways, and the growing population of connected OT devices are all products with digital elements. If you build or integrate them for the EU market, you carry CRA obligations, and the secure-by-design and vulnerability handling duties align closely with the practices in IEC 62443. Our OT cybersecurity services help manufacturers and integrators meet both.

Frequently Asked Questions

The Cyber Resilience Act, Regulation (EU) 2024/2847, is the first EU-wide law to set mandatory cybersecurity requirements for products with digital elements, covering both hardware and software across their whole lifecycle. It shifts responsibility for product security onto the organizations that place products on the market.
The CRA entered into force on 10 December 2024. The reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and the full requirements apply from 11 December 2027.
Non-compliance with the essential cybersecurity requirements or core manufacturer obligations can attract administrative fines of up to 15 million euros or 2.5 percent of total worldwide annual turnover, whichever is higher.
Yes. Industrial controllers, gateways, sensors, and other connected OT components are products with digital elements. Manufacturers, integrators, importers, and distributors placing such products on the EU market are in scope.
The CRA makes a software bill of materials, an SBOM, mandatory for every product with digital elements. The SBOM documents the components in your product so vulnerabilities can be tracked and managed across the support period.
It turns the CRA into a staged, practical plan with checklists for scope, essential requirements, SBOM and CE marking, and reporting. For hands-on support, explore our OT cybersecurity services.