Cyber Resilience Act (CRA) Compliance Software

EU Cyber Resilience Act: Compliance That Holds Up Under Audit

The CRA requires manufacturers to trace every cybersecurity requirement to a risk, a design decision, and a verification test and keep that evidence intact for 10 years. That is, at its core, a requirements management problem. Visure solves it.

CRA Enforcement Timeline

  1. Chapter IV active. Notified body and authority obligations apply. Internal tooling and processes must be in place.

  2. Article 14 reporting. Actively exploited vulnerabilities must be reported within 24 hours. Final report within 14 days.

  3. Full application. All PDEs need CE marking, Annex I compliance evidence, and complete Annex VII documentation.

  4. Ongoing

    10-year retention. All technical documentation, risk assessments, and baselines must be reproducible on demand.

CRA Requirements Overview

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal EU law mandating cybersecurity requirements for any product with digital elements (PDE) sold on the European market. It entered into force 10 December 2024 and applies fully from 11 December 2027.

A PDE is any hardware or software product whose intended or foreseeable use includes a direct or indirect logical or physical connection to a device or network from industrial controllers and smart home devices to enterprise software, IoT sensors, and connected vehicle components.

The CRA’s two objectives: ensure manufacturers improve cybersecurity throughout the entire product lifecycle, and give users reliable security information before purchase. Once in scope, a manufacturer must design against defined essential cybersecurity requirements (Annex I), document a risk assessment, manage vulnerabilities systematically, and maintain evidence for at least 10 years.

Excluded from CRA scope: medical devices (EU MDR), motor vehicles (UNECE WP.29 Reg. 2019/2144), civil aviation products, marine equipment, and national security/defence items. Open-source software outside commercial activity is also excluded.

Product Risk Tiers Articles 7, 8 & 32

Self-assessment permitted
Approx. 90% of all PDEs. Module A conformity route. Manufacturers self-declare.
Hard drives, smart home devices, most connected hardware
Full standards or EU-type examination
Self-assessment only if full harmonised standards applied. Otherwise Modules B+C or H required.
IAM, browsers, password managers, antivirus, VPN, SIEM
Third-party assessment required
Must use Modules B+C, Module H, or EU cybersecurity certification at “substantial” assurance level.
Industrial hypervisors, firewalls, IDS/IPS, tamper-resistant processors
Certification scheme mandatory
Where a delegated act applies, a European cybersecurity certification at “high” assurance level is required.
Hardware security boxes, smart-meter gateways, smartcards

Article 64 Enforcement

The cost of non-compliance is not just a fine

The CRA gives market surveillance authorities powers that go well beyond financial penalties. Understanding the full exposure is the first step to building a compliance program your legal and engineering teams can stand behind.
€15M

or up to

2.5% worldwide turnover

Non-compliance with Annex I essential requirements or Articles 13 and 14 manufacturer obligations

€10M

or up to

2% worldwide turnover

Breaches of importer, distributor, CE marking, conformity assessment, or declaration obligations

€5M

or up to

1% worldwide turnover

Incorrect, incomplete or misleading information supplied to notified bodies or market surveillance authorities

Market surveillance authorities can order mandatory product withdrawal from the EU market

Mandatory product recall powers for non-conforming products already on the market

Increased manufacturer liability for damages under EU product liability rules

The Core Challenge

Why CRA Is a Requirements Management Problem

Every Article 13 obligation demands that someone in your engineering org owns a requirement, traces it to evidence, and can reproduce that chain years later. That is not a legal task. It is an engineering one.

Requirements without traceability are unacceptable

Annex VII requires you to show, per requirement, how each Annex I clause is implemented and verified. A Word doc or spreadsheet cannot produce this link on demand and cannot prove it was maintained across years of product support.

10-year evidence retention is a systems architecture question

Article 13(13) requires 10 years minimum. Any compliance program built on shared drives or email trails will not survive a market surveillance audit five years after launch. You need reproducible baseline restore, not file versions.

Every vulnerability reopens the evidence chain

Article 14's 24-hour reporting window means the moment a vulnerability is discovered, you need to instantly identify every affected product version, requirement, and test. That requires live traceability, not retrospective documentation.

The CRA Evidence Chain

CRA Annex I Clause

Applicable essential requirement identified and scoped to your product

Cybersecurity Risk Assessment

Threat modelled, CVSS score assigned, linked to Annex I clause

Security Requirement

Authored, linked to risk, approved by Product Security Officer

Design and SBOM

Implementation traced to components, architecture, and software dependencies

Signed Baseline

Test passed, evidence frozen with electronic signature, retained 10 years

Visure in Action

How Visure Satisfies Each CRA Obligation

Every CRA obligation has a Visure capability that satisfies it. Select an obligation below to see the exact workflow your team will use from Day 1.

Annex I, Part I + Article 13(2)-(4) · Requirements and Risk Traceability

Connect every Annex I clause to a risk, a requirement, and a passing test.

Annex I defines the essential cybersecurity requirements your product must meet by design. Article 13 requires each one to be grounded in a documented risk assessment. Visure holds the full chain clause, risk, requirement, design, test as live linked items. If anything changes upstream, suspect links fire downstream automatically.

Annex I, Part II + Article 14 · SBOM Traceability and Vulnerability Response

Know which products are affected before the 24-hour clock runs out.

Annex I, Part II requires a machine-readable SBOM linked to your security requirements. Article 14 requires you to report actively exploited vulnerabilities within 24 hours. When a CVE hits an SBOM component, Visure’s blast-radius analysis surfaces every affected requirement, test, and product release instantly so your PSO files an accurate early warning, not a best guess.

Annex VII · Technical Documentation Package

Stop rebuilding your evidence pack the week before an audit.

Annex VII requires a complete technical documentation package risk assessment, design records, standards mapping, test reports, SBOM, CVD policy, and EU Declaration of Conformity available to market surveillance authorities on reasoned request at any time, retained for 10 years. Visure builds this pack continuously as your team works, not retrospectively before an audit.

Article 13(13) + Article 32 · Baselines, Signatures and Conformity Assessment

Every release locked, signed, and reproducible for 10 years.

Article 13(13) requires technical documentation to be reproducible for at least 10 years. Article 32 requires manufacturers to demonstrate to notified bodies that a governed, approved process was followed. Visure’s baseline system satisfies both: requirements pass through review and approval gates before signing, and every signed baseline can be restored exactly years later.

Vivia AI · Governed Security Requirements Generation

Define your Annex I requirements in hours, not weeks.

Vivia, Visure’s governed AI engine, generates CRA-aligned security requirement drafts from your product description and the applicable Annex I clauses. It cuts the blank-page time from weeks to hours but every AI output passes through a human review workflow and explicit sign-off before entering any baseline. The audit trail for every generation event is permanent.

Explore More

CRA Resources from Visure

CRA Compliance Handbook

A complete guide to CRA obligations, Annex I mapping, standards landscape, and how to structure your compliance program in Visure.

CRA Compliance Datasheet

One-page technical reference: every CRA obligation mapped to the exact Visure capability and feature that satisfies it, with Annex references.

Webinar: CRA in Practice

60-minute on-demand session covering the CRA compliance workflow in Visure, including live demos of traceability, risk management, and Article 14 response.

Get a Free CRA Readiness Assessment

A 60-minute session with a Visure compliance specialist. Walk away with an obligation-by-obligation gap report mapped to Annex I and Annex VII, before you write a single requirement.

CRA FAQ

Common Questions About CRA Compliance

Questions engineers, compliance leads, and product managers ask most. Each answer is written to stand alone no platform knowledge required.

The CRA aims to ensure that wired and wireless products connected to the internet or to a network are more secure; that manufacturers remain responsible for a product's cybersecurity throughout its lifecycle; and that consumers are properly informed about the cybersecurity of products they buy. It is the EU's response to an estimated annual cost of €5.5 trillion from cybercrime, much of it enabled by insecure connected products.

The CRA applies to products with digital elements (PDEs) commercially available in the EU, regardless of place of manufacture. PDEs include standalone software, hardware products with a direct or indirect connection to a network or device, and software or hardware components integrated into PDEs. It excludes websites and SaaS cloud applications that do not support remote processing for a PDE, open-source software outside commercial activity, and products covered by other EU sectoral regulation: medical devices under MDR, motor vehicles under UNECE WP.29, civil aviation products, and national security or defence items.

Get Started

Ensure CRA Compliance with Visure

Learn how Visure gives your engineering team the requirements management, traceability, and audit trail infrastructure that CRA compliance demands. 

Talk to Our CRA Compliance Team

By submitting you agree to Visure’s Privacy Policy.

Search

Find resources, features and more.

Watch Visure in Action

Complete the form below to access your demo