Does my product fall under the EU Cyber Resilience Act?
The CRA introduces mandatory security requirements for software shipped to EU customers. Check your product in seconds — no legal jargon required.
Check your product
Describe what your product does and how customers use it. Our AI will tell you whether it falls under the CRA.
What is the CRA?
The EU Cyber Resilience Act is a regulation that came into force in October 2024. It sets mandatory security requirements for any product that can connect to a device or network — covering software packages, SDKs, desktop apps, IoT firmware, and more.
In scope
- Desktop & mobile apps
- CLI tools and server packages
- Container images
- SDKs and APIs
- IoT firmware
- Self-hosted platforms
Out of scope
- Pure browser-based SaaS (vendor-hosted only)
- Non-commercial open-source projects
What CRA compliance actually requires
Living SBOM
A continuously maintained, machine-readable Software Bill of Materials covering all components — including transitive dependencies — updated for the product's lifetime.
24-hour disclosure
When you discover an actively exploited vulnerability, you must notify ENISA within 24 hours, with a fuller report within 72 hours.
No known exploits at release
You cannot ship a release containing known exploitable vulnerabilities. Vulnerability checks must be a gate in your release pipeline.
5-year support
Security updates must be provided for the expected product lifetime, or a minimum of five years from release.
StackRadar for CRA readiness
Get your dependency inventory, vulnerability gates, and SBOM — automatically
StackRadar tracks all dependencies across your repositories, enforces policies as CI gates, and generates automated upgrade PRs with repo-specific context. When a CVE drops, you know which products are affected in seconds — not days.
Frequently asked questions
Does the CRA apply to SaaS?
Purely browser-based SaaS — where all compute runs on your servers and users never install anything — is generally out of scope. But if you also ship a CLI tool, desktop app, server package, container image, or SDK that customers run themselves, those components are in scope.
What is a "product with digital elements"?
Any software or hardware that can connect, directly or indirectly, to another device or network. This covers desktop apps, mobile apps, server-side packages, IoT firmware, SDKs, APIs, and self-hosted platforms — essentially anything customers install and run themselves.
When do I need to be compliant?
Vulnerability and incident reporting obligations kick in September 2026 — less than 5 months away. Full compliance including CE marking is required by October 2027.
What if I use open-source dependencies?
Open-source software developed non-commercially is largely exempt. But if you are a commercial entity shipping products that include open-source components, you are responsible for the security of those components. Your dependency inventory becomes a compliance matter.
What does the CRA actually require?
A living SBOM (Software Bill of Materials) covering all dependencies; vulnerability disclosure to ENISA within 24 hours of discovering an actively exploited vulnerability; no known exploitable vulnerabilities at release; and security updates for the product's lifetime or at least 5 years.
What are the penalties for non-compliance?
Fines up to €15 million or 2.5% of global annual turnover, whichever is higher. Non-compliant products cannot carry the CE mark and cannot legally be sold in the EU.
This tool provides general information only. It is not legal advice. For binding compliance guidance, consult a qualified legal professional familiar with EU law.