GRCCopilot
Sign In
European Union / ENISA

EU Cyber Resilience Act (CRA) Assessment

Landmark EU regulation requiring security-by-design for all hardware and software products sold in the EU — enforced from 2027

Start Assessment Create Free Account
13
Controls
39
Questions
Active
Status
May 2031
Expires

About this Framework

The EU Cyber Resilience Act (CRA — EU 2024/2847), adopted in October 2024, introduces mandatory cybersecurity requirements for all products with digital elements placed on the EU market — hardware, software, firmware and connected applications. Manufacturers must ensure security by design and default, provide security updates throughout the product support period (minimum 5 years), maintain a software bill of materials (SBOM), implement coordinated vulnerability disclosure and notify ENISA of actively exploited vulnerabilities within 24 hours. CE marking requirements for cybersecurity take full effect in 2027.

Key Control Domains

Security by Design & Default
Software Bill of Materials (SBOM)
Vulnerability Handling Process
Coordinated Vulnerability Disclosure
Security Update Management
Incident & Vulnerability Reporting to ENISA
Conformity Assessment
CE Marking for Digital Products
Post-Market Security Obligations

Who Needs This?

  • Hardware and software product manufacturers selling in the EU
  • IoT device and connected product manufacturers
  • Commercial off-the-shelf (COTS) software developers
  • Open-source foundations with commercial OSS distributions
  • Technology importers and distributors in the EU market

Compliance Benefits

  • CE marking eligibility — required for EU product market access
  • Reduced product liability exposure from cybersecurity vulnerabilities
  • Structured vulnerability disclosure and patch management programme
  • Competitive advantage through verifiable, certified security assurance

Official Reference

EU Cyber Resilience Act — European Commission
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

Assessment Details

Issuer / AuthorityEuropean Union / ENISA
FrameworkEU Cyber Resilience Act (CRA) Assessment
Controls13
Questions39
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2031

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/eu-cyber-resilience-act-cra-assessment

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.