EU Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) law entered into force (EIF) on December 10, 2024, when it was published as Regulation (EU) 2024/2847 in the Official Journal of the European Union. Some CRA requirements become mandatory on 2026-09-11, and the CRA will fully apply three years later, on 2027-12-11. The CRA will obligate all products with digital elements, including their remote data processing, put on the European market to follow this regulation.

The CRA intends to address threats and vulnerabilities by establishing standardized frameworks for cybersecurity requirements as part of a wider set of European product legislation. It regulates so-called “products with digital elements”, or PDE for short, and its horizontal nature gives it a big scope, including a wide set of hardware and software, but excluding medical devices, cars and other product types with their own safety and security rules. The primary goal is to reduce the costs for data breaches and increase customer trust in products with a digital element.

EU CRAfish logo

CRA Resources

CRA News and Updates

Aug 26, 2026 | OpenSSF

Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes

Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security fixes directly to open source communities. Read more.

Aug 25, 2026 | OpenSSF

What’s in the SOSS? Podcast #70 – S3E22 Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

In this episode of What's in the SOSS, host Sally Cooper and Red Hat's Dave Russo unpack the European Union’s Cyber Resilience Act (CRA). Discover the hidden financial toll of private forks, the crucial legal distinction between manufacturers and open source stewards, and actionable steps your organization can take to… Read more.

Aug 18, 2026 | Jeff Diecks

What’s in the SOSS? Podcast #69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov

The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group… Read more.

Aug 14, 2026 | Jeff Diecks

CRA Monthly Tech Talk: ORBIT Launchpad SIG Updates

https://youtu.be/gAv60r9ZRVs?si=c329jpaEfHQE7TQ0 Read more.
Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance

Aug 11, 2026 | aliu

CRA Readiness: A Practitioner’s Guide to Compliance

The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality. With the September 2026 reporting deadline rapidly approaching and full compliance required by December 2027, software manufacturers, commercial entities, open source stewards, and foundations must establish a clear, pragmatic path forward.… Read more.

Aug 11, 2026 | Jeff Diecks

What’s in the SOSS? Podcast #68 – S3E20 CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight

Join Megan Knight on the What's in the SOSS podcast as she breaks down the upcoming EU Cyber Resilience Act (CRA) and shares practical compliance strategies for open source maintainers and organizations. Read more.

Jun 25, 2026 | OpenSSF

The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?

In 2025, Linux Foundation Research, Linux Foundation Europe, and Open Source Security Foundation (OpenSSF) published Unaware and Uncertain: The Stark Realities of Cyber Resilience Act Readiness in Open Source. It took a survey-based look at how prepared the open source ecosystem was for the European Union's Cyber Resilience Act (EU… Read more.

Jun 3, 2026 | OpenSSF

Updates from Europe: Single Reporting Platform, Public Consultations, New Publications

Updated FAQ on the CRA Single Reporting Platform ENISA published an updated FAQ on the CRA Single Reporting Platform, which includes valuable information concerning the procedures for reporting under Article 14 of the CRA. Notably, the FAQ includes the data fields to be filled in as part of the reporting… Read more.

May 29, 2026 | OpenSSF

Aligning on Machine-Readable Signals as the Foundation for Due Diligence

By Madalin Neag, EU Policy Advisor, OpenSSF Introduction The software supply chain has reached a level of complexity where manual oversight is no longer a viable strategy for security or regulatory compliance. Modern systems depend on vast, rapidly evolving networks of components, making manual, paper-based approaches to due diligence impractical.… Read more.

May 18, 2026 | OpenSSF

Taking Stock of the State of European Cyber Resilience Act (CRA) Compliance: An Urgent Wake-up Call for the Open Source Ecosystem

By Christopher (CRob) Robinson, OpenSSF For the better part of two years, discussions surrounding the European Cyber Resilience Act (CRA) have been somewhat theoretical: mapping requirements, debating definitions, and analyzing how the requirements will impact our amazing ecosystem. But folks, it’s mid-2026, and the CRA is live. Theory is officially… Read more.