About Cybiq
What Cybiq checks
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements sold in the EU. Cybiq asks six questions (how your product reaches users, what customers receive, overlapping EU regimes, your supply-chain role, and the product category) and returns a definitive verdict: in scope or out, which conformity route applies (self-assessment, Annex III Class I documentation, or notified-body assessment), your concrete obligations, and the dates that matter.
Every claim is anchored word-for-word in the Official Journal (CELEX 32024R2847) and re-verified weekly by automated tests against the live text, fetched from the Publications Office CELLAR endpoint.
The dates that matter
| Date | What starts |
|---|---|
| 11 June 2026 | Notified-body framework in application (Chapter IV, Articles 35 to 51): no operator duties yet, context for products that will need third-party assessment |
| 11 September 2026 | Manufacturers' vulnerability & incident reporting duties (Art. 14): early warning 24 h · notification 72 h · final report 1 month |
| 11 December 2027 | Full application: technical documentation, SBOM, support period, conformity assessment, CE marking |
Non-compliance with essential requirements and Articles 13–14: fines up to €15,000,000 or 2.5% of worldwide turnover (Art. 64(2)). Operator obligations: up to €10,000,000 or 2% (Art. 64(3)).
Frequently asked questions
- Does the CRA apply to my SaaS?
- Generally no: services running entirely on your own infrastructure are not “products with digital elements”. But if you ship client software (an app, agent, connector), those installed parts can fall in scope.
- What about free open-source software?
- Non-monetised OSS falls outside the CRA. Monetised open source (paid distribution, or support/licensing tied to the product) is treated like any other commercial product.
- When do my obligations start?
- Main application is 11 December 2027. Art. 14 reporting duties (manufacturers only) start 11 September 2026; the Chapter IV notified-body framework has applied since 11 June 2026.
- Do I need CE marking for my software?
- Once the CRA fully applies (11 December 2027), in-scope manufacturers affix CE marking visibly, legibly and indelibly, plus an EU declaration of conformity.
- What is an SBOM and do I need one?
- A machine-readable inventory of your product's components. The CRA requires one covering at least the top-level dependencies, in a common format such as CycloneDX or SPDX.
- How long must I support my product?
- At least five years from last placing on the market, or the expected use time where the product is expected to be in use for less than five years; declared visibly, with security updates throughout.
- I resell products: do I have duties?
- Yes: act with due care, confirm CE marking and documentation are present, and don't supply products you know to be non-compliant. Importers carry additional verification and labelling duties.
- What are the CRA fines?
- Up to €15,000,000 or 2.5% of worldwide turnover for breaches of the essential requirements and Articles 13–14; up to €10,000,000 or 2% for importer/distributor obligations (Art. 64).
- Which conformity route applies to my product?
- Most products: internal control (self-assessment). Annex III Class I products (browsers, password managers, routers): self-assessment plus full technical documentation. Annex III Class II (firewalls, hypervisors) and Annex IV critical products (security boxes, smartcards): notified body required.
- Is this legal advice?
- No: orientation grounded in the Official Journal, with verbatim citations on every item so you can verify. For a binding assessment, consult a qualified lawyer.
More depth: the full FAQ (34 evidence-checked answers) and the CRA glossary with verbatim definitions.
Documents after the check
- Verification checklist pack · €49: role-specific checklist for importers and distributors, plus their vulnerability-notification duties under Articles 19–20.
- CRA compliance pack · €199: classification memo, vulnerability-handling procedure, SBOM policy, secure-by-default checklist, support-period statement, Annex V index.
- Notified-body readiness pack · €299: everything above plus conformity-assessment preparation guide and regulatory-watch updates until December 2027.
Prices final; seller not VAT-registered (small-business exemption). Automated compliance documents, not legal advice.