About Cybiq

What Cybiq checks

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements sold in the EU. Cybiq asks six questions (how your product reaches users, what customers receive, overlapping EU regimes, your supply-chain role, and the product category) and returns a definitive verdict: in scope or out, which conformity route applies (self-assessment, Annex III Class I documentation, or notified-body assessment), your concrete obligations, and the dates that matter.

Every claim is anchored word-for-word in the Official Journal (CELEX 32024R2847) and re-verified weekly by automated tests against the live text, fetched from the Publications Office CELLAR endpoint.

The dates that matter

DateWhat starts
11 June 2026 Notified-body framework in application (Chapter IV, Articles 35 to 51): no operator duties yet, context for products that will need third-party assessment
11 September 2026 Manufacturers' vulnerability & incident reporting duties (Art. 14): early warning 24 h · notification 72 h · final report 1 month
11 December 2027 Full application: technical documentation, SBOM, support period, conformity assessment, CE marking

Non-compliance with essential requirements and Articles 13–14: fines up to €15,000,000 or 2.5% of worldwide turnover (Art. 64(2)). Operator obligations: up to €10,000,000 or 2% (Art. 64(3)).

Frequently asked questions

Does the CRA apply to my SaaS?
Generally no: services running entirely on your own infrastructure are not “products with digital elements”. But if you ship client software (an app, agent, connector), those installed parts can fall in scope.
What about free open-source software?
Non-monetised OSS falls outside the CRA. Monetised open source (paid distribution, or support/licensing tied to the product) is treated like any other commercial product.
When do my obligations start?
Main application is 11 December 2027. Art. 14 reporting duties (manufacturers only) start 11 September 2026; the Chapter IV notified-body framework has applied since 11 June 2026.
Do I need CE marking for my software?
Once the CRA fully applies (11 December 2027), in-scope manufacturers affix CE marking visibly, legibly and indelibly, plus an EU declaration of conformity.
What is an SBOM and do I need one?
A machine-readable inventory of your product's components. The CRA requires one covering at least the top-level dependencies, in a common format such as CycloneDX or SPDX.
How long must I support my product?
At least five years from last placing on the market, or the expected use time where the product is expected to be in use for less than five years; declared visibly, with security updates throughout.
I resell products: do I have duties?
Yes: act with due care, confirm CE marking and documentation are present, and don't supply products you know to be non-compliant. Importers carry additional verification and labelling duties.
What are the CRA fines?
Up to €15,000,000 or 2.5% of worldwide turnover for breaches of the essential requirements and Articles 13–14; up to €10,000,000 or 2% for importer/distributor obligations (Art. 64).
Which conformity route applies to my product?
Most products: internal control (self-assessment). Annex III Class I products (browsers, password managers, routers): self-assessment plus full technical documentation. Annex III Class II (firewalls, hypervisors) and Annex IV critical products (security boxes, smartcards): notified body required.
Is this legal advice?
No: orientation grounded in the Official Journal, with verbatim citations on every item so you can verify. For a binding assessment, consult a qualified lawyer.

More depth: the full FAQ (34 evidence-checked answers) and the CRA glossary with verbatim definitions.

Documents after the check

  • Verification checklist pack · €49: role-specific checklist for importers and distributors, plus their vulnerability-notification duties under Articles 19–20.
  • CRA compliance pack · €199: classification memo, vulnerability-handling procedure, SBOM policy, secure-by-default checklist, support-period statement, Annex V index.
  • Notified-body readiness pack · €299: everything above plus conformity-assessment preparation guide and regulatory-watch updates until December 2027.

Prices final; seller not VAT-registered (small-business exemption). Automated compliance documents, not legal advice.