Venvera Cyber Resilience Act product security compliance dashboard
The CRA module — shown with sample data.

The Cyber Resilience Act (CRA) framework in Venvera helps your organisation manage its obligations under Regulation (EU) 2024/2847, the first EU-wide law setting mandatory cybersecurity requirements for products with digital elements. It entered into force on 10 December 2024 and is built for the compliance owner who has to demonstrate product conformity to a market surveillance authority.

Regulatory Context

Who is in scope?

Scope follows the product and your role. A product with digital elements is broadly any software or hardware whose intended or reasonably foreseeable use includes a data connection to a device or network, so the scope reaches beyond IoT into firmware, operating systems, libraries and software sold as a product. The primary duty-holder is the manufacturer, who carries the essential requirements. Importers and distributors have lighter duties to verify that the manufacturer did its job. A limited set of products covered by sector rules (certain medical devices, motor vehicles, civil aviation) are carved out.

The key deadlines

The regulation entered into force on 10 December 2024. The reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. The full body of obligations, the essential requirements, vulnerability handling, conformity assessment, CE marking and documentation, applies from 11 December 2027.

Using the CRA module

The module gives you a scoped control set (applicability and product classification, economic-operator role, the Annex I essential requirements, vulnerability handling and SBOM, coordinated disclosure, incident reporting, conformity assessment and CE marking, technical documentation, the support period, and importer/distributor and third-party-component due diligence), a gap assessment, and a controls workspace where you record evidence.

ℹ️
Which Annex I Part I requirements apply, and how, is driven by a per-product cybersecurity risk assessment (CRA-3). Record that assessment first so the rest of the essential-requirement controls are scoped correctly.

Evidence you already hold

Many CRA controls overlap DORA, NIS2, ISO 27001 and SOC 2: secure development, vulnerability management, risk assessment, incident reporting, supplier and component due diligence, and security testing. Because Venvera maps controls across frameworks, evidencing one satisfies its CRA equivalent, and Evidence Autopilot chases only the CRA-specific gaps. The product classification, SBOM, CE marking, EU declaration of conformity, support period and ENISA reporting duties are CRA-specific and are never auto-satisfied by unrelated evidence.

⚠️
Venvera documents and tracks your CRA compliance programme. It does not perform product security testing, code analysis or SBOM generation itself: those artefacts are produced by your engineering tooling and recorded as evidence against the controls.