Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
EUEnforcement: September 11, 2026MEDIUM coverage

EU Cyber Resilience Act (CRA) — Software & AI Products: AI Compliance Requirements

The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and publishers of any software or hardware "product with digital elements" sold or made available in the EU to meet essential cybersecurity requirements. This includes SaaS products, AI applications, connected devices, and any software deployed by EU users. Phase 1 reporting obligations (vulnerability incident reporting) apply from September 11, 2026. Full compliance — including security-by-design requirements — required by December 11, 2027. AI software products are in scope as products with digital elements.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

December 10, 2024

Enforcement Begins

September 11, 2026

Maximum Penalty

€15,000,000 or 2.5% of global annual turnover for essential requirement violations

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Vulnerability & Incident Reporting (Sep 11, 2026)

Critical

From September 11, 2026: Report actively exploited vulnerabilities in your software or AI product within 24 hours of discovery (early warning) and submit a full notification within 72 hours. Final report due within 14 days. Report via ENISA's Single Reporting Platform (SRP) addressed to the CSIRT where you have your main EU establishment.

Deadline: September 11, 2026

CRA Art. 14

Vulnerability Disclosure Policy (VDP)

High Priority

Establish and publish a Vulnerability Disclosure Policy (VDP) allowing security researchers to responsibly report vulnerabilities in your product. Acknowledge reports promptly and provide remediation timelines. Required before September 2026 reporting obligations take effect.

Deadline: September 11, 2026

CRA Annex I, Part II

Security-by-Design Requirements (Dec 2027)

High Priority

By December 11, 2027: Design and develop your AI/software product with no known exploitable vulnerabilities, secure default configurations, minimal attack surface, and data protection mechanisms. Maintain a Software Bill of Materials (SBOM) and security architecture documentation.

Deadline: December 11, 2027

CRA Annex I, Part I; Art. 13

Security Update Lifecycle Commitment

Medium Priority

Commit to providing security updates for the expected product lifetime (minimum period to be set by Commission). Notify users of security issues. Publish a clear end-of-life policy so users know when updates will cease.

Deadline: December 11, 2027

CRA Art. 13(8)-(11)

Who Does This Apply To?

Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use includes a data connection) that is made available on the EU market — including connected devices, embedded software, and AI applications shipped as products. Scope turns on the product category, not company size, though micro and small enterprises receive lighter administrative treatment. Free and open-source software supplied outside the course of a commercial activity is excluded, and products already covered by certain sector regimes (e.g. medical devices, motor vehicles, certified aviation) are carved out. In-scope manufacturers must meet essential cybersecurity requirements (security-by-design, vulnerability handling, security updates across a defined support period) and operate a coordinated vulnerability-disclosure policy. Phased timeline: vulnerability/incident reporting obligations apply from 11 September 2026; full compliance (including the security-by-design essential requirements) is required by 11 December 2027. Regulation (EU) 2024/2847; penalties reach EUR 15,000,000 or 2.5% of global annual turnover.

Recent Regulatory Guidance

guidance2025-06

European Commission + ENISA — CRA implementation guidance and product classification (2025)

European Commission issued implementation guidance clarifying CRA scope: 'products with digital elements' is broadly defined and covers SaaS, IoT devices, embedded systems, mobile apps, and AI software where it has direct or indirect logical or physical data connection to a device or network. ENISA published a draft technical standards roadmap mapping CRA's Annex I essential cybersecurity requirements onto recognized European standards (EN 18031, ETSI EN 303 645). Phased timeline: vulnerability-reporting obligations from September 11, 2026; full essential-requirement compliance and conformity assessment from December 11, 2027.

Key Case Law & Precedent

Schrems II — Data Protection Commissioner v. Facebook Ireland (CJEU C-311/18)

Court of Justice of the European Union · 2020

Background only — NOT a CRA case (no CRA-specific enforcement action exists yet; the CRA's reporting obligations only commence 11 September 2026). Cited solely to illustrate the EU's general regulatory philosophy of a uniform protection floor regardless of where a company is established, which the CRA also embodies for product cybersecurity via its Annex I essential requirements. Schrems II itself concerned GDPR cross-border data-transfer mechanisms, not product security.

Outcome: Privacy Shield invalidated; SCCs upheld with supplementary measures requirement

Case reference

Industry Playbooks covering EU Cyber Resilience Act (CRA) — Software & AI Products

These industry playbooks include jurisdiction-specific checklist items and guidance for EU Cyber Resilience Act (CRA) — Software & AI Products.

Frequently Asked Questions

Does EU Cyber Resilience Act (CRA) — Software & AI Products apply to my business?

The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and publishers of any software or hardware "product with digital elements" sold or made available in the EU to meet essential… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under EU Cyber Resilience Act (CRA) — Software & AI Products is: €15,000,000 or 2.5% of global annual turnover for essential requirement violations. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with EU Cyber Resilience Act (CRA) — Software & AI Products?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan