EU Product Regulation

Cyber Resilience Act Readiness

Reporting from 11 Sep 2026 · full application 11 Dec 2027

Cybersecurity-by-design and lifecycle obligations for hardware and software products with digital elements.

11.09.2026reporting obligations begin
11.12.2027full application

Who it is for

Specific scope. Specific owners.

  • Manufacturers of hardware, software and digital components.
  • Product, engineering, security and compliance teams.

Readiness focus

From requirements to an implementable operating model.

The RUNOTECH approach connects governance, processes, controls, training and evidence — without legal oversimplification.

01

Product scope, role and classification.

02

Secure development lifecycle and essential requirements.

03

Vulnerability handling, reporting and technical documentation.

04

Conformity assessment, CE-marking readiness and post-market support.

Indicative deliverables

Evidence-backed outputs designed for use.

01Product applicability & classification memo
02Essential-requirements gap assessment
03Secure-SDLC and vulnerability framework
04Reporting playbook and technical-file plan

Official reference

Always check the current official version.

Open official source

RUNOTECH Readiness Support

Plan the next step for CRA.

Register interest

RUNOTECH Newsletter

Stay informed.

Selected updates on compliance, project management, European projects and the PMI Academy.