Back to blog
    Compliance

    CRA for software and digital products: what should you have tested?

    Sectricity Security TeamSeptember 21, 2026

    Since 11 September 2026 the Cyber Resilience Act requires manufacturers to report exploited vulnerabilities. What it means for your product and what you should have tested.

    CRACyber Resilience ActProduct securityPentestAPI pentest

    TL;DR

    • The CRA (Regulation (EU) 2024/2847) is European regulation for products with digital elements, such as software, apps and smart devices.
    • Since 11 September 2026 the reporting duty applies: report actively exploited vulnerabilities and severe incidents through the ENISA platform, with a first notification within 24 hours.
    • The remaining obligations, such as design and development requirements, apply from 11 December 2027.
    • A pentest shows whether a vulnerability can really be exploited and whether your fix works. It does not replace your reporting and incident process and does not make your product CRA compliant.
    • Start with an overview of your products, an internal reporting process and a test of the parts customers and attackers reach first.

    Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through a European platform. Anyone who puts software, apps or smart devices on the European market gets a new duty, including for products that are already on the market.

    That duty does not replace security, it makes security more visible. Below you read what the Cyber Resilience Act (CRA) is, what already applies and what only follows in December 2027. We also explain what an API pentest or a pentest of your applications can and cannot do.

    Product chip with a shield and check mark inside a 24-hour ring, symbolising product security and the CRA reporting duty

    What is the Cyber Resilience Act?

    The Cyber Resilience Act is European regulation that makes cybersecurity mandatory for products with digital elements made available on the European market. Think of software, apps and devices with software. The regulation entered into force on 10 December 2024 and applies in phases.

    What applies since 11 September 2026?

    Manufacturers must report two kinds of events: actively exploited vulnerabilities in their product and severe incidents that affect the security of the product. The report goes through ENISA's Single Reporting Platform and so reaches the national CSIRT and ENISA at the same time.

    A first warning follows within 24 hours, a more complete notification within 72 hours. The reporting duty also applies to products already on the market. According to the European Commission's guidance of 27 July 2026, you do not have to report retroactively what you already knew before 11 September 2026.

    Fines can reach 15 million euro or 2.5% of worldwide annual turnover.

    What follows from 11 December 2027?

    From 11 December 2027 the remaining CRA obligations apply, such as requirements for the design and development of the product, vulnerability handling over its lifetime and CE marking. That may seem far away, but for products you are building now the work starts today.

    What can a pentest do, and what can it not do?

    A pentest shows whether a vulnerability in your product can really be exploited, what the impact is and whether your fix works. That makes it easier to decide quickly what to fix and what you need to report.

    A pentest does not replace your reporting and incident process. It cannot establish whether a vulnerability is being exploited in the wild, and it does not make your product CRA compliant. See it as technical evidence within your product security.

    Where do you start?

    • Make an overview of your products with digital elements and who is responsible for them.
    • Agree internally who files a report and how you get a first warning ready within 24 hours.
    • Test the parts that get hit first: APIs, web applications and integrations.
    • Plan a retest after every fix, so you can show the risk is closed.

    Frequently Asked Questions

    What is the Cyber Resilience Act (CRA)?

    The CRA is European regulation (Regulation (EU) 2024/2847) for products with digital elements, such as software, apps and smart devices. It requires manufacturers to build cybersecurity into their product and to manage vulnerabilities.

    Since when does CRA reporting apply?

    Since 11 September 2026. Manufacturers report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. The remaining obligations apply from 11 December 2027.

    Does a pentest make my product CRA compliant?

    No. A pentest is technical evidence that vulnerabilities can really be exploited and that your fix works. Conformity also covers design, documentation and processes. You can use an API pentest or a web application pentest as part of your approach.

    Does my software fall under the CRA?

    That depends on what you deliver. The CRA applies to products with digital elements made available on the European market, such as software, apps and devices with software. Pure online services are usually not covered. Check this for your situation with a lawyer or compliance partner.

    What should I have tested before I release a product?

    Start with the parts customers and attackers reach first: APIs, web applications, authentication and integrations. After remediation, a retest confirms the fix works. For AI features in your product, an AI systems pentest helps.

    Related services and resources

    If you want your product tested technically, start with our API pentest or web application pentest. For follow-up tests after a change, RedSOC, on-demand pentesting works well. On the European Commission's website you find the explanation of CRA reporting.