How can I help with the Cyber Resilience Act?

Free AI guidance for Cyber Resilience Act compliance.

About the Cyber Resilience Act assistant

Seeded with Cyber Resilience Act concepts: the EU regulation on cybersecurity for products with digital elements placed on the EU market, Regulation (EU) 2024/2847; the roles of manufacturer, importer, and distributor; the essential cybersecurity requirements and the duty to handle vulnerabilities across the support period; the software bill of materials (SBOM); CE marking and the conformity assessment routes; the risk classes for default, important (Class I and Class II), and critical products; and the reporting of actively exploited vulnerabilities and severe incidents through the single reporting platform run with ENISA and the national CSIRTs. The obligations phase in over time, with the vulnerability and incident reporting duties applying first and the main manufacturer obligations following later.

  • Work out whether the Cyber Resilience Act applies to what you sell: whether your product is a product with digital elements placed on the EU market, whether you act as a manufacturer, importer, or distributor, and which obligations follow from that role.
  • Prepare a product to meet the essential cybersecurity requirements: secure-by-design choices, handling vulnerabilities and shipping security updates over the support period, drawing up a software bill of materials (SBOM), and understanding which conformity assessment route may apply for your product's risk class before you draw up the EU declaration of conformity and affix the CE marking.
  • Plan your vulnerability and incident reporting: what counts as an actively exploited vulnerability or a severe incident, the early warning, the fuller notification, and the final report, and how these are sent through the single reporting platform run with ENISA and the national CSIRTs.

It gives guidance to speed up your work. It is not a notified body, it cannot carry out a conformity assessment, draw up your EU declaration of conformity, or affix the CE marking, and it is not legal advice.

Read the full Cyber Resilience Act guide