Why now – Palantir alternatives for Europe: what 'sovereign' actually means, and how European public bodies are decidingRegister →
Cyber Resilience Act

Secure by design, with evidence that starts at the code

The Cyber Resilience Act makes cybersecurity a condition of placing hardware and software on the EU market. Scrydon is built secure by default and treats the CRA's manufacturer duties as its own — and gives customers who ship products on the platform the controls and evidence they need.

Written for the security, risk and data protection teams who have to evidence this — not just describe it.

What it is

Cyber Resilience Act (CRA)

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets horizontal cybersecurity requirements for products with digital elements — hardware and software with a direct or indirect connection to a device or network — placed on the EU market. Manufacturers must design, develop and produce products in line with essential cybersecurity requirements, run a vulnerability-handling process for the product's support period, maintain a software bill of materials, provide security updates, report actively exploited vulnerabilities and severe incidents through the single reporting platform run by ENISA, and demonstrate conformity through the CE marking. Higher-risk 'important' and 'critical' product classes face stricter conformity assessment. The regulation entered into force on 10 December 2024; reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027, with penalties of up to EUR 15 million or 2.5% of worldwide turnover.
At a glance
Jurisdiction
European Union
Applies to
Manufacturers, importers and distributors of products with digital elements — hardware and software — placed on the EU market, including software vendors and the organisations that build connected products on top of them.
Talk to us
How we help

How Scrydon helps you comply

Controls are built into the runtime, so compliance is something you can demonstrate with evidence drawn from the platform itself — not assembled after the fact.

Secure by default, out of the box

Fail-closed defaults, an mTLS service mesh, three-tier access control and a single policy-as-code decision point mean the platform ships in a secure configuration with a minimal attack surface. That is what the CRA's essential requirements ask of a product as delivered — secure by default, protecting confidentiality and integrity, and exposing no more than it needs to.

Vulnerability handling and controlled updates

As a manufacturer of software, Scrydon maintains a vulnerability-handling and coordinated-disclosure process for the platform and provides security updates across the support period. Because deployments run from reproducible, policy-governed configuration, you can roll those updates through your own environments in a controlled, evidenced way — including air-gapped ones.

Logging for incident detection and reporting

The essential requirements expect a product to record and monitor relevant internal activity, including access to or modification of data. The immutable, queryable audit log does exactly that, and gives you the actor, IP and decision detail needed to characterise an actively exploited vulnerability or severe incident inside the CRA's 24-hour and 72-hour windows.

A supply chain you can enumerate

The CRA expects manufacturers to know what is in their products. Scrydon keeps the AI and data supply chain explicit — external AI vendors are opt-in, models run where you choose, and platform components are documented — so that your own software bill of materials and technical documentation can account for the platform and everything it reaches.

Framework evidence packs

Evidence packs map platform controls to the CRA's essential requirements alongside ISO 27001 and NIS2, giving product-security, compliance and conformity-assessment work a documented starting point for the technical documentation and risk assessment the regulation requires.

Key requirements

What CRA asks of you

  • Design, develop and produce products in line with the CRA's essential cybersecurity requirements, secure by default.
  • Carry out a cybersecurity risk assessment and keep technical documentation, including a software bill of materials.
  • Operate a vulnerability-handling process with coordinated disclosure and free security updates over the support period (at least five years unless the product's expected lifetime is shorter).
  • Report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report within 14 days.
  • Complete the applicable conformity assessment — stricter for important and critical products — and affix the CE marking.
  • Give users clear security information, instructions and a defined support period.
  • Meet the timeline: reporting obligations from 11 September 2026, the main obligations from 11 December 2027.
Where the line sits

What we provide, and what stays yours

No vendor can be compliant on your behalf. We build the controls into the platform and produce the evidence; the assessment of your own deployment stays with you. Here is the split, stated plainly, so it does not surface late in a security review.

Scrydon provides

  • Controls enforced in the runtime by default, rather than left to configuration.
  • An immutable, queryable record of what ran, on whose authority, and against which data.
  • Evidence packs mapped to the obligations set out on this page.
  • Documented architecture and data flows your assessors can read.
  • Deployment inside your own perimeter — up to fully disconnected.

You remain responsible for

  • Classifying your own systems and data under the framework.
  • Your risk assessment, data protection impact assessment and conformity assessment.
  • Who you grant access to, and on what basis.
  • Your incident response and reporting obligations.
  • The operational security of the environment you run it in.
FAQ

Frequently asked questions

Does the Cyber Resilience Act apply to Scrydon itself?+
Yes. Software placed on the EU market is a product with digital elements, so Scrydon is a manufacturer under the CRA and treats the obligations as its own: secure-by-design engineering, a vulnerability-handling and disclosure process, security updates over the support period, and readiness for the reporting duties that apply from 11 September 2026. We describe our posture on the Trust & Security page and publish status rather than promises. This page also covers how the platform supports customers who are manufacturers in their own right.
Does the CRA apply to us if we build on Scrydon?+
If you place a product with digital elements on the EU market — a device, an application, or software with connectivity — you are a manufacturer and the CRA applies to that product, including the parts of it built on the platform. Software used only internally, and services delivered purely as SaaS, are generally outside the CRA, though remote data processing that a product depends on is in scope and services fall under NIS2. Where you are in scope, Scrydon supplies secure defaults, logging and documented components that your own conformity work can rely on.
When do CRA obligations start to apply?+
The regulation entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, provisions on conformity assessment bodies from 11 June 2026, and the main obligations — essential requirements, vulnerability handling, conformity assessment and CE marking — from 11 December 2027. Because those dates fall inside the lifetime of products being designed now, building on a secure-by-default platform is a way to meet them without a retrofit.
How does the platform help with the essential cybersecurity requirements?+
The essential requirements in Annex I cover secure-by-default configuration, protection of confidentiality and integrity, access control, minimised attack surface, resilience against attack, and logging of relevant internal activity. Scrydon's fail-closed defaults, mTLS service mesh, three-tier access control, policy-as-code authorisation, DLP guardrails and immutable audit log map to each of these, and evidence packs document the mapping for your technical file.
What are the vulnerability and incident reporting timelines, and how does Scrydon help?+
Manufacturers must give early warning of an actively exploited vulnerability or severe incident within 24 hours of becoming aware, a fuller notification within 72 hours and a final report within 14 days (one month for incidents), through the single reporting platform. The audit log gives you the actor, IP and decision detail to characterise what happened quickly; Scrydon's own disclosure process keeps you informed about the platform. Filing the notifications for your product remains your obligation as manufacturer.
How does Scrydon support the software bill of materials?+
The CRA requires manufacturers to identify and document the components in their products, at least at top-level dependency depth, in a machine-readable SBOM. Scrydon documents the components it ships so that your product's SBOM and technical documentation can account for the platform, and keeps the AI supply chain explicit through opt-in external vendors and your choice of where models run. Assembling and maintaining the SBOM for your product as a whole remains your responsibility.
How does the CRA relate to NIS2 and ISO 27001?+
The CRA regulates products; NIS2 regulates the entities and services that use them; ISO 27001 governs an organisation's security management. They are designed to reinforce each other: CRA-conformant products help NIS2 entities evidence supply-chain security, and an ISO 27001 ISMS is a natural home for the vulnerability-handling and secure-development processes the CRA demands. Scrydon's evidence packs map its controls to all three so the same evidence serves each.

Or write to us

Tell us what you are working on and who should reply. A person reads it and replies within one business day.

We only use these details to reply to you. Privacy policy

Prefer to write? Email hello [at] scrydon.com and we will get back to you.