Regulation (EU) 2024/2847
The Cyber Resilience Act, before 11 September 2026
From that date, becoming aware that a vulnerability in your product is being actively exploited starts a 24-hour clock. Everything here is free, needs no account, stores nothing, and cites the article behind every step.
Start here
Or start from what you build
We ran it on ourselves
legalithm (CLI) and legalithm-mcp-server — Published on npm, installable worldwide including the EU. The verdict below is produced by calling our own classifier at build time, not stored, so it changes if the engine changes its mind about us.
in scope, manufacturer.
The inputs, and why each is set that way
hasDataConnection: trueArticle 2(1)The classification path is offline and deterministic. The product is not: the CLI sends telemetry, fetches the KEV feed, and makes authenticated API requests. Article 2(1) asks about the product, and reasonably foreseeable use is broad.
commercialActivity: trueArticle 3(22)Everything is free while we build, and free is not the test. Supply in the course of a commercial activity is, and ours is.
placedOnEuMarket: trueArticle 2(1)Published on npm and installable in the EU. Scope follows the market, not our address.
annexIii: null, annexIv: falseAnnex III and Annex IVA compliance CLI is not a listed important or critical product. This decides the conformity route, not whether we are in scope.
isFoss: falseopen-source steward provisionsParts are source-available and the packages are published under our own name in a commercial activity, so we do not claim the carve-out. It is narrower than it is usually quoted and we would rather not lean on it.
Which means the 11 September deadline is ours too, and the readiness questions we ask you are ones we have to answer.
Questions
- When does the CRA reporting obligation start?
- Article 14 reporting obligations apply from 11 September 2026. General application of the Cyber Resilience Act follows on 11 December 2027, so the reporting duty arrives roughly fifteen months before the essential requirements do.
- How long do I have to report an actively exploited vulnerability?
- 24 hours for an early warning to CSIRT designated as coordinator, and ENISA, 72 hours for the fuller notification, and 14 days for the final report. All three run from the moment you become aware, not from confirmation and not from the next business day.
- Does the Cyber Resilience Act apply to SaaS?
- Often not, and the exception matters. Browser-accessed software with nothing shipped to the user is generally outside scope, unless it is a remote data processing solution under Article 3(2). That has three legs and all must hold, the deciding one usually being whether the absence of your processing would break a function of the product. Degraded is not broken.
- Is there an exemption for small companies or free products?
- No to both. The CRA has no company-size exemption, and the definition of making available on the market covers products supplied free of charge in the course of a commercial activity. The open-source steward provisions are a real carve-out but narrower than they are usually quoted.
- What are the CRA penalties?
- Article 64 sets them. We do not model penalties in our corpus, so we do not quote a figure here; read Article 64 in the Official Journal rather than taking a number from a vendor page.
- Has Legalithm run its own CRA check?
- Yes, and the result is on this page: in scope, as manufacturer. It is computed by running our own classifier at build time rather than stored, so it changes if the engine changes its mind about us.