For US software and product teams

Cyber Resilience Act compliance for US companies.

Selling software, connected products or digital products in the EU? Understand when the CRA may be relevant, which questions to resolve, and how to prepare product-security evidence without assuming every US company is in scope.

Short answer: a company's US location does not by itself remove a product from CRA scope. The regulation applies to qualifying products with digital elements made available on the EU market in the course of commercial activity. Whether a specific product meets those conditions depends on what it is, how it connects, how it is offered, and whether a specific exclusion or sector regime applies.

Assess the product and the relevant business roles individually. A company may have one product in scope and another outside it; a cloud service may have a different boundary from software shipped with a device. Vellaci's existing CRA scope guide explains the definitions, while the readiness assessment provides a preliminary product-oriented gap map.

QuestionWhy it mattersEvidence to gather
Is the product made available in the EU?The regulation is tied to placing or making available a qualifying product on the EU market.Distribution, sales, target-market and product availability records.
Is this a product with digital elements?The definition includes software or hardware products and certain remote data processing solutions.Product architecture, connectivity and backend dependencies.
Which role does the company perform?Manufacturer, importer, distributor and authorised representative duties differ.Brand ownership, contracts, EU importer/distributor arrangements and mandates.
Does an exclusion or sector law apply?Some products are excluded or governed by sector-specific Union legislation.Product classification and the applicable sector-law analysis.

A practical starting point

Build the evidence around the product.

Once the scope questions are being reviewed, connect product inventory to the technical work engineers already do.

  1. 1 · Inventory

    List the EU-facing software and connected products, their versions, owners and support periods.

  2. 2 · Know components

    Generate a machine-readable SBOM per released version and preserve its origin.

  3. 3 · Review exposure

    Match components to advisories and exploitation evidence; record product-specific decisions and remediation.

  4. 4 · Preserve evidence

    Keep risk reasoning, update practices, vulnerability handling and conformity records retrievable by product and release.

An SBOM supports component visibility. It does not establish CRA scope, prove conformity, or make a vulnerability reportability decision. Keep those conclusions with the responsible people and their supporting evidence.

Current regulation

Key dates and source

Last verified 29 September 2026 against the Official Journal text of Regulation (EU) 2024/2847. Chapter IV on notifying conformity-assessment bodies applied from 11 June 2026; Article 14 reporting applies from 11 September 2026; the regulation generally applies from 11 December 2027.

This guide is general product information, not legal advice or a binding applicability determination. Have counsel or your qualified compliance adviser review product scope, roles and transition questions.

Questions from US teams

Cyber Resilience Act applicability FAQ

Does the Cyber Resilience Act apply to US companies?
It can. The CRA does not provide a general exemption based on the manufacturer's country. It concerns products with digital elements made available on the EU market in commercial activity. A US company should assess each product, how it reaches EU users, its connectivity and any sector exclusions before deciding whether the rules apply.
Does every US software company selling to an EU customer fall under the CRA?
No. A sale to an EU customer alone is not enough to settle scope. The product must meet the CRA definitions, including product with digital elements and commercial availability; the software must be connectable directly or indirectly to a device or network. Pure cloud services are generally not products with digital elements as such, while product-dependent remote data processing can be included. Review the design and distribution facts for each offering.
Who is responsible if the manufacturer is outside the EU?
The manufacturer remains responsible for its manufacturer obligations. The CRA also assigns duties to other economic operators such as importers and distributors, and provides for authorised representatives. The correct roles and main establishment are product and business-structure questions to document with qualified advisers.
When do the CRA requirements apply?
Chapter IV provisions concerning notification of conformity-assessment bodies have applied since 11 June 2026. Article 14 reporting obligations apply from 11 September 2026. The regulation generally applies from 11 December 2027. The official regulation is the controlling source for exact transition and product-specific questions.
Should a US team start with an SBOM?
An SBOM is a useful technical foundation for component visibility and vulnerability handling. Annex I Part II requires manufacturers to draw up a commonly used, machine-readable SBOM covering at least top-level dependencies as part of identifying and documenting components and vulnerabilities. It does not answer every scope or conformity question by itself.

Start with a product-level gap map.

Review preliminary scope, vulnerability handling, component visibility and evidence areas in Vellaci's existing assessment workflow.