EU Cyber Resilience Act (CRA) · vRegulation (EU) 2024/2847

EU Cyber Resilience Act (CRA)

EU Cyber Resilience Act (CRA) — 86% of in-scope requirements covered.

13 requirements · 11 in scope (8 enforced · 3 designed) · 2 out-of-scope (outside KYE’s authority layer). The 86% is weighted over the in-scope base.

Source: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). Fully applicable 11 December 2027; the vulnerability-and-incident reporting obligation (Article 14) applies from 11 September 2026.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Conformity assessment, CE marking & market surveillance (Articles 13, 32, Annex VII) 2 0 1 0 0 50%
Reporting of actively exploited vulnerabilities & severe incidents (Article 14) 2 2 0 0 0 100%
Essential cybersecurity requirements — security-by-design (Annex I, Part I) 4 4 0 0 0 100%
Vulnerability handling requirements (Annex I, Part II) + SBOM 5 2 2 0 0 75%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
cra.A13.12 Article 13(12) + Annex VII — Manufacturer draws up technical documentation (including the SBOM) and keeps it at the disposal of market-surveillance authorities for ten years designed audit_events: kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
cra.A32 Article 32 + Annex VIII — Conformity assessment of the product and affixing of the CE marking before placing on the market out-of-scope constitution_refs: constitution/15-MCP-AND-SDK.md
cra.A14.1 Article 14(1) — Manufacturer notifies any actively exploited vulnerability contained in the product to the CSIRT designated as coordinator and to ENISA (early warning ≤24h, notification ≤72h, final report ≤14 days) enforced audit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
cra.A14.2 Article 14(2) — Manufacturer notifies any severe incident having an impact on the security of the product to the coordinator CSIRT and ENISA, with the same staged timeline enforced audit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.evidence.pack.v1
engines: internal, internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
constitution_refs: constitution/13-RESILIENCE-LOOP.md
cra.annex1.I.1 Annex I, Part I (1) — Products with digital elements designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks (security-by-design) enforced audit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
dictionaries: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md
cra.annex1.I.2.a Annex I, Part I (2)(a) — Products made available without known exploitable vulnerabilities enforced audit_events: kye.evidence.decision_map.v1, kye.compliance.attestation.v1
engines: internal
dictionaries: internal
constitution_refs: constitution/15-MCP-AND-SDK.md
cra.annex1.I.2.d Annex I, Part I (2)(d) — Protect confidentiality, integrity and availability of data via state-of-the-art mechanisms; processed data limited to what is necessary enforced audit_events: kye.audit.event.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/31-DATA-GOVERNANCE-PACK.md
cra.annex1.I.2.j Annex I, Part I (2)(j) — Record and monitor relevant internal activity, including access to or modification of data, services or functions (security logging) enforced audit_events: kye.audit.event.v1
engines: internal, internal
constitution_refs: constitution/35-STREAMING-LOGS.md, constitution/30-AUDIT-WORM-RETENTION.md
cra.annex1.II.1 Annex I, Part II (1) — Identify and document vulnerabilities and components, including by drawing up a software bill of materials (SBOM) in a commonly used machine-readable format covering at least the top-level dependencies designed audit_events: kye.evidence.decision_map.v1, kye.evidence.tool_call_pin.v1
engines: internal
constitution_refs: constitution/71-DOCUMENT-INTELLIGENCE-RAIL.md
cra.annex1.II.2 Annex I, Part II (2) — In relation to the risks, address and remediate vulnerabilities without delay, including by providing security updates enforced audit_events: kye.evidence.decision_map.v1, kye.signal.incident.opened.v1
engines: internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
dictionaries: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
cra.annex1.II.3 Annex I, Part II (3) — Apply effective and regular tests and reviews of the security of the product enforced audit_events: kye.compliance.attestation.v1
engines: internal
dictionaries: internal
constitution_refs: constitution/15-MCP-AND-SDK.md
cra.annex1.II.4 Annex I, Part II (4) — Put in place and enforce a coordinated vulnerability disclosure (CVD) policy designed audit_events: kye.evidence.decision_map.v1, kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
cra.annex1.II.6 Annex I, Part II (6) — Once a security update is available, disseminate it without delay and free of charge, with advisory messages informing users of required actions out-of-scope constitution_refs: constitution/38-COMMS-RAIL.md