EU Cyber Resilience Act (CRA) · vRegulation (EU) 2024/2847
EU Cyber Resilience Act (CRA)
EU Cyber Resilience Act (CRA) — 86% of in-scope requirements covered.
13 requirements · 11 in scope (8 enforced · 3 designed) · 2 out-of-scope (outside KYE™’s authority layer). The 86% is weighted over the in-scope base.
Source: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). Fully applicable 11 December 2027; the vulnerability-and-incident reporting obligation (Article 14) applies from 11 September 2026.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Conformity assessment, CE marking & market surveillance (Articles 13, 32, Annex VII) | 2 | 0 | 1 | 0 | 0 | 50% |
| Reporting of actively exploited vulnerabilities & severe incidents (Article 14) | 2 | 2 | 0 | 0 | 0 | 100% |
| Essential cybersecurity requirements — security-by-design (Annex I, Part I) | 4 | 4 | 0 | 0 | 0 | 100% |
| Vulnerability handling requirements (Annex I, Part II) + SBOM | 5 | 2 | 2 | 0 | 0 | 75% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
cra.A13.12 |
Article 13(12) + Annex VII — Manufacturer draws up technical documentation (including the SBOM) and keeps it at the disposal of market-surveillance authorities for ten years | designed | audit_events: kye.compliance.attestation.v1, kye.evidence.pack.v1engines: internalconstitution_refs: constitution/30-AUDIT-WORM-RETENTION.md |
cra.A32 |
Article 32 + Annex VIII — Conformity assessment of the product and affixing of the CE marking before placing on the market | out-of-scope | constitution_refs: constitution/15-MCP-AND-SDK.md |
cra.A14.1 |
Article 14(1) — Manufacturer notifies any actively exploited vulnerability contained in the product to the CSIRT designated as coordinator and to ENISA (early warning ≤24h, notification ≤72h, final report ≤14 days) | enforced | audit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1, kye.evidence.pack.v1engines: internal, internalrule_packs: kye:rule-pack:cyber-resilience-incidentconstitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md |
cra.A14.2 |
Article 14(2) — Manufacturer notifies any severe incident having an impact on the security of the product to the coordinator CSIRT and ENISA, with the same staged timeline | enforced | audit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.evidence.pack.v1engines: internal, internal, internalrule_packs: kye:rule-pack:cyber-resilience-incidentconstitution_refs: constitution/13-RESILIENCE-LOOP.md |
cra.annex1.I.1 |
Annex I, Part I (1) — Products with digital elements designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks (security-by-design) | enforced | audit_events: kye.purpose.admissibility.v1, kye.evidence.decision_map.v1engines: internal, internalrule_packs: kye:rule-pack:cyber-resilience-incidentdictionaries: internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md |
cra.annex1.I.2.a |
Annex I, Part I (2)(a) — Products made available without known exploitable vulnerabilities | enforced | audit_events: kye.evidence.decision_map.v1, kye.compliance.attestation.v1engines: internaldictionaries: internalconstitution_refs: constitution/15-MCP-AND-SDK.md |
cra.annex1.I.2.d |
Annex I, Part I (2)(d) — Protect confidentiality, integrity and availability of data via state-of-the-art mechanisms; processed data limited to what is necessary | enforced | audit_events: kye.audit.event.v1, kye.evidence.pack.v1engines: internal, internalconstitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/31-DATA-GOVERNANCE-PACK.md |
cra.annex1.I.2.j |
Annex I, Part I (2)(j) — Record and monitor relevant internal activity, including access to or modification of data, services or functions (security logging) | enforced | audit_events: kye.audit.event.v1engines: internal, internalconstitution_refs: constitution/35-STREAMING-LOGS.md, constitution/30-AUDIT-WORM-RETENTION.md |
cra.annex1.II.1 |
Annex I, Part II (1) — Identify and document vulnerabilities and components, including by drawing up a software bill of materials (SBOM) in a commonly used machine-readable format covering at least the top-level dependencies | designed | audit_events: kye.evidence.decision_map.v1, kye.evidence.tool_call_pin.v1engines: internalconstitution_refs: constitution/71-DOCUMENT-INTELLIGENCE-RAIL.md |
cra.annex1.II.2 |
Annex I, Part II (2) — In relation to the risks, address and remediate vulnerabilities without delay, including by providing security updates | enforced | audit_events: kye.evidence.decision_map.v1, kye.signal.incident.opened.v1engines: internal, internalrule_packs: kye:rule-pack:cyber-resilience-incidentdictionaries: internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md |
cra.annex1.II.3 |
Annex I, Part II (3) — Apply effective and regular tests and reviews of the security of the product | enforced | audit_events: kye.compliance.attestation.v1engines: internaldictionaries: internalconstitution_refs: constitution/15-MCP-AND-SDK.md |
cra.annex1.II.4 |
Annex I, Part II (4) — Put in place and enforce a coordinated vulnerability disclosure (CVD) policy | designed | audit_events: kye.evidence.decision_map.v1, kye.comms.dispatched.v1engines: internalconstitution_refs: constitution/38-COMMS-RAIL.md |
cra.annex1.II.6 |
Annex I, Part II (6) — Once a security update is available, disseminate it without delay and free of charge, with advisory messages informing users of required actions | out-of-scope | constitution_refs: constitution/38-COMMS-RAIL.md |