CRA's reporting obligation is now in effect. Applus+ Laboratories' Cybersecurity Business Unit Director Jose Ruiz Gualda joins Taipei in person to share first-hand European conformity assessment insights alongside SVS. Sept 18, limited seats.

The essential requirements apply to products placed on the EU market from 11 December 2027 onward. However, a substantial modification to an existing product can make it count as newly placed — and the reporting obligations from 11 September 2026 apply to manufacturers regardless of when the product shipped.
Only if another EU law already covers the same risk: medical devices (MDR / IVDR), motor vehicles, certified aviation products, marine equipment, and products built solely for national security or defence. Everything else with digital elements is in scope by default.
Most likely not: roughly 90% of products fall into the default class and may self-assess against the essential requirements — especially when applying harmonized standards such as EN 18031. Important Class I (until harmonized standards apply), Class II and critical products are the exceptions. Classification is step one of any CRA engagement.
RED applies to specific radio equipment categories and is already in force; the CRA covers all products with digital elements — a much broader scope. If you've already gone through RED cybersecurity conformity, that evidence isn't wasted — it's the foundation your CRA technical file builds on.
Your SBOM must be machine-readable — SPDX or CycloneDX, not a hand-compiled document. That format matches the EUVD's API, so you can cross-reference your components against EU Vulnerability Database entries and flag actively exploited ones. Open source supplied outside a commercial activity is exempt; once it ships inside your commercial product, it belongs in your SBOM and your vulnerability handling.