The Cyber Resilience Act sets security rules for "products with digital elements" sold in the EU. That covers hardware and software, and it does not exempt small companies. A two-person team selling a self-hosted Laravel application has the same core obligations as a large vendor.
The short answer
If you sell or otherwise make available installable software in the EU as part of a commercial activity, the CRA very likely applies to you. "Installable" is the important word: software your customer downloads and runs on their own server, desktop or device.
Common PHP and Laravel cases
| What you ship | Likely position |
|---|---|
| A self-hosted app customers install (a helpdesk, a shop, a CMS, an admin panel) | In scope |
| A paid plugin, theme or module (Laravel, WordPress, Magento, Drupal) | In scope |
| A free open-source package with no money involved | Generally out of scope, because there is no commercial activity |
| An open-source package with a paid "pro" version or paid support | Likely in scope. The Commission's guidance treats charging fees or monetising related services as commercial activity |
| Pure SaaS that customers only use in the browser | Generally out of scope on its own. It can come in as a "remote data processing solution" if an in-scope product needs it to perform one of its functions |
The Commission published guidelines on the scope in July 2026. They are not legally binding, but they are what market surveillance authorities will read. For edge cases, check them and ask a lawyer.
The dates that matter
- 11 September 2026: reporting obligations apply. You must report actively exploited vulnerabilities and severe incidents within 24 hours. This already covers products you put on the market before the CRA. See CRA Article 14 reporting.
- 11 December 2027: everything else applies to products placed on the market from that date, and to older products that receive a substantial modification.
What you need by 11 December 2027
- Security by design. Meet the essential requirements in Annex I, Part I: secure defaults, no known exploitable vulnerabilities at release, protection of data, security updates.
- Vulnerability handling. Annex I, Part II: a contact address for reports, a coordinated vulnerability disclosure policy, security fixes delivered without delay and free of charge, and an SBOM covering at least the top-level dependencies.
- A support period. Article 13(8): at least five years, unless the product is expected to be used for less. Publish it so buyers can see it.
- A risk assessment and technical documentation for each product, kept for ten years.
- Conformity assessment, CE marking and an EU Declaration of Conformity. Most software falls in the default category, where the manufacturer can carry out the assessment itself. Products listed in Annex III (important) or Annex IV (critical) have stricter routes.
What happens if you ignore it
Article 64 allows fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential requirements and the reporting obligations. Authorities can also order a product off the market. For a small vendor, the more realistic risk is losing deals: EU buyers are starting to ask for an SBOM, a support period and a disclosure policy before they sign.
A checklist for this month
- List every product and version you sell or support in the EU.
- Publish a security contact: a security.txt file and a short disclosure policy.
- Decide who owns the 24-hour reporting clock, and prepare the report templates.
- Generate an SBOM from your
composer.lockandpackage-lock.jsonfor each release. - Decide and publish a support period for each product.
This guide explains the regulation in plain terms. It is not legal advice. For decisions about your obligations, speak to a qualified adviser.