Cyber Resilience Act
Regulation (EU) 2024/2847 and the eSeGeCe component libraries. Last updated: August 2026
Regulation (EU) 2024/2847 and the eSeGeCe component libraries. Last updated: August 2026
Customers building products for the European market ask us how the Cyber Resilience Act affects software that embeds our components. This page sets out where the Regulation stands, which obligations fall on us and which fall on you, and what we provide so you can complete your own due diligence file.
Regulation (EU) 2024/2847 entered into force on 10 December 2024, and its obligations arrive in stages:
Until December 2027 no product on the market carries a CRA declaration of conformity, because the framework that issues one is still being put in place. Any supplier claiming a completed CRA conformity assessment today is describing something that does not yet exist. What we can do now, and what this page is for, is give you the evidence your own assessment needs.
Yes. A software library supplied commercially is a product with digital elements in its own right, so the eSeGeCe components fall within the scope of the Regulation and we are their manufacturer. That is separate from your own obligations for the product you place on the market.
The eSeGeCe component libraries are not listed in Annex III or Annex IV of the Regulation. They are not operating systems, hypervisors, container runtimes, firewalls, intrusion detection systems, VPNs, identity management systems, password managers, boot managers, public key infrastructure, network management systems or any other important or critical class.
They therefore fall in the default category, where conformity is established by the manufacturer under the internal control procedure of Module A rather than by a notified body. For your file, this means integrating our components does not by itself pull your product into a higher conformity assessment class. How your own product is classified depends on what your product does.
You are the manufacturer of the product you place on the EU market, and the CE marking and declaration of conformity for that product are yours. Two articles govern the relationship between us:
Annex I Part I asks that a product be delivered with a secure default configuration, that it protect itself against denial of service, and that its attack surface be minimised. That work is already visible in the product. Recent releases made the WebSocket server rate limit incoming control frames, bounded the number of simultaneous connections instead of accepting an unlimited number, added a maximum request body size to the HTTP/2 server, and restricted browser origins allowed to call an MCP server. Transport security is available through OpenSSL or, on Windows, through SChannel with no external library to deploy at all. These defaults were tightened because they are the right defaults, not because a deadline required them.
Ahead of the deadlines above we are working towards the technical documentation described in Annex VII, the EU declaration of conformity of Annex V, the CE marking where it applies to us, the information and instructions to users of Annex II, and the internal process for the Article 14 reporting duties that begin in September 2026. We will publish the results here as they are completed. Harmonised standards under the Regulation are still being drafted, and we will align with them once they are available.
If your compliance team has a supplier assessment form, a component questionnaire or an SBOM request, send it through our contact form, stating the product, edition and version you use, and we will complete it with the specific answers for your build.
This page is provided to support your own assessment. It is information about our products and our practices, not legal advice about your obligations under the Regulation.