The Cyber Resilience Act (CRA) is a European Union regulation — not a voluntary standard — that entered into force on 10 December 2024 and will be fully applicable on 11 December 2027. It is issued by the European Commission and co-legislated by the European Parliament and Council; it is not a certification scheme but a horizontal product-safety law, comparable in structure to the CE-marking directives for physical goods. The CRA applies to all manufacturers, importers, and distributors of “products with digital elements” — any software or hardware product containing a data connection — that is made available on the EU single market, regardless of where the manufacturer is headquartered. Compliance is mandatory: non-compliant products cannot legally be placed on the EU market after the deadline, and penalties can reach €15 million or 2.5 % of global annual turnover. Key intermediate deadlines include 11 September 2026 (manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours) and 11 June 2026 (conformity assessment body framework becomes operational). Products already on the market before 11 December 2027 are exempt from the full requirements unless they undergo a “substantial modification,” but they are subject to the vulnerability reporting obligation from September 2026 onward.
Red Hat is directly in scope of the CRA as a manufacturer of products with digital elements (RHEL, OpenShift, Ansible Automation Platform, and the broader portfolio). Red Hat publicly states it is aligning its mature secure-by-design lifecycle with CRA mandates and has published a dedicated compliance page on its Customer Portal. Concretely, Red Hat already provides machine-readable security advisories (CSAF/VEX), SBOMs for container images, Sigstore-based artifact signing, and SLSA-compliant build pipelines via the Trusted Software Supply Chain portfolio — all of which map to CRA essential requirements around vulnerability handling, transparency, and supply-chain integrity. Red Hat also acts as an open source software steward for upstream projects like Fedora and Ansible, a role explicitly recognized by the CRA with lighter (but non-zero) obligations. Through leadership in the Eclipse Open Regulatory Compliance (ORC) Working Group and the OpenSSF, Red Hat has helped shape CRA implementing standards so they reflect how open source software is actually developed — ensuring that compliance obligations fall on commercial manufacturers rather than volunteer maintainers. For Red Hat customers, the practical implication is that Red Hat’s products are being engineered to ship with the technical documentation, conformity evidence, and vulnerability-handling processes the CRA demands, reducing the customers’ own burden when integrating Red Hat software into their CE-marked products or fulfilling their downstream obligations.
