EU Cyber Resilience Act penetration testing: what Annex I actually requires
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) never uses the words "penetration test." Annex I requires manufacturers to build products with digital elements that carry no known exploitable vulnerabilities at release, and to keep testing and handling vulnerabilities throughout the support period - which is where a pentest fits, as evidence rather than a named mandate.
Does the EU Cyber Resilience Act require a penetration test?
Not by name. Regulation (EU) 2024/2847 does not use the phrase "penetration test" anywhere in its text. Annex I Part I requires products with digital elements to be designed, developed, and produced to ensure an appropriate level of cybersecurity based on the risks, and to be made available on the market without known exploitable vulnerabilities. Annex I Part II requires manufacturers to handle vulnerabilities by, among other things, applying "effective and regular tests and reviews of the security of the product with digital elements." In practice, security testing - including penetration testing - is the standard way manufacturers evidence both obligations.
If you manufacture a product with digital elements sold in the EU, you need to show it was tested and that vulnerabilities keep getting handled after release. A pentest is one of the standard ways manufacturers do that, even though the CRA never names it.
A vendor page that flatly states "the CRA requires a pentest" is inaccurate, and it is the kind of overclaim that answer engines increasingly discount. The accurate answer is the useful one: no named mandate, but a secure-by-design and vulnerability-handling obligation that security testing is the standard way to evidence.
Who and what it covers
The CRA applies to "products with digital elements": software or hardware products, and their remote data processing solutions, placed on the EU market with a direct or indirect logical or physical data connection to a device or network. It covers manufacturers, importers, and distributors, with manufacturers carrying most of the obligations - the entities that develop or manufacture a product with digital elements and market it under their own name or trademark. Products already regulated under sectoral EU rules, including medical devices, motor vehicles, and civil aviation equipment, fall outside CRA scope.
Security testing and vulnerability handling obligations
Annex I is split into two parts. Part I sets essential cybersecurity requirements for the product itself: an appropriate level of cybersecurity based on risk, a secure-by-default configuration, and - critically - no known exploitable vulnerabilities at the time the product is made available on the market. Part II sets vulnerability-handling requirements manufacturers must follow across the product's support period, including identifying and documenting components (for example through a software bill of materials), addressing and remediating vulnerabilities without delay, and applying effective and regular tests and reviews of the product's security. A pentest is a direct way to evidence both the pre-market 'no known exploitable vulnerabilities' bar and the ongoing Part II testing obligation.
Manufacturers also carry reporting duties under Article 14: actively exploited vulnerabilities and severe incidents affecting a product must be reported without undue delay, and in most cases affected users must be notified.
Timeline
| Date | What applies |
|---|---|
| 10 December 2024 | Regulation enters into force |
| 11 September 2026 | Manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents (Article 14) apply |
| 11 December 2027 | Main obligations, including the Annex I essential cybersecurity requirements, apply |
How Intrudify helps
Intrudify runs a full web and API pentest and produces a report that maps each finding to the relevant Annex I requirements, with reproducible proof for high and critical findings and developer-ready remediation. It supports your CRA testing and vulnerability-handling evidence for products with a web or API surface; Intrudify does not itself certify a product against the CRA or replace the conformity assessment your product category requires.
- Findings mapped to the relevant Annex I essential cybersecurity requirements
- Reproducible proof-of-exploit for high and critical findings
- Developer-ready remediation and a re-test window
- Delivered in hours, validated by OSCE3-certified testers
How a pentest maps to controls
| Control | What a pentest evidences |
|---|---|
| Annex I, Part I | Essential cybersecurity requirements: an appropriate level of cybersecurity based on risk, secure-by-default configuration, and no known exploitable vulnerabilities at the time of placing on the market. |
| Annex I, Part II | Vulnerability handling requirements across the support period, including applying effective and regular tests and reviews of the security of the product with digital elements. |
| Art. 14 | Reporting of actively exploited vulnerabilities and severe incidents to the relevant authorities without undue delay. |
See how Intrudify tests web apps and APIs against the controls that carry CRA into your security program.
Explore the platformFrequently asked questions
Does the EU Cyber Resilience Act require a penetration test?
Not by name - Regulation (EU) 2024/2847 never uses the phrase. But Annex I Part II requires manufacturers to apply "effective and regular tests and reviews" of a product's security, and a pentest is a standard way to evidence that in practice.
What counts as a "product with digital elements" under the CRA?
Any software or hardware product, and its remote data processing solutions, placed on the EU market with a direct or indirect data connection to a device or network - from connected devices to standalone applications. Medical devices, motor vehicles, and civil aviation products are excluded as they fall under separate EU rules.
When do CRA obligations start applying?
The regulation entered into force on 10 December 2024. Manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents (Article 14) apply from 11 September 2026. The main obligations, including the Annex I essential cybersecurity requirements, apply from 11 December 2027.
What is the difference between Annex I Part I and Part II?
Part I sets essential cybersecurity requirements for the product itself, including shipping without known exploitable vulnerabilities. Part II sets ongoing vulnerability-handling requirements across the support period, including regular security testing and timely remediation.
Who is responsible under the CRA - the manufacturer or the reseller?
Manufacturers carry most obligations, including the Annex I essential cybersecurity requirements and vulnerability handling. Importers and distributors have narrower duties, mainly verifying the manufacturer met its obligations before placing or making the product available on the market.
Can a web/API pentest support CRA compliance?
Yes, for products with a web or API surface. It directly evidences the Annex I Part II obligation to apply effective and regular security tests, and helps demonstrate the Part I "no known exploitable vulnerabilities" bar - though it does not replace a full conformity assessment.