Cyber Resilience Act

← All instruments
applies partiallyproduct
Type
regulation
Layer
product
Status
applies partially
In force
2024-12-10
Key date
2026-09-11 reporting; 2027-12-11 full
Last verified
2026-07-16

Cyber Resilience Act (CRA) — security for every connected product

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. The first broad “secure products” law: anything with software or a data connection sold in the EU must be secure by design, kept secure with updates, and carry the CE marking for cybersecurity.

Scope

Products with digital elements (PDEs) — hardware and software whose use includes a direct or indirect data connection, from smart toys and routers to operating systems, apps and industrial components — including manufacturer-developed remote data processing.

Out of scope: products under equivalent sectoral regimes (medical devices, civil aviation, motor vehicles/UNECE R155, marine equipment); military/classified; pure SaaS not tied to a product (NIS2 territory); spare parts. Open source: non-commercial development is out; “open-source software stewards” get a light-touch regime; monetised open source is in scope.

Risk-based tiers

TierExamplesConformity route
Default (~90%)most consumer/business productsself-assessment
Important — Class I (Annex III)password managers, VPNs, browsers, smart-home, OSesharmonised standards or third-party assessment
Important — Class II (Annex III)firewalls, hypervisors, tamper-resistant microcontrollersthird-party assessment
Critical (Annex IV)hardware security modules, smart-meter gateways, secure elementsEU certification (EUCC) may be mandated

Core obligations (manufacturers)

  1. Essential requirements — Annex I Part I: secure-by-design and by-default; no known exploitable vulnerabilities at release; confidentiality/integrity/ availability protection; attack-surface minimisation; a security-update mechanism separable from feature updates.
  2. Annex I Part II (vulnerability handling): identify/document components (SBOM); remediate without delay and provide free security patches; coordinated vulnerability disclosure policy; publish advisories.
  3. Support period: security support for the expected lifetime, in principle ≥ 5 years; the end-of-support date must be transparent to buyers.
  4. Risk assessment + technical documentation + EU declaration of conformity + CE marking; user information/instructions (Annex II).
  5. Importers/distributors have verification duties; substantial modification makes you the “manufacturer”.

Reporting (Art. 14) — starts 11 September 2026

To the manufacturer’s CSIRT + ENISA via the single reporting platform:

  • Actively exploited vulnerabilities: early warning ≤ 24h, notification ≤ 72h, final report ≤ 14 days after a fix is available.
  • Severe incidents affecting product security: early warning ≤ 24h, notification ≤ 72h, final report ≤ 1 month. Users must be told about incidents/vulnerabilities and mitigations.

Penalties

Up to €15M or 2.5% of worldwide turnover for breaching essential requirements; €10M/2% for other obligations; €5M/1% for misleading information. Authorities can force withdrawal/recall.

Timeline

DateMilestone
2024-12-10In force
2026-06-11Rules on notification of conformity-assessment bodies apply
2026-09-11Reporting obligations (Art. 14) apply
2027-12-11Full application — essential requirements, CE marking, market surveillance

Harmonised standards (CEN/CENELEC, requested 2025) are the key compliance vehicle to watch through 2026–2027.

Interplay

RED cyber requirements are the on-ramp (CRA supersedes them once fully applicable); NIS2 regulates the operators who buy CRA products; CRA conformity can presume AI Act Art. 15 cybersecurity conformity; the new Product Liability Directive adds a private-law liability route for insecure software.

Sources