Cyber Resilience Act
Cyber Resilience Act (CRA) — security for every connected product
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. The first broad “secure products” law: anything with software or a data connection sold in the EU must be secure by design, kept secure with updates, and carry the CE marking for cybersecurity.
Scope
Products with digital elements (PDEs) — hardware and software whose use includes a direct or indirect data connection, from smart toys and routers to operating systems, apps and industrial components — including manufacturer-developed remote data processing.
Out of scope: products under equivalent sectoral regimes (medical devices, civil aviation, motor vehicles/UNECE R155, marine equipment); military/classified; pure SaaS not tied to a product (NIS2 territory); spare parts. Open source: non-commercial development is out; “open-source software stewards” get a light-touch regime; monetised open source is in scope.
Risk-based tiers
| Tier | Examples | Conformity route |
|---|---|---|
| Default (~90%) | most consumer/business products | self-assessment |
| Important — Class I (Annex III) | password managers, VPNs, browsers, smart-home, OSes | harmonised standards or third-party assessment |
| Important — Class II (Annex III) | firewalls, hypervisors, tamper-resistant microcontrollers | third-party assessment |
| Critical (Annex IV) | hardware security modules, smart-meter gateways, secure elements | EU certification (EUCC) may be mandated |
Core obligations (manufacturers)
- Essential requirements — Annex I Part I: secure-by-design and by-default; no known exploitable vulnerabilities at release; confidentiality/integrity/ availability protection; attack-surface minimisation; a security-update mechanism separable from feature updates.
- Annex I Part II (vulnerability handling): identify/document components (SBOM); remediate without delay and provide free security patches; coordinated vulnerability disclosure policy; publish advisories.
- Support period: security support for the expected lifetime, in principle ≥ 5 years; the end-of-support date must be transparent to buyers.
- Risk assessment + technical documentation + EU declaration of conformity + CE marking; user information/instructions (Annex II).
- Importers/distributors have verification duties; substantial modification makes you the “manufacturer”.
Reporting (Art. 14) — starts 11 September 2026
To the manufacturer’s CSIRT + ENISA via the single reporting platform:
- Actively exploited vulnerabilities: early warning ≤ 24h, notification ≤ 72h, final report ≤ 14 days after a fix is available.
- Severe incidents affecting product security: early warning ≤ 24h, notification ≤ 72h, final report ≤ 1 month. Users must be told about incidents/vulnerabilities and mitigations.
Penalties
Up to €15M or 2.5% of worldwide turnover for breaching essential requirements; €10M/2% for other obligations; €5M/1% for misleading information. Authorities can force withdrawal/recall.
Timeline
| Date | Milestone |
|---|---|
| 2024-12-10 | In force |
| 2026-06-11 | Rules on notification of conformity-assessment bodies apply |
| 2026-09-11 | Reporting obligations (Art. 14) apply |
| 2027-12-11 | Full application — essential requirements, CE marking, market surveillance |
Harmonised standards (CEN/CENELEC, requested 2025) are the key compliance vehicle to watch through 2026–2027.
Interplay
RED cyber requirements are the on-ramp (CRA supersedes them once fully applicable); NIS2 regulates the operators who buy CRA products; CRA conformity can presume AI Act Art. 15 cybersecurity conformity; the new Product Liability Directive adds a private-law liability route for insecure software.
Sources
- Text: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- Commission CRA page: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
- ENISA (single reporting platform): https://www.enisa.europa.eu