Cyber Resilience Act
Enacted European Union · In force Dec 10, 2024 · next deadline Dec 11, 2027 (in 15 months)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU: secure by design, vulnerability handling, security updates for the support period, SBOMs, and CE marking after conformity assessment. Manufacturers must report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA from 11 Sep 2026.
- Who it applies to
- Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.
- Penalties
- Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).
- Enforced by
- National market surveillance authorities; CSIRTs and ENISA (vulnerability and incident reporting via the single reporting platform); European Commission
- Official name
- Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)
- Citation
- OJ L, 2024/2847, 20.11.2024
- Topics
- cybersecurity, breach-notification
Research notes
Status is 'enacted' because the main product obligations do not apply until 11 Dec 2027, although reporting obligations apply from 11 Sep 2026. No proposal to delay CRA dates was confirmed in this research. The Digital Omnibus's single-entry point for incident reporting is designed to build on the CRA single reporting platform.
Related
Questions about Cyber Resilience Act
- What are the Cyber Resilience Act compliance deadlines?
- Dec 10, 2024: CRA enters into force. Jun 11, 2026: Conformity assessment body provisions apply. Sep 11, 2026: Vulnerability and incident reporting obligations apply. Dec 11, 2027: CRA fully applies. Jun 11, 2028: Legacy type-examination certificates expire. Sep 11, 2028: Report on single reporting platform. Dec 11, 2030: First CRA evaluation.
- When does Cyber Resilience Act take effect?
- Cyber Resilience Act took effect on Dec 10, 2024. The next milestone is Dec 11, 2027: CRA fully applies.
- Who does Cyber Resilience Act apply to?
- Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.
- What are the penalties under Cyber Resilience Act?
- Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).