Skip to content

Cyber Resilience Act

Enacted European Union · In force Dec 10, 2024 · next deadline Dec 11, 2027 (in 15 months)

Deadlines

DateWhat happens
Dec 10, 2024CRA enters into force21 months ago
Jun 11, 2026Conformity assessment body provisions apply3 months ago
Sep 11, 2026Vulnerability and incident reporting obligations apply13 days ago
Dec 11, 2027CRA fully appliesin 15 months
Jun 11, 2028Legacy type-examination certificates expirein 21 months
Sep 11, 2028Report on single reporting platformin 24 months
Dec 11, 2030First CRA evaluationin 4.2 years

Summaries for reference, not legal advice. Check the official text.

What it does

Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU: secure by design, vulnerability handling, security updates for the support period, SBOMs, and CE marking after conformity assessment. Manufacturers must report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA from 11 Sep 2026.

Who it applies to
Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.
Penalties
Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).
Enforced by
National market surveillance authorities; CSIRTs and ENISA (vulnerability and incident reporting via the single reporting platform); European Commission
Official name
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)
Citation
OJ L, 2024/2847, 20.11.2024
Topics
cybersecurity, breach-notification
Verified 2026-09-22
Research notes

Status is 'enacted' because the main product obligations do not apply until 11 Dec 2027, although reporting obligations apply from 11 Sep 2026. No proposal to delay CRA dates was confirmed in this research. The Digital Omnibus's single-entry point for incident reporting is designed to build on the CRA single reporting platform.

Related

Questions about Cyber Resilience Act
What are the Cyber Resilience Act compliance deadlines?
Dec 10, 2024: CRA enters into force. Jun 11, 2026: Conformity assessment body provisions apply. Sep 11, 2026: Vulnerability and incident reporting obligations apply. Dec 11, 2027: CRA fully applies. Jun 11, 2028: Legacy type-examination certificates expire. Sep 11, 2028: Report on single reporting platform. Dec 11, 2030: First CRA evaluation.
When does Cyber Resilience Act take effect?
Cyber Resilience Act took effect on Dec 10, 2024. The next milestone is Dec 11, 2027: CRA fully applies.
Who does Cyber Resilience Act apply to?
Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.
What are the penalties under Cyber Resilience Act?
Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.