What the Cyber Resilience Act establishes

Regulation (EU) 2024/2847, known as the Cyber Resilience Act or CRA, establishes horizontal cybersecurity requirements for products with digital elements placed on the European Union market. It covers both finished products and certain digital components placed on the market separately. The Regulation was adopted on 23 October 2024 and published in the Official Journal of the EU on 20 November that year. Text of the Regulation.

Its regulatory aim is to ensure that security is not limited to a one-off check before a device or software is sold. The text sets out requirements relating to design, development, production and maintenance, as well as measures for handling vulnerabilities during the relevant lifetime of a product. The Commission describes the CRA as a mandatory framework for digital products, while noting that its explanation does not replace consultation of the Regulation itself. Official Commission summary.

The practical difference from a general statement that a product is “secure” is that manufacturers must meet specific requirements and maintain processes throughout the product lifecycle. This does not mean the CRA guarantees that failures or attacks will not occur: it imposes regulatory obligations, not a promise of zero risk. Whether a specific model complies depends on its characteristics, its function and the applicable assessment.

Which products and economic operators are covered

The general criterion is that a product with digital elements is placed on the EU market and its intended or reasonably foreseeable use includes a direct or indirect connection to another device or a network. The definition covers hardware and software and may also include components placed on the market separately. An application, an operating system, a connected device or a software component may therefore need to be assessed, even if it is not the final product used by consumers. The applicable boundaries should be checked against the scope and definitions in the Regulation, rather than inferred solely from whether something “has internet”. Legal text, Regulation (EU) 2024/2847.

The Regulation allocates responsibilities among economic operators. Manufacturers have a central role because they must meet the essential requirements, document conformity and manage vulnerabilities. Importers and distributors have obligations relating to making products available on the market and checking that the requirements applicable to them have been met. The Commission describes the CRA as a framework affecting manufacturers, importers and distributors, although specific tasks vary according to each operator’s role. Commission summary.

It is not enough to identify a product as “digital” to conclude automatically that every provision applies to it. The Regulation contains exclusions and rules governing its interaction with other sectoral frameworks; it also treats certain situations involving free and open-source software differently. Whether it applies depends on the specific legal and commercial circumstances. For a business or product, it is advisable to review the scope and exclusion provisions in the full text and, where appropriate, seek specialist advice.

Security by design and vulnerability management

The essential requirements include designing, developing and producing products so that they achieve an appropriate level of cybersecurity, limiting known vulnerabilities and providing a secure default configuration where appropriate. The details are not an identical checklist for every product: the Regulation sets out requirements and obligations that must be applied in light of the product and its intended use. Annex I to the Regulation contains the essential cybersecurity requirements.

Management does not end when a product is placed on the market. Manufacturers must address vulnerabilities during the applicable support period, take measures to remedy them and provide security updates under the conditions laid down in the Regulation. They must also establish vulnerability-management policies and procedures, including ways to receive information and, where appropriate, disclose resolved issues. The Commission summarises these obligations as part of a lifecycle security approach. European Commission: CRA.

The Regulation also covers technical documentation, user information and conformity assessment. The documentary elements include a list of software components, which may take the form of a software bill of materials (SBOM) in a common, machine-readable format, in accordance with the requirements of the text. This does not amount to requiring a public SBOM for every product: documentation obligations and access conditions must be interpreted in accordance with the Regulation, including the protection of sensitive information. Legal text.

Product categories and conformity assessment

The Regulation distinguishes product categories according to their function and cybersecurity relevance. Most products will follow a less demanding assessment route than the one provided for certain particularly sensitive categories; other products, identified in Annexes III and IV, are subject to specific procedures. Relevant categories include important products and critical products. The precise classification is determined by the product’s function and the legal criteria, not by a commercial label chosen by the manufacturer. Annexes III and IV to the Regulation.

For some products, the manufacturer may use an internal conformity assessment; for others, the Regulation provides for the involvement of a notified body or routes associated with European certification schemes, depending on the category and applicable conditions. It would be incorrect to summarise this as “all devices need external certification”, or to assume that all products can be self-assessed in the same way. The applicable annex, the availability of harmonised standards and the legally applicable procedure determine the route.

In practice, anyone assessing a product should first document its main function, the digital components it contains, how it is placed on the market and which annex category might apply. They can then determine who bears the obligations and which conformity procedure is appropriate. The designation “important” or “critical” cannot simply be inferred from a device appearing sensitive: its characteristics must be checked against the legal classification.

Timetable: entry into force does not mean full application

The Regulation entered into force on 10 December 2024. That date should not be confused with the general start of the obligations: the bulk of the regime is set to apply from 11 December 2027. The difference provides a transition period for manufacturers and other operators to prepare processes, documentation and products in line with the framework. Article 71 of the Regulation.

There is an important intermediate date: the obligations to report vulnerabilities and actively exploited incidents start to apply on 11 September 2026. Presenting 2027 as the first relevant date would omit this milestone. Conversely, it would also be incorrect to say that the entire set of requirements has applied fully since 2024. The Commission’s official timetable distinguishes these stages. European Commission: CRA implementation.

Milestone Date What it means
Entry into force 10 December 2024 The Regulation enters into force; this is not the same as general application of all obligations.
Reporting of vulnerabilities and incidents 11 September 2026 The reporting obligations provided for in the Regulation start to apply.
General application 11 December 2027 Most of the provisions start to apply.

The dates follow the timetable set out in the Regulation itself and the Commission’s implementation page. For a specific case, transitional provisions and any relevant sectoral rules should also be checked.

How to check the impact on a specific product

For businesses, the CRA requires a horizontal regulation to be translated into a product- and supply-chain-specific assessment. A useful initial review can follow these steps:

  • Define the product: identify the hardware, software and components being placed on the market, and their intended function or connection.
  • Identify the organisation’s role: manufacturer, importer, distributor or another operator covered by the Regulation.
  • Check scope and exceptions: review the legal text, including interactions with sectoral legislation and provisions on free and open-source software.
  • Determine the category and conformity route: compare the product’s function with the annexes and document the applicable procedure.
  • Prepare for the lifecycle: assign responsibility for updates, receiving vulnerability reports, documentation and notifications on the relevant dates.

For consumers, the Regulation is intended to strengthen security requirements and the information associated with digital products, but it is not a universal certification that can, by itself, be used to compare every device. The CE marking and conformity documentation have a specific legal context; they do not replace practices such as installing updates or changing insecure settings. The Commission presents the CRA as a regulation of products and supply-chain obligations, not as a guarantee of invulnerability. Official Commission information.