Regulation (EU) 2024/2847

Cyber Resilience Act

Cybersecurity requirements for every product with digital elements sold in the EU: connected hardware, software, and the remote processing that is part of a product. The catalog carries its requirements as controls, so readings from your source control, vulnerability scanner and clouds land on them as evidence.

What the regulation asks of a manufacturer

  1. Secure by design and by default

    Security requirements apply across the whole lifecycle of a product with digital elements, from design to the end of the support period.

  2. Conformity assessment and CE marking

    A manufacturer assesses conformity before placing the product on the market and affixes the CE marking to it.

  3. Security updates for the support period

    Vulnerabilities are handled and fixed for the support period, which is at least five years unless the product is expected to be in use for less.

  4. Reporting of exploited vulnerabilities

    An actively exploited vulnerability or a severe incident goes to ENISA and the national CSIRT: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days.

When it applies

The reporting duties come first; the rest follows a year later. Read the regulation.

  • 10 December 2024Entered into force, twenty days after publication in the Official Journal.
  • 11 September 2026Vulnerability and incident reporting duties apply.
  • 11 December 2027Most obligations apply to products placed on the market.

See the CRA controls on your own tools

Thirty minutes. We connect one of your integrations live and show the first readings landing on your controls.