====== EU Cyber Resilience Act (2024) ====== //As of 1 October 2026. Information only, not legal advice – see the [[about:disclaimer|disclaimer]].// ^ Full title | Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) | ^ Type | EU regulation | ^ Adopted by | European Parliament and Council of the European Union | ^ Adopted | 23 October 2024 | ^ Legal status | In force since 10 December 2024; directly applicable. Reporting obligations (Art. 14) apply from 11 September 2026; provisions on conformity assessment bodies from 11 June 2026; the Regulation applies in general from 11 December 2027 | ^ Official text | [[https://eur-lex.europa.eu/eli/reg/2024/2847/oj|EUR-Lex]] | ^ Subject area | Private actors, liability and insurance; Cybersecurity, cybercrime and critical infrastructure | ===== Overview ===== The Cyber Resilience Act sets mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market. Manufacturers must design, develop and produce such products in accordance with essential cybersecurity requirements, handle vulnerabilities throughout a defined support period and report actively exploited vulnerabilities and severe incidents. Conformity is indicated by the CE marking. The Regulation is referred to in debates on reducing the vulnerabilities that cyber operations, including State-sponsored operations, exploit. ===== Provisions relevant to the cyber and information sphere ===== * **Art. 13 and Annex I** – Obligations of manufacturers and essential cybersecurity requirements, including secure-by-default configuration, protection against unauthorised access, and vulnerability handling with security updates. * **Art. 13(8)** – Support period reflecting the expected use time of the product, in principle at least five years. * **Art. 14** – Reporting of actively exploited vulnerabilities and severe incidents to the coordinating CSIRT and ENISA: early warning within 24 hours, notification within 72 hours, final report; information of affected users. * **Art. 16** – Single reporting platform established by ENISA. * **Art. 64** – Administrative fines of up to EUR 15 million or 2.5 % of total worldwide annual turnover for infringements of the essential requirements and of Arts. 13 and 14. ===== Application to cyber and information operations ===== The Regulation does not address attribution or State conduct. It places security obligations on manufacturers and creates a Union-wide reporting system for exploited vulnerabilities. Its requirements are taken into account in the assessment of defectiveness under the [[law:eu:product_liability|EU Product Liability Directive]] (Art. 7(2) of that directive). ===== Recent developments ===== * 2024-12-10: Entry into force. * 2026-06-11: Provisions on notification of conformity assessment bodies apply. * 2026-09-11: Reporting obligations under Art. 14 apply; ENISA launches the CRA single reporting platform (ENISA). * 2027-12-11: General application (scheduled). ===== Related entries ===== * [[law:eu:product_liability]] * [[law:eu:nis2_cer]] * [[law:un:ict_norms]] * [[topics:private_actors]] ===== Sources ===== * [[https://eur-lex.europa.eu/eli/reg/2024/2847/oj|Regulation (EU) 2024/2847 (EUR-Lex)]], accessed 2026-10-01 * [[https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched|ENISA: The CRA Single Reporting Platform is launched]], accessed 2026-10-01 ===== Change log ===== * 2026-10-01: Entry created.