As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) |
|---|---|
| Type | EU regulation |
| Adopted by | European Parliament and Council of the European Union |
| Adopted | 23 October 2024 |
| Legal status | In force since 10 December 2024; directly applicable. Reporting obligations (Art. 14) apply from 11 September 2026; provisions on conformity assessment bodies from 11 June 2026; the Regulation applies in general from 11 December 2027 |
| Official text | EUR-Lex |
| Subject area | Private actors, liability and insurance; Cybersecurity, cybercrime and critical infrastructure |
The Cyber Resilience Act sets mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market. Manufacturers must design, develop and produce such products in accordance with essential cybersecurity requirements, handle vulnerabilities throughout a defined support period and report actively exploited vulnerabilities and severe incidents. Conformity is indicated by the CE marking. The Regulation is referred to in debates on reducing the vulnerabilities that cyber operations, including State-sponsored operations, exploit.
The Regulation does not address attribution or State conduct. It places security obligations on manufacturers and creates a Union-wide reporting system for exploited vulnerabilities. Its requirements are taken into account in the assessment of defectiveness under the EU Product Liability Directive (Art. 7(2) of that directive).