LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:cyber_resilience_act

This is an old revision of the document!


EU Cyber Resilience Act (2024)

As of 1 October 2026.

Full title Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
Type EU regulation
Adopted by European Parliament and Council of the European Union
Adopted 23 October 2024
Legal status In force since 10 December 2024; directly applicable. Reporting obligations (Art. 14) apply from 11 September 2026; provisions on conformity assessment bodies from 11 June 2026; the Regulation applies in general from 11 December 2027
Official text EUR-Lex
Subject area Private actors, liability and insurance; Cybersecurity, cybercrime and critical infrastructure

Overview

The Cyber Resilience Act sets mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market. Manufacturers must design, develop and produce such products in accordance with essential cybersecurity requirements, handle vulnerabilities throughout a defined support period and report actively exploited vulnerabilities and severe incidents. Conformity is indicated by the CE marking. The Regulation is referred to in debates on reducing the vulnerabilities that cyber operations, including State-sponsored operations, exploit.

Provisions relevant to the cyber and information sphere

  • Art. 13 and Annex I – Obligations of manufacturers and essential cybersecurity requirements, including secure-by-default configuration, protection against unauthorised access, and vulnerability handling with security updates.
  • Art. 13(8) – Support period reflecting the expected use time of the product, in principle at least five years.
  • Art. 14 – Reporting of actively exploited vulnerabilities and severe incidents to the coordinating CSIRT and ENISA: early warning within 24 hours, notification within 72 hours, final report; information of affected users.
  • Art. 16 – Single reporting platform established by ENISA.
  • Art. 64 – Administrative fines of up to EUR 15 million or 2.5 % of total worldwide annual turnover for infringements of the essential requirements and of Arts. 13 and 14.

Application to cyber and information operations

The Regulation does not address attribution or State conduct. It places security obligations on manufacturers and creates a Union-wide reporting system for exploited vulnerabilities. Its requirements are taken into account in the assessment of defectiveness under the EU Product Liability Directive (Art. 7(2) of that directive).

Recent developments

  • 2024-12-10: Entry into force.
  • 2026-06-11: Provisions on notification of conformity assessment bodies apply.
  • 2026-09-11: Reporting obligations under Art. 14 apply; ENISA launches the CRA single reporting platform (ENISA).
  • 2027-12-11: General application (scheduled).

Sources

Change log

  • 2026-10-01: Entry created.
law/eu/cyber_resilience_act.1790863199.txt.gz · Last modified: by lfpo