Horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)

SUMMARY OF:

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements

WHAT IS THE AIM OF THE REGULATION?

Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), aims to strengthen cybersecurity across the European Union (EU). It sets out a comprehensive framework to ensure that digital products and services are:

It addresses the growing cybersecurity challenges posed by the increasing connectivity of devices and the rise of cyberattacks, which have significant economic and societal impacts.

KEY POINTS

The CRA has several core objectives.

Scope

The regulation applies to a wide range of products with digital elements placed on the EU market, regardless of where the manufacturer is based, that can connect directly or indirectly to other devices or networks, including:

Certain products are excluded, such as:

Key requirements for manufacturers

Secure by design

Manufacturers must integrate cybersecurity into product design and development. This includes, among other things, secure-by-default configurations, appropriate levels of encryption and access control mechanisms.

Risk assessment and mitigation

Transparency and documentation

Manufacturers must provide clear and comprehensive documentation, including:

Reporting incidents

Manufacturers must:

Software updates and support

Obligations for importers and distributors

The regulation also places responsibilities on importers and distributors to ensure that products comply with cybersecurity requirements.

Enforcement

To ensure compliance, the regulation establishes a robust enforcement framework.

FROM WHEN DOES THE REGULATION APPLY?

The regulation applies from , with some exceptions:

BACKGROUND

For further information, see:

MAIN DOCUMENT

Regulation (EU) 2024/2847 of the European Parliament and of the Council of on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, ).

Successive amendments to Directive (EU) 2024/2847 have been incorporated into the original text. This consolidated version is of documentary value only.

last update