Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), aims to strengthen cybersecurity across the European Union (EU). It sets out a comprehensive framework to ensure that digital products and services are:
secure by design;
resilient against cyber threats; and
capable of providing continuing protection throughout their life cycle.
It addresses the growing cybersecurity challenges posed by the increasing connectivity of devices and the rise in the number of cyberattacks, which have significant economic and societal impacts.
KEY POINTS
The CRA has several core objectives:
enhance cybersecurity across the EU by setting mandatory cybersecurity requirements for products with digital elements;
promote secure practices by encouraging manufacturers to integrate cybersecurity into the product design and development phases;
ensure transparency and accountability by requiring manufacturers to provide clear information about the cybersecurity features of their products and to take responsibility for addressing vulnerabilities;
foster a single market for cybersecurity by harmonising rules across EU Member States to reduce fragmentation and ensure a level playing field.
Scope
The regulation applies to a wide range of products with digital elements placed on the EU market, regardless of where the manufacturer is based, that can connect directly or indirectly to other devices or networks, including:
hardware products (e.g. internet-of-things devices, smart home appliances, industrial control systems, microchips);
software products (e.g. video games, apps, computer programmes).
Some products with digital elements are classified as ‘important’ or ‘critical’ and are subject to stricter conformity assessment procedures before being placed on the market. Implementing Regulation (EU) 2025/2392 sets out the technical descriptions of those categories.
Certain products are excluded from the regulation, such as:
medical devices already covered by specific EU regulations;
aviation and automotive products regulated under sector-specific legislation;
marine equipment within the scope of Directive 2014/90/EU;
two- and three-wheel vehicles and quadricycles covered by Regulation (EU) No 168/2013 (see summary), with the exception of L1e category vehicles designed to be pedalled, as provided for by Delegated Regulation (EU) 2025/1535.
Key requirements for manufacturers
Secure by design
Manufacturers must integrate cybersecurity into product design and development. This includes, among other things, secure-by-default configurations, appropriate levels of encryption and access control mechanisms.
Risk assessment and mitigation
Manufacturers are required to conduct a risk assessment and keep it updated, and to implement measures to address identified vulnerabilities during the product’s life cycle.
If manufacturers rely on third-party components or services, they must exercise due diligence when integrating them into their products.
Transparency and documentation
Manufacturers must provide clear and comprehensive documentation, including:
a description of the product’s cybersecurity features;
instructions for secure installation, configuration and use;
information on how to report vulnerabilities;
a declaration of conformity to confirm compliance with the regulation.
Reporting incidents
Manufacturers must:
report severe cybersecurity incidents and actively exploited vulnerabilities to relevant national authorities and the European Union Agency for Cybersecurity without undue delay;
inform users about potential risks and provide guidance on mitigating them.
In exceptional circumstances and on justified cybersecurity-related grounds, the computer security incident response teams (CSIRTs) initially receiving the notification may delay the sharing of incident and vulnerability notifications with other relevant CSIRTs via the single reporting platform for a period that is no longer than strictly necessary, under the conditions specified in Delegated Regulation (EU) 2026/881.
Software updates and support
Manufacturers must provide security updates during the product’s support period, which needs to reflect the period the product is expected to be in use.
Updates must address vulnerabilities and ensure the continued security of the product.
Obligations for importers and distributors
The regulation also places responsibilities on importers and distributors to ensure that products comply with cybersecurity requirements:
importers must verify that manufacturers have complied with the regulation and ensure that products are labelled and documented correctly;
distributors must ensure that products carry the CE marking, and that information and instructions for the user have been supplied, before making products available on the market;
products will bear the CE marking to indicate that they comply with the CRA requirements;
non-EU manufacturers must comply with the regulation to access the EU market, potentially influencing global cybersecurity standards.
Enforcement
To ensure compliance, the regulation establishes a robust enforcement framework:
national market surveillance authorities will monitor compliance and carry out inspections;
non-compliance can result in significant sanctions, which may include:
fines of up to 2.5 % of the manufacturer’s global annual turnover,
prohibiting or restricting the availability of a product,
ordering a product to be withdrawn or recalled;
Member State authorities will share information and coordinate enforcement measures.
FROM WHEN DOES THE REGULATION APPLY?
The regulation applies from , with some exceptions:
reporting obligations concerning actively exploited vulnerabilities and severe incidents will apply from ;
notification of conformity assessment bodies has applied since .
Regulation (EU) 2024/2847 of the European Parliament and of the Council of on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, ).
Successive amendments to Regulation (EU) 2024/2847 have been incorporated into the original text. This consolidated version is of documentary value only.
RELATED DOCUMENTS
Delegated Regulation (EU) 2026/881 specifying the terms and conditions for delaying the sharing of notifications on cybersecurity-related grounds.
Delegated Regulation (EU) 2025/1535 on the exclusion of certain products with digital elements covered by Regulation (EU) No 168/2013 from the CRA.
Implementing Regulation (EU) 2025/2392 on technical descriptions for important and critical products with digital elements under the CRA.
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act).
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the EU.
Regulation (EU) 2019/881 on the European Union Agency for Cybersecurity and on information and communications technology cybersecurity certification (EU Cybersecurity Act).
Regulation (EU) 2019/2144 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users.
Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure.