Horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)

SUMMARY OF:

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements

WHAT IS THE AIM OF THE REGULATION?

Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), aims to strengthen cybersecurity across the European Union (EU). It sets out a comprehensive framework to ensure that digital products and services are:

It addresses the growing cybersecurity challenges posed by the increasing connectivity of devices and the rise in the number of cyberattacks, which have significant economic and societal impacts.

KEY POINTS

The CRA has several core objectives:

Scope

The regulation applies to a wide range of products with digital elements placed on the EU market, regardless of where the manufacturer is based, that can connect directly or indirectly to other devices or networks, including:

Some products with digital elements are classified as ‘important’ or ‘critical’ and are subject to stricter conformity assessment procedures before being placed on the market. Implementing Regulation (EU) 2025/2392 sets out the technical descriptions of those categories.

Certain products are excluded from the regulation, such as:

Key requirements for manufacturers

Secure by design

Manufacturers must integrate cybersecurity into product design and development. This includes, among other things, secure-by-default configurations, appropriate levels of encryption and access control mechanisms.

Risk assessment and mitigation

Transparency and documentation

Manufacturers must provide clear and comprehensive documentation, including:

Reporting incidents

Manufacturers must:

In exceptional circumstances and on justified cybersecurity-related grounds, the computer security incident response teams (CSIRTs) initially receiving the notification may delay the sharing of incident and vulnerability notifications with other relevant CSIRTs via the single reporting platform for a period that is no longer than strictly necessary, under the conditions specified in Delegated Regulation (EU) 2026/881.

Software updates and support

Obligations for importers and distributors

The regulation also places responsibilities on importers and distributors to ensure that products comply with cybersecurity requirements:

Enforcement

To ensure compliance, the regulation establishes a robust enforcement framework:

FROM WHEN DOES THE REGULATION APPLY?

The regulation applies from , with some exceptions:

BACKGROUND

For further information, see:

MAIN DOCUMENT

Regulation (EU) 2024/2847 of the European Parliament and of the Council of on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, ).

Successive amendments to Regulation (EU) 2024/2847 have been incorporated into the original text. This consolidated version is of documentary value only.

last update