CRA introduces horizontal cybersecurity requirements for hardware and software products with digital elements — including remote data-processing solutions.
It targets the whole product lifecycle: secure-by-design, vulnerability handling, and coordinated disclosure, backed by CE marking and market surveillance.
It complements NIS2: NIS2 covers the security posture of operators; CRA covers the security of the products they buy and sell.
Manufacturers, importers and distributors placing products with digital elements on the EU market.
Open-source software stewards receive a lighter, dedicated regime.
Essential cybersecurity requirements set out in Annex I (secure defaults, minimal attack surface, protection of confidentiality/integrity/availability of processed data, minimisation of exploitable surfaces).
Vulnerability handling throughout the support period: SBOM, coordinated disclosure policy, free security updates, and clear communication to users.
Conformity assessment (self-assessment, third-party, or EU-type examination depending on the product class — Annex III / IV) and CE marking, with technical documentation.
Reporting to ENISA and the coordinating CSIRT: early warning of an actively exploited vulnerability or severe incident within 24h, incident/vulnerability notification within 72h, and a final report within 14 days of a corrective or mitigating measure being available.
- 2022-09-15European Commission proposal
- 2024-10-10Council of the EU adopts the Regulation
- 2024-11-20Regulation (EU) 2024/2847 published in the Official Journal
- 2024-12-10Entry into force (20 days after OJ publication)
- 2026-06-11Chapter IV applies — notification of conformity assessment bodies
- 2026-09-11Reporting obligations for manufacturers (Article 14) apply
- 2027-12-11Full application of remaining obligations
License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).