Nix2
Back to Nix2
Regulation·European Union (directly applicable)

CRA

CRA — Cyber Resilience Act

EU regulation setting cybersecurity requirements for products with digital elements placed on the EU market.

Official sources ↓
Entered into force 10 December 2024; main obligations apply from 11 December 2027
Scroll
Overview

CRA introduces horizontal cybersecurity requirements for hardware and software products with digital elements — including remote data-processing solutions.

It targets the whole product lifecycle: secure-by-design, vulnerability handling, and coordinated disclosure, backed by CE marking and market surveillance.

It complements NIS2: NIS2 covers the security posture of operators; CRA covers the security of the products they buy and sell.

Who it applies to
01

Manufacturers, importers and distributors placing products with digital elements on the EU market.

02

Open-source software stewards receive a lighter, dedicated regime.

Core obligations
Duty · 01

Essential cybersecurity requirements set out in Annex I (secure defaults, minimal attack surface, protection of confidentiality/integrity/availability of processed data, minimisation of exploitable surfaces).

Duty · 02

Vulnerability handling throughout the support period: SBOM, coordinated disclosure policy, free security updates, and clear communication to users.

Duty · 03

Conformity assessment (self-assessment, third-party, or EU-type examination depending on the product class — Annex III / IV) and CE marking, with technical documentation.

Duty · 04

Reporting to ENISA and the coordinating CSIRT: early warning of an actively exploited vulnerability or severe incident within 24h, incident/vulnerability notification within 72h, and a final report within 14 days of a corrective or mitigating measure being available.

Timeline
  1. 2022-09-15
    European Commission proposal
  2. 2024-10-10
    Council of the EU adopts the Regulation
  3. 2024-11-20
    Regulation (EU) 2024/2847 published in the Official Journal
  4. 2024-12-10
    Entry into force (20 days after OJ publication)
  5. 2026-06-11
    Chapter IV applies — notification of conformity assessment bodies
  6. 2026-09-11
    Reporting obligations for manufacturers (Article 14) apply
  7. 2027-12-11
    Full application of remaining obligations
Official sources

License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).

Explore other frameworks