EU Regulation · CRA
Cyber Resilience Act
Regulation (EU) 2024/2847
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements across their whole lifecycle — from secure design and a Software Bill of Materials to vulnerability handling and incident reporting.
What it covers
Products with digital elements whose intended or foreseeable use includes direct/indirect data connections, subject to statutory exclusions including MDR/IVDR.
How it applies to your product
In practice the CRA means a connected product needs secure-by-default configuration, a documented vulnerability-handling process, and a Software Bill of Materials — and the manufacturer must report actively exploited vulnerabilities and severe incidents through the EU single reporting platform to the relevant national CSIRT (with ENISA notified in parallel) within tight deadlines. It applies on top of a product’s other CE-marking obligations, not instead of them.
Key dates
Applies in full from 11 December 2027; the vulnerability and incident reporting obligations apply earlier, from 11 September 2026.
Authoritative source
Always confirm against the primary text on EUR-Lex — the official EU legal database.
Read Regulation (EU) 2024/2847 on EUR-Lex ↗See also the CRA entry in the glossary.
Guides on CRA
From the Library
tutorial
Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers
Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.
reference
Official Journal monitoring for hardware compliance — a quarterly review workflow
A practical workflow for tracking EU product legislation, OJ standards citations, restrictions and transition dates, with a review record for each affected product.
guide
CRA readiness countdown — scope, reporting, assessment and release checkpoints
Planning checkpoints before CRA main product obligations apply on 11 December 2027, with reporting already in force, class-specific routes and release evidence.
reference
CRA harmonised standards — citation and assessment checks
How to check the role of harmonised standards in CRA assessment: exact citation, requirement coverage, route conditions and evidence. This is not a live OJ ledger.
tutorial
How to check NANDO for Notified Bodies
Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.
guide
CE marking AI-enabled hardware — CRA + AI Act overlap
A scope overview for AI-enabled hardware: updated high-risk application dates, category-specific assessment, and evidence needed alongside product legislation.
Check your product