EU Regulation · CRA
Cyber Resilience Act
Regulation (EU) 2024/2847
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements across their whole lifecycle — from secure design and a Software Bill of Materials to vulnerability handling and incident reporting.
What it covers
Any product with digital elements that connects to a network or runs software, placed on the EU market.
How it applies to your product
In practice the CRA means a connected product needs secure-by-default configuration, a documented vulnerability-handling process, and a Software Bill of Materials — and the manufacturer must report actively exploited vulnerabilities and severe incidents through the EU single reporting platform to the relevant national CSIRT (with ENISA notified in parallel) within tight deadlines. It applies on top of a product’s other CE-marking obligations, not instead of them.
Key dates
Applies in full from 11 December 2027; the vulnerability and incident reporting obligations apply earlier, from 11 September 2026.
Authoritative source
Always confirm against the primary text on EUR-Lex — the official EU legal database.
Read Regulation (EU) 2024/2847 on EUR-Lex ↗See also the CRA entry in the glossary.
Guides on CRA
From the Library
guide
CRA enforcement countdown — T-365d, T-180d, T-90d
Operational countdown to the CRA general application date of 11 December 2027. Concrete checkpoints at T-12m, T-6m, T-3m and T-0 for hardware manufacturers.
reference
CRA harmonised standards — OJEU tracker (July 2026)
Live status of harmonised standards under the Cyber Resilience Act: standardisation request M/606, EN 40000 series, expected OJEU listings 2027.
tutorial
How to check NANDO for Notified Bodies
Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.
guide
CE marking AI-enabled hardware — CRA + AI Act overlap
How CE marking works for hardware embedding AI under the AI Act (Regulation (EU) 2024/1689) and the CRA — Article 6 high-risk routing, Article 48 CE, Annex I integration.
guide
CE marking for industrial sensors and gateways
EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.
guide
CE marking medical wearables — MDR + CRA overlap
How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.
Check your product