Regulation (EU) 2024/2847
Cyber Resilience Act
Cybersecurity requirements for every product with digital elements sold in the EU: connected hardware, software, and the remote processing that is part of a product. The catalog carries its requirements as controls, so readings from your source control, vulnerability scanner and clouds land on them as evidence.
What the regulation asks of a manufacturer
Secure by design and by default
Security requirements apply across the whole lifecycle of a product with digital elements, from design to the end of the support period.
Conformity assessment and CE marking
A manufacturer assesses conformity before placing the product on the market and affixes the CE marking to it.
Security updates for the support period
Vulnerabilities are handled and fixed for the support period, which is at least five years unless the product is expected to be in use for less.
Reporting of exploited vulnerabilities
An actively exploited vulnerability or a severe incident goes to ENISA and the national CSIRT: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days.
When it applies
The reporting duties come first; the rest follows a year later. Read the regulation.
- 10 December 2024Entered into force, twenty days after publication in the Official Journal.
- 11 September 2026Vulnerability and incident reporting duties apply.
- 11 December 2027Most obligations apply to products placed on the market.
See the CRA controls on your own tools
Thirty minutes. We connect one of your integrations live and show the first readings landing on your controls.