Cyber Resilience Act (EU) 2024/2847
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (the "Cyber Resilience Act" or CRA) makes cybersecurity a condition for placing hardware and software products on the Union market. It was published in the Official Journal on 20 November 2024 (OJ L, 2024/2847). Compliant products carry the CE marking.
Legal status and timeline
- Adoption: 23 October 2024.
- Entry into force: 10 December 2024 (twentieth day following publication, Article 71(1)).
- Chapter IV (Articles 35 to 51), notification of conformity assessment bodies: applies from 11 June 2026.
- Article 14, reporting obligations of manufacturers: applies from 11 September 2026.
- Full application: 11 December 2027 (Article 71(2)).
Under Article 69(2), products placed on the market before 11 December 2027 are subject to the Regulation only if they undergo a substantial modification from that date. Article 69(3) is the exception: the Article 14 reporting obligations apply to all in-scope products, whenever placed on the market.
Scope: products covered
Article 2(1) applies the Regulation to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Article 3(1) defines a "product with digital elements" as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately.
Exclusions
- Medical devices and in vitro diagnostic medical devices under Regulations (EU) 2017/745 and 2017/746 (Article 2(2)(a) and (b));
- Motor vehicles, their systems and components under Regulation (EU) 2019/2144 (Article 2(2)(c));
- Products certified in accordance with Regulation (EU) 2018/1139 on civil aviation (Article 2(3));
- Equipment within the scope of Directive 2014/90/EU on marine equipment (Article 2(4));
- Spare parts made available to replace identical components and manufactured to the same specifications (Article 2(6));
- Products developed or modified exclusively for national security or defence purposes, or specifically designed to process classified information (Article 2(7)).
Free and open-source software
Only software made available on the market — supplied in the course of a commercial activity — is in scope. Recital 18 states that providing free and open-source software that is not monetised by its manufacturer should not be considered a commercial activity. Article 24 creates a lighter regime for "open-source software stewards" (Article 3(14)): a documented cybersecurity policy, cooperation with market surveillance authorities and, to a defined extent, the Article 14 reporting obligations. Manufacturers that integrate open-source components must still exercise due diligence under Article 13(5).
Essential requirements: Annex I
Article 6 permits making a product available only where it meets Part I of Annex I and the manufacturer's processes meet Part II. Under Article 13(2) and (3), the manufacturer must carry out and document a cybersecurity risk assessment that determines how each requirement applies.
Part I — properties of the product
Products must ensure an appropriate level of cybersecurity based on the risks. Where applicable, they must be made available without known exploitable vulnerabilities and with a secure by default configuration; support security updates, including automatic updates by default with an opt-out; protect against unauthorised access and protect the confidentiality, integrity and availability of data and functions; apply data minimisation; limit attack surfaces; log relevant internal activity; and let users securely remove all data and settings.
Part II — vulnerability handling
Manufacturers must document components, including a software bill of materials covering at least top-level dependencies; remediate vulnerabilities without delay through security updates, separate from functionality updates where technically feasible; test security regularly; disclose fixed vulnerabilities; operate a coordinated vulnerability disclosure policy; and distribute security updates securely and, as a rule, free of charge.
Product categories and conformity assessment
Article 32(1) offers four routes: internal control (module A); EU-type examination followed by conformity to type based on internal production control (modules B + C); full quality assurance (module H); or, where available and applicable, a European cybersecurity certification scheme under Article 27(9). Which routes are open depends on the product's category.
| Category | Permitted procedures |
|---|---|
| Default (not listed in Annex III or IV) | Any Article 32(1) procedure, including module A self-assessment. |
| Important, class I (Annex III) | Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least "substantial" have been applied in full; otherwise B + C or H (Article 32(2)). |
| Important, class II (Annex III) | B + C, H, or a European cybersecurity certification scheme at assurance level at least "substantial" (Article 32(3)). |
| Critical (Annex IV) | A European cybersecurity certificate where required by delegated act under Article 8(1); otherwise any Article 32(3) procedure (Article 32(4)). |
Class I lists 19 categories, including identity and privileged access management systems, browsers, password managers, anti-malware software, VPNs, operating systems, routers, internet modems and switches, microprocessors and microcontrollers with security-related functionalities, smart home products with security functionalities (such as smart door locks, security cameras and baby monitors), certain internet-connected toys, and certain health-monitoring or children's wearables.
Class II lists hypervisors and container runtime systems; firewalls and intrusion detection and prevention systems; tamper-resistant microprocessors; and tamper-resistant microcontrollers.
Annex IV (critical) lists hardware devices with security boxes; smart meter gateways and other devices for advanced security purposes, including secure cryptoprocessing; and smartcards or similar devices, including secure elements. Recital 46 notes that these categories are covered by the EUCC scheme (Implementing Regulation (EU) 2024/482).
Classification follows the product's core functionality. Under Article 7(1), integrating an Annex III component does not in itself make the host product subject to the stricter procedures. Technical descriptions of the Annex III and IV categories are set out in Commission Implementing Regulation (EU) 2025/2392, adopted under Article 7(4). See conformity assessment modules and Notified Bodies.
Reporting obligations: Article 14
Since 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents having an impact on the security of their products. Notifications go simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established by ENISA under Article 16. The European Commission states that the platform has been operational since 11 September 2026. The competent CSIRT is that of the Member State of the manufacturer's main establishment in the Union (Article 14(7)).
| Stage | Actively exploited vulnerability (Art. 14(2)) | Severe incident (Art. 14(4)) |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Within 24 hours of becoming aware |
| Notification | Within 72 hours of becoming aware | Within 72 hours of becoming aware |
| Final report | No later than 14 days after a corrective or mitigating measure is available | Within one month after the incident notification |
An incident is severe where it affects, or could affect, the product's ability to protect sensitive or important data or functions, or could lead to the execution of malicious code (Article 14(5)). Manufacturers must also inform impacted users (Article 14(8)).
Technical documentation, EU Declaration of Conformity and CE marking
Technical documentation (Article 31 and Annex VII) must be drawn up before placing on the market and kept up to date at least during the support period. It includes the cybersecurity risk assessment, the vulnerability handling processes, the basis for the support period, the standards applied and test reports. See technical documentation.
EU Declaration of Conformity (Article 28, Annex V): where several Union acts require a Declaration, a single Declaration covers all of them (Article 28(3)). A copy of the Declaration, or the simplified Declaration in Annex VI giving the internet address of the full text, must accompany the product (Article 13(20)). See EU Declaration of Conformity.
CE marking (Articles 29 and 30): affixed visibly, legibly and indelibly to the product, or to the packaging and the Declaration where that is not possible. For software, the marking is affixed to the Declaration or on the website accompanying the software. It may be smaller than 5 mm where the nature of the product requires, provided it remains visible and legible. The Notified Body identification number follows the CE marking where that body is involved in a module H procedure (Article 30(4)).
Documentation and the Declaration must be kept for at least 10 years after placing on the market or for the support period, whichever is longer (Article 13(13)).
Interplay with other legislation
- Radio Equipment Directive 2014/53/EU and Delegated Regulation (EU) 2022/30. Recital 30 states that the CRA's essential requirements include all elements of RED Article 3(3)(d), (e) and (f), and anticipates the Commission repealing or amending Delegated Regulation 2022/30 for products subject to the CRA. Recital 100 states that bodies notified under Delegated Regulation 2022/30 must be newly assessed and notified under the CRA.
- Machinery Regulation (EU) 2023/1230. Recital 53: machinery that is also a product with digital elements must comply with both acts. CRA compliance can facilitate compliance with the machinery requirements on protection against corruption and safety and reliability of control systems (Annex III, sections 1.1.9 and 1.2.1); both conformity assessment procedures must be followed.
- AI Act (EU) 2024/1689. Under Article 12, high-risk AI systems that meet Annex I of the CRA, with that level of protection demonstrated in the CRA Declaration, are deemed to comply with the cybersecurity requirements of Article 15 of the AI Act. See AI Act and CE marking.
- General Product Safety Regulation (EU) 2023/988. Article 11 applies specified GPSR chapters to products with digital elements for risks not covered by the CRA and not subject to specific safety requirements in other harmonisation legislation.
Common errors
- Assuming nothing applies until December 2027. The Article 14 reporting obligations have applied since 11 September 2026 and cover products already on the market.
- Treating software as outside CE marking. Stand-alone software made available on the market is a product with digital elements and must carry the CE marking, on the Declaration or the accompanying website.
- Classifying by component rather than core functionality. A product does not become an important product merely because it integrates an Annex III component (Article 7(1)).
- Using module A for class I without full standards coverage. Partial application of harmonised standards, or their absence, requires B + C or H.
Frequently asked questions
Do the reporting obligations cover products placed on the market before 11 December 2027?
Yes. Article 69(3) applies the Article 14 obligations to all in-scope products with digital elements placed on the market before 11 December 2027. The other requirements apply to such products only if they undergo a substantial modification from that date.
Is open-source software covered?
Only where it is made available on the market, that is, supplied in the course of a commercial activity. Recital 18 states that free and open-source software not monetised by its manufacturer should not be considered a commercial activity. Open-source software stewards are subject to the lighter regime in Article 24.
Does an important product always need a Notified Body?
No. A class I product may use internal control (module A) where the manufacturer has applied in full harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial. Otherwise, and always for class II, module B + C, module H or, where available, a European cybersecurity certification scheme is required.
How long must security updates be provided?
The manufacturer determines a support period reflecting the expected time in use. Under Article 13(8) it must be at least five years, unless the product is expected to be in use for less than five years. Each security update must remain available for at least 10 years after issue or for the remainder of the support period, whichever is longer.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — EUR-Lex.
- Commission Implementing Regulation (EU) 2025/2392 (technical descriptions of important and critical products) — EUR-Lex.
- Commission Implementing Regulation (EU) 2024/482 (EUCC scheme) — EUR-Lex.
- Commission Delegated Regulation (EU) 2022/30 — EUR-Lex.
- European Commission — Cyber Resilience Act: reporting obligations.