CECheck The reference for CE marking

Cyber Resilience Act (EU) 2024/2847

Last reviewed: October 2026 · Legal status verified against EUR-Lex.

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (the "Cyber Resilience Act" or CRA) makes cybersecurity a condition for placing hardware and software products on the Union market. It was published in the Official Journal on 20 November 2024 (OJ L, 2024/2847). Compliant products carry the CE marking.

Legal status and timeline

Under Article 69(2), products placed on the market before 11 December 2027 are subject to the Regulation only if they undergo a substantial modification from that date. Article 69(3) is the exception: the Article 14 reporting obligations apply to all in-scope products, whenever placed on the market.

Scope: products covered

Article 2(1) applies the Regulation to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Article 3(1) defines a "product with digital elements" as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately.

Exclusions

Free and open-source software

Only software made available on the market — supplied in the course of a commercial activity — is in scope. Recital 18 states that providing free and open-source software that is not monetised by its manufacturer should not be considered a commercial activity. Article 24 creates a lighter regime for "open-source software stewards" (Article 3(14)): a documented cybersecurity policy, cooperation with market surveillance authorities and, to a defined extent, the Article 14 reporting obligations. Manufacturers that integrate open-source components must still exercise due diligence under Article 13(5).

Essential requirements: Annex I

Article 6 permits making a product available only where it meets Part I of Annex I and the manufacturer's processes meet Part II. Under Article 13(2) and (3), the manufacturer must carry out and document a cybersecurity risk assessment that determines how each requirement applies.

Part I — properties of the product

Products must ensure an appropriate level of cybersecurity based on the risks. Where applicable, they must be made available without known exploitable vulnerabilities and with a secure by default configuration; support security updates, including automatic updates by default with an opt-out; protect against unauthorised access and protect the confidentiality, integrity and availability of data and functions; apply data minimisation; limit attack surfaces; log relevant internal activity; and let users securely remove all data and settings.

Part II — vulnerability handling

Manufacturers must document components, including a software bill of materials covering at least top-level dependencies; remediate vulnerabilities without delay through security updates, separate from functionality updates where technically feasible; test security regularly; disclose fixed vulnerabilities; operate a coordinated vulnerability disclosure policy; and distribute security updates securely and, as a rule, free of charge.

The support period must reflect the time the product is expected to be in use and must be at least five years, unless the expected use time is shorter (Article 13(8)). Each security update must remain available for at least 10 years after issue or for the rest of the support period, whichever is longer (Article 13(9)). The end date of the support period, at least month and year, must be stated at the time of purchase (Article 13(19)).

Product categories and conformity assessment

Article 32(1) offers four routes: internal control (module A); EU-type examination followed by conformity to type based on internal production control (modules B + C); full quality assurance (module H); or, where available and applicable, a European cybersecurity certification scheme under Article 27(9). Which routes are open depends on the product's category.

CategoryPermitted procedures
Default (not listed in Annex III or IV)Any Article 32(1) procedure, including module A self-assessment.
Important, class I (Annex III)Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least "substantial" have been applied in full; otherwise B + C or H (Article 32(2)).
Important, class II (Annex III)B + C, H, or a European cybersecurity certification scheme at assurance level at least "substantial" (Article 32(3)).
Critical (Annex IV)A European cybersecurity certificate where required by delegated act under Article 8(1); otherwise any Article 32(3) procedure (Article 32(4)).

Class I lists 19 categories, including identity and privileged access management systems, browsers, password managers, anti-malware software, VPNs, operating systems, routers, internet modems and switches, microprocessors and microcontrollers with security-related functionalities, smart home products with security functionalities (such as smart door locks, security cameras and baby monitors), certain internet-connected toys, and certain health-monitoring or children's wearables.

Class II lists hypervisors and container runtime systems; firewalls and intrusion detection and prevention systems; tamper-resistant microprocessors; and tamper-resistant microcontrollers.

Annex IV (critical) lists hardware devices with security boxes; smart meter gateways and other devices for advanced security purposes, including secure cryptoprocessing; and smartcards or similar devices, including secure elements. Recital 46 notes that these categories are covered by the EUCC scheme (Implementing Regulation (EU) 2024/482).

Classification follows the product's core functionality. Under Article 7(1), integrating an Annex III component does not in itself make the host product subject to the stricter procedures. Technical descriptions of the Annex III and IV categories are set out in Commission Implementing Regulation (EU) 2025/2392, adopted under Article 7(4). See conformity assessment modules and Notified Bodies.

Reporting obligations: Article 14

Since 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents having an impact on the security of their products. Notifications go simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established by ENISA under Article 16. The European Commission states that the platform has been operational since 11 September 2026. The competent CSIRT is that of the Member State of the manufacturer's main establishment in the Union (Article 14(7)).

StageActively exploited vulnerability (Art. 14(2))Severe incident (Art. 14(4))
Early warningWithin 24 hours of becoming awareWithin 24 hours of becoming aware
NotificationWithin 72 hours of becoming awareWithin 72 hours of becoming aware
Final reportNo later than 14 days after a corrective or mitigating measure is availableWithin one month after the incident notification

An incident is severe where it affects, or could affect, the product's ability to protect sensitive or important data or functions, or could lead to the execution of malicious code (Article 14(5)). Manufacturers must also inform impacted users (Article 14(8)).

Technical documentation, EU Declaration of Conformity and CE marking

Technical documentation (Article 31 and Annex VII) must be drawn up before placing on the market and kept up to date at least during the support period. It includes the cybersecurity risk assessment, the vulnerability handling processes, the basis for the support period, the standards applied and test reports. See technical documentation.

EU Declaration of Conformity (Article 28, Annex V): where several Union acts require a Declaration, a single Declaration covers all of them (Article 28(3)). A copy of the Declaration, or the simplified Declaration in Annex VI giving the internet address of the full text, must accompany the product (Article 13(20)). See EU Declaration of Conformity.

CE marking (Articles 29 and 30): affixed visibly, legibly and indelibly to the product, or to the packaging and the Declaration where that is not possible. For software, the marking is affixed to the Declaration or on the website accompanying the software. It may be smaller than 5 mm where the nature of the product requires, provided it remains visible and legible. The Notified Body identification number follows the CE marking where that body is involved in a module H procedure (Article 30(4)).

Documentation and the Declaration must be kept for at least 10 years after placing on the market or for the support period, whichever is longer (Article 13(13)).

Interplay with other legislation

Common errors

Frequently asked questions

Do the reporting obligations cover products placed on the market before 11 December 2027?

Yes. Article 69(3) applies the Article 14 obligations to all in-scope products with digital elements placed on the market before 11 December 2027. The other requirements apply to such products only if they undergo a substantial modification from that date.

Is open-source software covered?

Only where it is made available on the market, that is, supplied in the course of a commercial activity. Recital 18 states that free and open-source software not monetised by its manufacturer should not be considered a commercial activity. Open-source software stewards are subject to the lighter regime in Article 24.

Does an important product always need a Notified Body?

No. A class I product may use internal control (module A) where the manufacturer has applied in full harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial. Otherwise, and always for class II, module B + C, module H or, where available, a European cybersecurity certification scheme is required.

How long must security updates be provided?

The manufacturer determines a support period reflecting the expected time in use. Under Article 13(8) it must be at least five years, unless the product is expected to be in use for less than five years. Each security update must remain available for at least 10 years after issue or for the remainder of the support period, whichever is longer.

Sources