Definition
Cyber Resilience Act (CRA)
Also: Regulation (EU) 2024/2847
EU regulation setting cybersecurity requirements for products with digital elements placed on the EU market, including vulnerability handling and incident reporting.
Regulation (EU) 2024/2847 of 23 October 2024 lays down horizontal cybersecurity requirements for products with digital elements — hardware and software — placed on the EU market. It obliges manufacturers to design products securely, handle vulnerabilities throughout a defined support period, report actively exploited vulnerabilities and severe incidents, draw up technical documentation and affix the CE marking after conformity assessment. It entered into force on 10 December 2024; Article 14 reporting obligations have applied since 11 September 2026 and the regulation applies in full from 11 December 2027.
Reference: Regulation (EU) 2024/2847, Art. 1 and Art. 71 · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.