EU Regulatory Center

Cyber Resilience Act — security by design for connected products

Essential cybersecurity requirements for hardware and software products with digital elements, from design through end of support.

Status

Law in force
Regulation (EU) 2024/2847
The CRA entered into force in December 2024 and introduces mandatory cybersecurity requirements for manufacturers, importers and distributors of products with digital elements placed on the EU market, with obligations phasing in over several years — including vulnerability and incident reporting duties ahead of the regulation’s full application.
Reviewed 2026-06 · Source: Official Journal of the European Union

Scope at a glance

QuestionAnswer
WhoManufacturers, importers and distributors of hardware and software products with digital elements sold in the EU.
WhatSecurity-by-design requirements, vulnerability handling, and a Software Bill of Materials (SBOM) for covered products.
ReportingManufacturers must report actively exploited vulnerabilities and severe incidents to the relevant authority.
LifecycleObligations extend across the product lifecycle, including security updates for a defined support period.

Core obligations

General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps

Supply Chain Security tracks SBOM exposure against known vulnerabilities, and Evidence keeps the artifacts a CRA conformity assessment will ask for.

See Supply Chain Security
How CYRKIL tracks this

Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.

See the pipeline

Get a readiness review against this regulation.