EU Regulatory Center
Cyber Resilience Act — security by design for connected products
Essential cybersecurity requirements for hardware and software products with digital elements, from design through end of support.
Status
Law in force
Regulation (EU) 2024/2847
The CRA entered into force in December 2024 and introduces mandatory cybersecurity requirements for manufacturers, importers and distributors of products with digital elements placed on the EU market, with obligations phasing in over several years — including vulnerability and incident reporting duties ahead of the regulation’s full application.
Scope at a glance
| Question | Answer |
|---|---|
| Who | Manufacturers, importers and distributors of hardware and software products with digital elements sold in the EU. |
| What | Security-by-design requirements, vulnerability handling, and a Software Bill of Materials (SBOM) for covered products. |
| Reporting | Manufacturers must report actively exploited vulnerabilities and severe incidents to the relevant authority. |
| Lifecycle | Obligations extend across the product lifecycle, including security updates for a defined support period. |
Core obligations
- Apply security-by-design and security-by-default principles during product development.
- Maintain a Software Bill of Materials (SBOM) and a vulnerability-handling process.
- Report qualifying vulnerabilities and incidents within the regulation’s timelines.
- Provide security updates for the product’s defined support period.
General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps
Supply Chain Security tracks SBOM exposure against known vulnerabilities, and Evidence keeps the artifacts a CRA conformity assessment will ask for.
See Supply Chain SecurityHow CYRKIL tracks this
Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.
See the pipeline