Cyber Resilience Act
In force (staggered)Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)
This applies to you if …
- You manufacture products with digital elements placed on the EU market (hardware or software).
- You import or distribute connected devices, apps, firmware or software components.
- You develop software sold on its own or as part of a product (B2B included).
Core obligations
- Implement security-by-design and security-by-default across the full product lifecycle.
- Establish vulnerability management and provide security updates throughout the defined support period.
- Report actively exploited vulnerabilities and severe incidents to ENISA / CSIRT within the deadlines.
- Carry out conformity assessment and provide CE marking with technical documentation.
Keep reading — free
Unlock the full content
Enter and confirm your email address: you subscribe to the Signal Forge newsletter by FORGE and get instant access to this and all other registration-gated content. You can unsubscribe at any time.
Already registered? The link from your confirmation email unlocks this device again.
First steps
- Create an inventory of all your products with digital elements and their components (including open-source dependencies).
- Determine which category (default / important / critical) each product falls into.
- Define a process for vulnerability reporting, patch delivery and support period.
- Prepare technical documentation and an SBOM (Software Bill of Materials).
Deadlines
- 2024-12-10Regulation entered into force
- 2026-09-11Reporting obligations for actively exploited vulnerabilities and severe incidents apply
- 2027-12-11Full applicability of manufacturer obligations (CE marking, conformity assessment)
Penalty for non-compliance
Fines up to EUR 15 million or 2.5 % of worldwide annual turnover (for breaching the essential cybersecurity requirements); tiered framework for other infringements.