Back to the navigator

Cyber Resilience Act

In force (staggered)

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)

As of: 2026-08-02 Maintained by: Ruth/Content

This applies to you if …

Core obligations

Keep reading — free

Unlock the full content

Enter and confirm your email address: you subscribe to the Signal Forge newsletter by FORGE and get instant access to this and all other registration-gated content. You can unsubscribe at any time.

Already registered? The link from your confirmation email unlocks this device again.

First steps

  • Create an inventory of all your products with digital elements and their components (including open-source dependencies).
  • Determine which category (default / important / critical) each product falls into.
  • Define a process for vulnerability reporting, patch delivery and support period.
  • Prepare technical documentation and an SBOM (Software Bill of Materials).

Deadlines

  • 2024-12-10Regulation entered into force
  • 2026-09-11Reporting obligations for actively exploited vulnerabilities and severe incidents apply
  • 2027-12-11Full applicability of manufacturer obligations (CE marking, conformity assessment)

Penalty for non-compliance

Fines up to EUR 15 million or 2.5 % of worldwide annual turnover (for breaching the essential cybersecurity requirements); tiered framework for other infringements.

Sources