started · updated
European Union implements Cyber Resilience Act for digital products
The European Union's Cyber Resilience Act (CRA), officially Regulation (EU) 2024/2847, establishes mandatory cybersecurity requirements for digital products, including hardware and software with network connectivity. The regulation mandates a ‘Security by Design’ approach, requiring manufacturers, importers, and distributors to ensure cybersecurity is integrated from the initial stages of product development.
Obligations cover the entire product lifecycle, including secure development, providing security updates throughout the expected period of use, maintaining technical documentation, and reporting security incidents. The CRA is distinct from the NIS-2 directive; while NIS-2 focuses on the security of organizational operations in critical sectors, the CRA regulates the digital products themselves.
The regulation entered into force on December 10, 2024. Reporting requirements for actively exploited vulnerabilities and serious security incidents will begin on September 11, 2026. Full compliance, including CE marking and technical documentation requirements, becomes mandatory on December 11, 2027.