Regulations library · European Union
CRA
Cyber Resilience Act, Regulation (EU) 2024/2847
In force European Union security products
Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.
At a glance
- Who it applies to
- Manufacturers, importers and distributors of products with digital elements sold in the EU.
- Who enforces it
- National market surveillance authorities
- When
- In effect since 10 December 2024. Vulnerability and incident reporting from 11 September 2026; most obligations from 11 December 2027.
This is a reference entry. The priority laws get a full practical guide first.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Regulation (EU) 2024/2847 EUR-Lex · Official text or regulator
Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.