The CRA framework
This section is the site’s single source of truth on the Cyber Resilience Act. Everything else — Legal path, Cyber path, organisation — links here rather than rephrasing.
Identity of the text
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).
| Milestone | Date |
|---|---|
| Adoption | 23 October 2024 |
| Publication in the Official Journal of the European Union | 20 November 2024 |
| Entry into force | 10 December 2024 |
| Application of the provisions on notified bodies | 11 June 2026 |
| Application of the reporting obligations (Art. 14) | 11 September 2026 |
| Full application | 11 December 2027 |
Legal nature
It is a Regulation, therefore directly applicable across all twenty-seven Member States with no transposition — unlike the NIS 2 Directive. It is also Union harmonisation legislation under the “new legislative framework”: it borrows the grammar of CE marking for machinery or toys and applies it to cybersecurity.
Practical consequence: the notions of placing on the market, essential requirements, presumption of conformity through harmonised standards, assessment modules, technical documentation and EU declaration of conformity are not CRA inventions. Teams that already handle other CE markings know this vocabulary, and it should remain theirs.
What the Regulation pursues
The five objectives stated by the legislator, useful to cite internally when building a case:
- reduce the number of vulnerable products placed on the market;
- make manufacturers accountable for security across the whole life cycle, not only at the point of sale;
- improve transparency about the security properties of products;
- enable users, professional and consumer alike, to choose and use secure products;
- close the gaps between existing sectoral legislation.
Structure of the Regulation
| Part | Content |
|---|---|
| Chapter I | Subject matter, scope, definitions |
| Chapter II | Obligations of economic operators, provisions on open source |
| Chapter III | Presumption of conformity, harmonised standards, conformity assessment |
| Chapter IV | Notification of conformity assessment bodies |
| Chapter V | Market surveillance and enforcement |
| Chapter VI | Delegated and implementing acts |
| Chapter VII | Confidentiality and penalties |
| Chapter VIII | Transitional and final provisions |
| Annex I | Essential requirements — Part I: product security; Part II: vulnerability handling |
| Annex II | Information and instructions to the user |
| Annex III | Important products — Part I (class I) and Part II (class II) |
| Annex IV | Critical products |
| Annex V | Content of the EU declaration of conformity |
| Annex VI | Simplified EU declaration of conformity |
| Annex VII | Content of the technical documentation |
| Annex VIII | Conformity assessment procedures |
Official sources
- The text of the Regulation on EUR-Lex: Regulation (EU) 2024/2847 — the only authoritative version. All twenty-four language versions carry equal legal force.
- The European Commission’s Cyber Resilience Act page: digital-strategy.ec.europa.eu — guidance, FAQ, delegated and implementing acts as they are adopted.
- ENISA: enisa.europa.eu for publications, and the European vulnerability database at euvd.enisa.europa.eu.
- CEN and CENELEC: cencenelec.eu, for progress on the harmonised standards that condition the presumption of conformity.
- ANSSI: cyber.gouv.fr, and CERT-FR for alerts.
Caveat. The pages in this section are a working reading. The article and annex numbers cited must be checked against the consolidated text before any enforceable use, and the pages must be reviewed by legal counsel.
In this section
Legal
Regulation (EU) 2024/2847
Identity, legal nature, objectives and structure of the Cyber Resilience Act, with publication milestones and the official sources to cite.
Legal
Scope: products with digital elements
Definition of a PDE, breakdown into hardware / software / remote data processing, triggering criteria, and the notions of placing on the market and substantial modification.
Legal
Exclusions from scope
Medical devices, motor vehicles, civil aviation, marine equipment, defence, spare parts, non-commercial open source: what the Regulation leaves out, and the false friends.
Legal
Interplay with other legislation
NIS 2, Cybersecurity Act, AI Act, RED, Machinery, GPSR, DORA, GDPR, product liability: where the CRA stops, where it overlaps, and how to pool evidence.
Cross-cutting
Criticality classes
Default, Important class I, Important class II, Critical: the classification determines whether a notified body is mandatory, and therefore the cost, the lead time and the critical path.
Cyber
Essential requirements
Annex I: thirteen product security requirements in Part I, eight vulnerability handling obligations in Part II. The substance of the Regulation, identical for every class.
Legal
Conformity assessment
Presumption of conformity, harmonised standards and request M/606, modules A, B+C and H, notified bodies, EUCC certification, and support measures for SMEs.
Legal
CE marking
What the marking means legally, the seven cumulative conditions before affixing it, the rules for software, and the commercial gate it represents.
Legal
Technical documentation (Annex VII)
The standard file structure, where the SBOM sits, the ten-year retention rule, and the completeness checklist to run before the pre-market review.
Legal
Support period and life cycle
Five years minimum or the expected lifetime, ten years of fix availability, the duty to inform the buyer, end of support and cessation of operations: the CRA's long-term commitment.
Cross-cutting
Free and open-source software
The criterion is not the licence but the commercial nature of the supply. Four statuses, from the out-of-scope individual contributor to the fully responsible manufacturer.
Legal
Economic operators and their responsibilities
Manufacturer, authorised representative, importer, distributor, and the shift of responsibility in white-label arrangements. The authorities: Commission, ENISA, CSIRTs, market surveillance, notified bodies.
Cross-cutting
Reporting to ENISA and CSIRTs
The nearest obligation: 24 hours, 72 hours, 14 days or one month. Triggers, the meaning of active exploitation, the single reporting platform, confidentiality and the extended time scope.
Leadership
The timeline
The three application dates, the transitional regime, the derogation that subjects the legacy portfolio to reporting, and the internal back-planning that follows.
Leadership
Penalties
The three-tier scale, the modulating criteria, non-financial measures — often heavier than the fine — and the interaction with product liability.
Legal
Market surveillance
Authorities' powers, the procedure for products presenting a significant risk, formal non-compliance, coordinated sweeps, and the response card for an authority request.