EU Cyber Resilience Act (Regulation (EU) 2024/2847)
The Cyber Resilience Act is a European Union regulation that mandates cybersecurity requirements for products with digital elements throughout their entire lifecycle. It exists to ensure that hardware and software sold in the EU market are secure by design and default, reducing systemic vulnerabilities across the digital ecosystem.
Who it applies to
- Manufacturers of hardware products containing software or electronic components.
- Developers of standalone software applications and operating systems.
- Non-EU based companies that export digital products into the EU market.
- Importers and distributors who must ensure a compliant representative is established within the Union.
How it works
The Act establishes "essential security requirements" focusing on the product's design, development, and maintenance phases. Products are categorized by risk level: default products typically undergo self-assessment, while higher-risk categories—such as password managers or network interfaces (Critical Class I and II)—may require third-party audits to verify compliance.
To demonstrate conformity, manufacturers must perform a technical assessment, create detailed documentation known as a Technical File, and affix the CE marking to the product. Once on the market, companies are required to provide security updates for the expected lifetime of the product and report actively exploited vulnerabilities to ENISA within 24 hours.
Getting started
- Identify all products in your portfolio that qualify as "products with digital elements."
- Categorize each product based on its risk level (Default, Critical Class I, or Critical Class II) to determine the required assessment path.
- Conduct a gap analysis between current development practices and the Act's essential security requirements.
- Implement a vulnerability handling process for tracking, patching, and reporting flaws.
- Compile the necessary technical documentation and declarations of conformity for each product line.
Controls & requirements
- Art. 2 Which products are in scope: products with digital elements
- Annex I Part I Essential cybersecurity requirements
- Annex I Part II Vulnerability handling requirements
- Secure by design and by default
- Annexes III–IV Important and critical product classes
- Conformity assessment and CE marking
- Art. 14 Reporting actively exploited vulnerabilities and severe incidents
- The support period and security updates
- How the CRA treats open-source software
- Application timeline and penalties
Common misconceptions
- It only applies to software: The Act covers any hardware product that incorporates digital elements, including IoT devices and industrial controllers.
- Compliance is a one-time certification: Compliance requires ongoing lifecycle management, including continuous security updates and mandatory vulnerability reporting for the duration of the product's support period.