Auditen
Home / Frameworks / Cyber Resilience Act

EU Cyber Resilience Act (Regulation (EU) 2024/2847)

The Cyber Resilience Act is a European Union regulation that mandates cybersecurity requirements for products with digital elements throughout their entire lifecycle. It exists to ensure that hardware and software sold in the EU market are secure by design and default, reducing systemic vulnerabilities across the digital ecosystem.

Who it applies to

  • Manufacturers of hardware products containing software or electronic components.
  • Developers of standalone software applications and operating systems.
  • Non-EU based companies that export digital products into the EU market.
  • Importers and distributors who must ensure a compliant representative is established within the Union.

How it works

The Act establishes "essential security requirements" focusing on the product's design, development, and maintenance phases. Products are categorized by risk level: default products typically undergo self-assessment, while higher-risk categories—such as password managers or network interfaces (Critical Class I and II)—may require third-party audits to verify compliance.

To demonstrate conformity, manufacturers must perform a technical assessment, create detailed documentation known as a Technical File, and affix the CE marking to the product. Once on the market, companies are required to provide security updates for the expected lifetime of the product and report actively exploited vulnerabilities to ENISA within 24 hours.

Getting started

  1. Identify all products in your portfolio that qualify as "products with digital elements."
  2. Categorize each product based on its risk level (Default, Critical Class I, or Critical Class II) to determine the required assessment path.
  3. Conduct a gap analysis between current development practices and the Act's essential security requirements.
  4. Implement a vulnerability handling process for tracking, patching, and reporting flaws.
  5. Compile the necessary technical documentation and declarations of conformity for each product line.

Controls & requirements

Common misconceptions

  • It only applies to software: The Act covers any hardware product that incorporates digital elements, including IoT devices and industrial controllers.
  • Compliance is a one-time certification: Compliance requires ongoing lifecycle management, including continuous security updates and mandatory vulnerability reporting for the duration of the product's support period.