# What is the Cyber Resilience Act (CRA)?

> The Cyber Resilience Act (CRA) is the European Union regulation establishing horizontal cybersecurity requirements for products with digital elements made available on the EU market.

- Canonical URL: https://yellowcube.eu/glossary/cyber-resilience-act/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Formally Regulation (EU) 2024/2847, it applies where the product’s intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. A product includes a remote data-processing solution only where that software is designed and developed by the manufacturer, or under its responsibility, and the product would not perform one of its functions without it. This general scope is subject to Article 2 exclusions and possible sector-specific limitations, including specified medical and in-vitro diagnostic devices, regulated motor vehicles, certified civil-aviation products, marine equipment, qualifying like-for-like spare parts, and products developed exclusively for national-security or defense purposes or specifically designed to process classified information.

The CRA entered into force on 10 December 2024. Its main obligations apply from **11 December 2027**. Provisions concerning notification of conformity-assessment bodies began applying on 11 June 2026, and the vulnerability and incident reporting obligations in Article 14 apply from **11 September 2026**. Article 14 also applies to in-scope products placed on the market before the main application date; other requirements generally affect earlier products when they are substantially modified from 11 December 2027. Transitional cases still require product-specific analysis.

### Key points

- **Manufacturer responsibilities:** Perform and document a cybersecurity risk assessment; design, develop, and produce the product to meet the essential requirements; manage vulnerabilities; provide security updates and user information; maintain technical documentation; conduct the required conformity assessment; and support market-surveillance obligations.
- **Secure lifecycle:** Requirements address secure-by-design and secure-by-default characteristics, protection from unauthorized access, confidentiality and integrity, attack-surface reduction, resilience, security logging where appropriate, vulnerability handling, coordinated disclosure, and remediation throughout the support period.
- **Support period:** Manufacturers must determine and communicate a support period reflecting the product’s expected use and the factors specified by the regulation. The period must generally be at least five years; where the product is expected to be used for less than five years, it may correspond to that shorter expected-use period. Each security update made available during the support period must remain available after issue for at least ten years or for the remainder of the support period, whichever is longer.
- **Conformity:** Many products can use internal control procedures, while products classified as important or critical may require stricter procedures or third-party assessment depending on category, standards, certification, and the applicable conformity route. CE marking communicates conformity with applicable EU requirements; it is not a promise that vulnerabilities will never exist.
- **Supply-chain roles:** Importers and distributors have their own duties, including checks before placing or making products available on the market and action when they believe a product is non-conforming. An importer or distributor that markets a product under its own name or trademark, or carries out a substantial modification, is considered a manufacturer and becomes subject to the manufacturer obligations.
- **Reporting from 11 September 2026:** Manufacturers must report actively exploited vulnerabilities and severe security incidents through the CRA Single Reporting Platform. Both processes begin with an early warning within 24 hours and a fuller notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the 72-hour notification for a severe incident.
- **Important limitation:** CRA scope, classification, conformity routes, reporting, and transition dates depend on the product, economic-operator role, and facts. CE marking and conformity assessment do not prove that a product is vulnerability-free, and publication decisions require qualified legal review.

### Related terms

[Secure by design](<https://yellowcube.eu/glossary/secure-by-design/>) · [Coordinated vulnerability disclosure (CVD)](<https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/>) · [Software bill of materials (SBOM)](<https://yellowcube.eu/glossary/software-bill-of-materials/>) · [NIS2 Directive](<https://yellowcube.eu/glossary/nis2-directive/>)

### Sources

[EUR-Lex: Regulation (EU) 2024/2847, especially Articles 2, 13–16, 43, and 68–71](https://eur-lex.europa.eu/eli/reg/2024/2847/oj) · [European Commission: Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act) · [European Commission: CRA Reporting Obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

