The Cyber Resilience Act (CRA) was officially published in the Official Journal of the European Union on 20 November 2024, marking a key milestone in Europe’s cybersecurity framework. The Regulation will come into force on 10 December 2024, with its main provisions expected to take effect in late 2027. Reporting obligations for manufacturers will apply from 11 September 2026.
The CRA applies to connected software and hardware products, regardless of whether they connect directly or indirectly to another device or network. Exceptions include products already governed by specific regulations, such as medical devices, aeronautical equipment, and cars. This broad scope encompasses consumer electronics and complex industrial systems.
The CRA seeks to strengthen consumer protection and bolster cybersecurity by:
The CRA introduces comprehensive obligations for manufacturers, distributors, and importers of digital products, including standalone components and remote data processing solutions.
To find out more about the CRA, please read this article: New cybersecurity requirements for products with digital components - adoption of the Cyber Resilience Act (CRA)