The CRA framework

This section is the site’s single source of truth on the Cyber Resilience Act. Everything else — Legal path, Cyber path, organisation — links here rather than rephrasing.

Identity of the text

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).

Milestone Date
Adoption 23 October 2024
Publication in the Official Journal of the European Union 20 November 2024
Entry into force 10 December 2024
Application of the provisions on notified bodies 11 June 2026
Application of the reporting obligations (Art. 14) 11 September 2026
Full application 11 December 2027

It is a Regulation, therefore directly applicable across all twenty-seven Member States with no transposition — unlike the NIS 2 Directive. It is also Union harmonisation legislation under the “new legislative framework”: it borrows the grammar of CE marking for machinery or toys and applies it to cybersecurity.

Practical consequence: the notions of placing on the market, essential requirements, presumption of conformity through harmonised standards, assessment modules, technical documentation and EU declaration of conformity are not CRA inventions. Teams that already handle other CE markings know this vocabulary, and it should remain theirs.

What the Regulation pursues

The five objectives stated by the legislator, useful to cite internally when building a case:

  1. reduce the number of vulnerable products placed on the market;
  2. make manufacturers accountable for security across the whole life cycle, not only at the point of sale;
  3. improve transparency about the security properties of products;
  4. enable users, professional and consumer alike, to choose and use secure products;
  5. close the gaps between existing sectoral legislation.

Structure of the Regulation

Part Content
Chapter I Subject matter, scope, definitions
Chapter II Obligations of economic operators, provisions on open source
Chapter III Presumption of conformity, harmonised standards, conformity assessment
Chapter IV Notification of conformity assessment bodies
Chapter V Market surveillance and enforcement
Chapter VI Delegated and implementing acts
Chapter VII Confidentiality and penalties
Chapter VIII Transitional and final provisions
Annex I Essential requirements — Part I: product security; Part II: vulnerability handling
Annex II Information and instructions to the user
Annex III Important products — Part I (class I) and Part II (class II)
Annex IV Critical products
Annex V Content of the EU declaration of conformity
Annex VI Simplified EU declaration of conformity
Annex VII Content of the technical documentation
Annex VIII Conformity assessment procedures

Official sources

Caveat. The pages in this section are a working reading. The article and annex numbers cited must be checked against the consolidated text before any enforceable use, and the pages must be reviewed by legal counsel.

In this section

  • Legal

    Regulation (EU) 2024/2847

    Identity, legal nature, objectives and structure of the Cyber Resilience Act, with publication milestones and the official sources to cite.

  • Legal

    Scope: products with digital elements

    Definition of a PDE, breakdown into hardware / software / remote data processing, triggering criteria, and the notions of placing on the market and substantial modification.

  • Legal

    Exclusions from scope

    Medical devices, motor vehicles, civil aviation, marine equipment, defence, spare parts, non-commercial open source: what the Regulation leaves out, and the false friends.

  • Legal

    Interplay with other legislation

    NIS 2, Cybersecurity Act, AI Act, RED, Machinery, GPSR, DORA, GDPR, product liability: where the CRA stops, where it overlaps, and how to pool evidence.

  • Cross-cutting

    Criticality classes

    Default, Important class I, Important class II, Critical: the classification determines whether a notified body is mandatory, and therefore the cost, the lead time and the critical path.

  • Cyber

    Essential requirements

    Annex I: thirteen product security requirements in Part I, eight vulnerability handling obligations in Part II. The substance of the Regulation, identical for every class.

  • Legal

    Conformity assessment

    Presumption of conformity, harmonised standards and request M/606, modules A, B+C and H, notified bodies, EUCC certification, and support measures for SMEs.

  • Legal

    CE marking

    What the marking means legally, the seven cumulative conditions before affixing it, the rules for software, and the commercial gate it represents.

  • Legal

    Technical documentation (Annex VII)

    The standard file structure, where the SBOM sits, the ten-year retention rule, and the completeness checklist to run before the pre-market review.

  • Legal

    Support period and life cycle

    Five years minimum or the expected lifetime, ten years of fix availability, the duty to inform the buyer, end of support and cessation of operations: the CRA's long-term commitment.

  • Cross-cutting

    Free and open-source software

    The criterion is not the licence but the commercial nature of the supply. Four statuses, from the out-of-scope individual contributor to the fully responsible manufacturer.

  • Legal

    Economic operators and their responsibilities

    Manufacturer, authorised representative, importer, distributor, and the shift of responsibility in white-label arrangements. The authorities: Commission, ENISA, CSIRTs, market surveillance, notified bodies.

  • Cross-cutting

    Reporting to ENISA and CSIRTs

    The nearest obligation: 24 hours, 72 hours, 14 days or one month. Triggers, the meaning of active exploitation, the single reporting platform, confidentiality and the extended time scope.

  • Leadership

    The timeline

    The three application dates, the transitional regime, the derogation that subjects the legacy portfolio to reporting, and the internal back-planning that follows.

  • Leadership

    Penalties

    The three-tier scale, the modulating criteria, non-financial measures — often heavier than the fine — and the interaction with product liability.

  • Legal

    Market surveillance

    Authorities' powers, the procedure for products presenting a significant risk, formal non-compliance, coordinated sweeps, and the response card for an authority request.