Regulation (EU) 2024/2847
How to cite the text
In full, once per document:
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).
Thereafter: “Regulation (EU) 2024/2847” or “the CRA”. Avoid “the CRA directive” and “the CRA law”, which are wrong and discredit the document they appear in.
What “Regulation” means in practice
| Directive (e.g. NIS 2) | Regulation (e.g. CRA) | |
|---|---|---|
| Effect | Must be transposed into national law | Directly applicable |
| National delay | A transposition deadline, often missed | None |
| Variation between States | Possible, sometimes significant | Marginal |
| Text to read | The national transposing law | The European text itself |
There will therefore be no national CRA law to delay, soften or clarify the deadline. Member States intervene on three points only: designating authorities (market surveillance, notifying authority, coordinating CSIRT), setting the penalty regime within the ceilings the Regulation fixes, and support measures for small enterprises.
The lineage: the new legislative framework
The CRA is Union harmonisation legislation. It reuses the proven architecture of product directives and regulations:
- essential requirements expressed as objectives, not technical solutions (Annex I);
- a presumption of conformity for those applying harmonised standards;
- conformity assessment modules graduated by risk;
- technical documentation and an EU declaration of conformity;
- the CE marking as the signal of conformity;
- market surveillance after the fact, with power to withdraw.
Two practical consequences. First, teams already handling other CE markings — machinery, radio equipment, toys — know this vocabulary: reuse their processes rather than inventing new ones. Second, the Regulation almost never says how: it says what result to achieve, and leaves the proof to the manufacturer.
The legislator’s five objectives
Useful to cite in an internal memo justifying the effort:
- reduce the number of vulnerable products placed on the Union market;
- make manufacturers responsible for security across the whole life cycle, not only at the point of sale;
- improve transparency about the security properties of products;
- enable users — businesses and consumers — to choose and use secure products;
- close the gaps between existing sectoral legislation.
Date markers
| Date | Event |
|---|---|
| 23 October 2024 | Adopted by the European Parliament and the Council |
| 20 November 2024 | Published in the Official Journal of the European Union |
| 10 December 2024 | Entry into force — the text is final, the clocks start |
| 11 June 2026 | Application of the chapter on notification of conformity assessment bodies |
| 11 September 2026 | Application of the Article 14 reporting obligations |
| 11 December 2027 | Full application |
The operational consequences of each date are set out in The timeline.
Sources to rely on
- EUR-Lex — Regulation (EU) 2024/2847 — the consolidated text, the only authoritative version. All language versions have equal legal force; where a national wording seems ambiguous, compare with English.
- European Commission — the Cyber Resilience Act page: guidance, FAQ, delegated and implementing acts as they are adopted.
- ENISA — single reporting platform, European vulnerability database, technical documents.
- CEN and CENELEC — progress of the harmonised standards (joint technical committee JTC 13, working group 9), which conditions the presumption of conformity.
- ANSSI — national implementation guidance, and CERT-FR for alerts.
What is not a source. Vendor blog posts, commercial white papers and unverified AI-generated summaries circulate widely and contain recurring errors, particularly about criticality classes and the status of open source. Any statement reused internally must be traceable to an article or an annex.