Home › Law library › Cyber Resilience Act (CRA)
EU
Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)
Sourced. Last verified 9 October 2026
European Union Cybersecurity
- Status
- In force since 10 Dec 2024; reporting obligations apply from 11 Sep 2026; main obligations from 11 Dec 2027.
- Who it applies to
- Manufacturers, importers and distributors of hardware and software products with digital elements placed on the EU market, wherever they are based (consumer IoT, apps, software, components).
- Size thresholds
- None — applies regardless of size; no fines on micro/small firms for missing the 24h early-warning deadline.
- Regulator
- National market surveillance authorities and CSIRTs; ENISA runs the Single Reporting Platform
- Breach or incident reporting
- Actively exploited vulnerabilities and severe incidents: early warning within 24h, notification within 72h; final report 14 days after a fix (vulnerabilities) or 1 month after notification (incidents). Via ENISA Single Reporting Platform.
- Local representative
- Non-EU manufacturers may appoint an EU authorised representative; importers must ensure compliance.
- Maximum penalty
- Up to EUR 15m or 2.5% of worldwide turnover (essential requirements, Arts 13-14); EUR 10m or 2% (other duties); EUR 5m or 1% (misleading info).
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Report actively exploited vulnerabilities and severe incidents within 24h (from 11 Sep 2026).
- Register on ENISA's Single Reporting Platform and assign a reporting owner.
- Design products to meet Annex I security requirements by 11 Dec 2027.
- Define a support period and ship security updates throughout it.
- Keep an SBOM and run a coordinated vulnerability disclosure policy.
- Complete conformity assessment and CE marking before placing products on the market.
Recent changes
Reporting obligations went live 11 Sep 2026 with ENISA's Single Reporting Platform; delegated act on delayed CSIRT sharing adopted 11 Dec 2025.
Sources
- Primary source: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- Second source: https://www.mccannfitzgerald.com/knowledge/data-privacy-and-cyber-risk/cyber-resilience-act-reporting-obligations-apply-from-11-september-2026
- Regulator: National market surveillance authorities and CSIRTs; ENISA runs the Single Reporting Platform
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].