Skip to content
GlanceDeskJurisdiction

Home › Law library › Cyber Resilience Act (CRA)

EU

Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)

Sourced. Last verified 9 October 2026

European Union Cybersecurity

Status
In force since 10 Dec 2024; reporting obligations apply from 11 Sep 2026; main obligations from 11 Dec 2027.
Who it applies to
Manufacturers, importers and distributors of hardware and software products with digital elements placed on the EU market, wherever they are based (consumer IoT, apps, software, components).
Size thresholds
None — applies regardless of size; no fines on micro/small firms for missing the 24h early-warning deadline.
Regulator
National market surveillance authorities and CSIRTs; ENISA runs the Single Reporting Platform
Breach or incident reporting
Actively exploited vulnerabilities and severe incidents: early warning within 24h, notification within 72h; final report 14 days after a fix (vulnerabilities) or 1 month after notification (incidents). Via ENISA Single Reporting Platform.
Local representative
Non-EU manufacturers may appoint an EU authorised representative; importers must ensure compliance.
Maximum penalty
Up to EUR 15m or 2.5% of worldwide turnover (essential requirements, Arts 13-14); EUR 10m or 2% (other duties); EUR 5m or 1% (misleading info).

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Reporting obligations went live 11 Sep 2026 with ENISA's Single Reporting Platform; delegated act on delayed CSIRT sharing adopted 11 Dec 2025.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].