Don’t do SECURITY. Do business SECURELY.

EU Cyber Resilience Act enters into force

The CRA introduces mandatory cybersecurity requirements for products with digital elements sold in the EU.

The Cyber Resilience Act (CRA) (Regulation (EU) 2024/2847) enters into force today.

What it requires

  • Security by design and by default for hardware and software products with digital elements.
  • Vulnerability handling, including a software bill of materials (SBOM) and coordinated vulnerability disclosure.
  • Security updates throughout a defined support period.
  • CE marking and conformity assessment, with stricter requirements for important and critical products.

Key dates: reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026, and the Act applies in full from 11 December 2027.

Manufacturers, importers and distributors selling into the EU, including UK businesses, should start planning now. Pure SaaS is generally out of scope unless it is the remote data processing element of a product.

Source: Regulation (EU) 2024/2847, Cyber Resilience Act (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights