Cyber Resilience Act
AI-generated text. This page was generated using artificial intelligence.
Cyber Resilience Act[1]
European Union[1]
EU regulation[1]
Regulation (EU) 2024/2847[1]
Enacted; phased application. Manufacturer reporting applies from September 11, 2026.[2]
In force: December 10, 2024. Conformity-assessment bodies: June 11, 2026. Manufacturer reporting: September 11, 2026. General application: December 11, 2027.[1]
Overview
The Cyber Resilience Act establishes EU cybersecurity requirements for products with digital elements. Its manufacturer reporting obligations began on September 11, 2026, ahead of its general application on December 11, 2027.[1][2]
Scope and relevance to AI
Article 2 covers marketed products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network, subject to the regulation’s exclusions.[1] AI features do not by themselves settle coverage: CMS explains that businesses incorporating AI into products marketed under their own name can have manufacturer responsibilities. The reporting rules address qualifying security events, rather than every erroneous AI output.[3]
Covered products and exclusions
Coverage includes software and hardware, separately marketed components, and qualifying remote data processing solutions. A remote service is included when it is developed by or under the manufacturer's responsibility and its absence would prevent the product from performing one of its functions. Recitals 11–12 distinguish this from websites and cloud services outside that relationship; the CRA is not a blanket regulation of every cloud service.[4]
Article 2 excludes, among other categories, products covered by specified medical-device and motor-vehicle legislation, products certified under the EU civil-aviation regulation, covered marine equipment, identical replacement spare parts made to the same specifications, and products developed or modified exclusively for national security or defence. The exclusions depend on the statutory conditions, rather than simply on a product's industry label.[4]
Interaction with the EU AI Act
Article 12 expressly coordinates the CRA with the EU AI Act for products that are also high-risk AI systems. Its deemed-compliance route for AI Act cybersecurity requirements requires compliance with both parts of CRA Annex I and an EU declaration demonstrating the cybersecurity protection required by AI Act Article 15. It preserves the AI Act's separate accuracy and robustness requirements; CRA compliance alone does not establish compliance with the entire AI Act.[5]
The relevant AI Act conformity-assessment procedure generally applies to this overlap, but Article 12(3) retains stricter CRA cybersecurity assessment routes for specified important or critical products where the AI Act would otherwise use internal control. These coordination provisions form part of the CRA's general December 2027 application, rather than its earlier reporting phase.[5][1]
Product security and manufacturer duties
The following lifecycle requirements generally apply from December 11, 2027, subject to the transitional rules below. Article 13 requires a documented cybersecurity risk assessment that informs product planning, design, development, production, delivery and maintenance and is updated as appropriate during support.[6]
- Security by design and default: Annex I requires security appropriate to the risks. Its risk-based product requirements include no known exploitable vulnerabilities at market release, secure default configurations, access controls, protection of confidentiality and integrity, data minimisation, resilience of essential functions, and mechanisms for security updates.[6]
- Component and vulnerability management: Manufacturers must exercise due diligence over third-party components, including noncommercial open-source components. Annex I requires a machine-readable software bill of materials covering at least top-level dependencies, regular security testing, prompt remediation, a coordinated disclosure policy and a vulnerability-reporting contact.[6]
- Security updates: Updates addressing identified security issues must be distributed without delay and ordinarily free of charge; a limited exception permits a different agreement for a tailor-made product supplied to a business user. Security fixes must be separated from functionality updates where technically feasible.[6]
Support periods and user information
The support period must reflect how long the product is expected to be used, considering reasonable user expectations and the product's nature and purpose. The minimum is five years unless expected use is shorter, in which case support must cover that expected period. Five years is therefore a floor for many products, not a universal maximum. The support end date must be communicated clearly at purchase.[7]
Each security update issued during support must remain available for at least ten years after issue or the remaining support period, whichever is longer. This availability requirement is distinct from the period for developing new fixes.[7]
Importers and distributors
Importers must check matters including the manufacturer's conformity assessment, technical documentation and CE marking; distributors must verify required marking and accompanying information and act on suspected noncompliance. Rebranding or substantially modifying a product can bring manufacturer obligations into play under Articles 21–22.[8]
Conformity assessment and CE marking
Before market placement under the generally applicable regime, manufacturers must demonstrate conformity, prepare technical documentation, issue an EU declaration of conformity and affix the CE marking. Harmonised standards whose references appear in the Official Journal create a presumption of conformity only for the requirements they cover.[9]
The assessment route depends on product classification:
- Products outside the important and critical categories: internal control (self-assessment) is an available route under Article 32(1).[9]
- Important products, class I: third-party assessment is required where the relevant harmonised standards, common specifications or qualifying certification schemes are absent or not fully applied.[9]
- Important products, class II: assessment uses a notified body or an available and applicable qualifying European cybersecurity certification scheme.[9]
- Critical products: Article 32(4) provides for certification under Article 8(1), or class II procedures where those certification conditions are not met.[9]
Annex III open-source products have a specific exception: manufacturers can use Article 32(1) routes, including self-assessment, if they publish the technical documentation when placing the product on the market. This is not a general exemption from the security requirements.[9]
Free and open-source software
Software supplied outside commercial activity is outside the CRA's market-based product obligations. An open-source licence or zero price does not by itself establish that exclusion: the commercial context matters, and manufacturers incorporating such components retain their own due-diligence duties.[4][6]
Article 24 creates a separate regime for open-source software stewards: legal persons other than manufacturers that sustainably support specified open-source products intended for commercial activities and ensure their viability. Stewards must document a cybersecurity policy, cooperate with market-surveillance authorities and meet tailored reporting duties. Their Article 24(3) reporting starts on December 11, 2027; reporting of exploited vulnerabilities is tied to involvement in development, while severe-incident reporting concerns the development systems they provide.[10]
Reporting requirements
Manufacturers must report actively exploited vulnerabilities and severe incidents affecting covered products’ security. Early warnings are due without undue delay and within 24 hours of awareness; the next notification is due within 72 hours. The vulnerability final report is due no later than 14 days after a corrective or mitigating measure is available. For a severe incident, the final report is due within one month after the incident notification.[1][2]
An actively exploited vulnerability requires reliable evidence of exploitation by a malicious actor without the system owner's permission. A severe incident includes actual or potential impairment of protection for sensitive or important data or functions, or the introduction or execution of malicious code. Manufacturers must also inform impacted users and, where appropriate, all users, including necessary mitigation or corrective measures.[11]
Reports use ENISA’s Single Reporting Platform and the relevant national coordinating CSIRT. The Commission confirms that the platform is operational from September 11, 2026. ENISA explains that launch functionality covers mandatory reporting; voluntary reporting will follow in a later phase.[2][12]
Article 69(3) extends manufacturer reporting to covered products already placed on the market before general application. Open-source software stewards’ separate reporting obligations begin December 11, 2027; they should not be confused with manufacturers’ September 2026 start.[1][12]
Enforcement
The general enforcement regime assigns market surveillance to national authorities, with EU coordination. Authorities may require corrective measures and, where the statutory conditions are met, restrict market availability or require withdrawal or recall of products presenting significant cybersecurity risks.[13]
Article 64 sets maximum administrative fines, subject to proportionate national enforcement and the circumstances of the infringement:
- Up to €15 million or 2.5% of an undertaking's preceding-year worldwide turnover, whichever is higher, for Annex I or Article 13–14 breaches.[13]
- Up to €10 million or 2% for specified other obligations, including listed supply-chain and conformity requirements.[13]
- Up to €5 million or 1% for incorrect, incomplete or misleading information supplied in response to requests from notified bodies or market-surveillance authorities.[13]
These are the CRA's general penalty provisions, applicable from December 11, 2027; the earlier September 2026 reporting start does not bring Article 64 forward. The Commission's summary identifies protections for open-source software stewards and for micro- or small-enterprise manufacturers missing the 24-hour early-warning deadline. These should not be read as a general exemption for small businesses from CRA duties.[13][14]
Application timeline
- December 10, 2024: entry into force, distinct from phased application.[1]
- June 11, 2026: Chapter IV on notification of conformity-assessment bodies applies.[1]
- September 11, 2026: Article 14 manufacturer reporting applies.[1]
- December 11, 2027: general application, including the separate reporting obligations for open-source software stewards.[1][12]
Products placed on the market before December 11, 2027 generally become subject to the CRA only if substantially modified from that date. Article 69(3) separately applies manufacturer reporting to covered products already on the market. A legacy product is therefore not automatically outside the reporting regime.[1]
Related articles and coverage
References
- ↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 1.11 1.12 1.13 1.14 1.15 Regulation (EU) 2024/2847 (Cyber Resilience Act), Official Journal, November 20, 2024. Articles 1–3, 12–14, 24, 27–32, 52–64, 69 and 71; Annex I. Reviewed September 11, 2026.
- ↑ 2.0 2.1 2.2 2.3 2.4 European Commission, Cyber Resilience Act — Reporting obligations, updated September 11, 2026.
- ↑ CMS, AI in every product: the 24-hour reporting duty included, August 21, 2026.
- ↑ 4.0 4.1 4.2 Regulation (EU) 2024/2847, recitals 11–18 and Articles 2–3.
- ↑ 5.0 5.1 Regulation (EU) 2024/2847, Article 12.
- ↑ 6.0 6.1 6.2 6.3 6.4 Regulation (EU) 2024/2847, Article 13, Annex I and Article 71.
- ↑ 7.0 7.1 Regulation (EU) 2024/2847, Article 13(8), (9) and (19).
- ↑ Regulation (EU) 2024/2847, Articles 19–22.
- ↑ 9.0 9.1 9.2 9.3 9.4 9.5 Regulation (EU) 2024/2847, Articles 27–32 and 71.
- ↑ Regulation (EU) 2024/2847, Articles 3(14) and 24; European Commission, CRA reporting obligations, updated September 11, 2026.
- ↑ Regulation (EU) 2024/2847, Articles 3(42) and 14(5), (8).
- ↑ 12.0 12.1 12.2 ENISA, Single Reporting Platform FAQs, updated September 11, 2026.
- ↑ 13.0 13.1 13.2 13.3 13.4 Regulation (EU) 2024/2847, Articles 52–58, 64 and 71.
- ↑ European Commission services, Summary of the legislative text, Chapter VII.