1. Digital Policy
  2. Instruments
  3. CRA

Regulation · directly applicable · CELEX 32024R2847

CRA

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements

Known as the Cyber Resilience Act. Official text: Regulation (EU) 2024/2847 (Cyber Resilience Act)Tier 1 · primary law

Status
Partly applicable as of 26 September 2026
Competent authority
National competent authorities
Sanction ceiling
none recorded

In force since December 2024. Chapter IV (notification of conformity assessment bodies) has applied since 11 June 2026 and Article 14 reporting since 11 September 2026; the Regulation as a whole applies from 11 December 2027. The scalar alone is insufficient — read the milestones.

What it does

Horizontal cybersecurity requirements for products with digital elements.

How it allocates obligations

Product security across the lifecycle.

Regulated actor
Manufacturer of a product with digital elements
Protected party
End user
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
Market surveillance authorities; coordinated vulnerability reporting.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 23 October 2024AdoptionAdoption
  2. 20 November 2024Publication in the Official JournalPublication in the Official Journal
  3. 10 December 2024Entry into forceEntry into force
  4. 11 June 2026Application dateChapter IV (Articles 35 to 51), on the notification of conformity assessment bodies, applies.
  5. 11 September 2026Reporting deadlineReporting of actively exploited vulnerabilities and serious incidents begins.What it requires: Stand up a coordinated vulnerability disclosure and incident reporting process before this date.
  6. 11 December 2027Application dateFull application of the Cyber Resilience Act.What it requires: Complete conformity assessment for products with digital elements.

The whole compliance calendar, filterable →

Who it applies to

1 rule in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Potentially applicable

actor Manufacturer or Manufacturer of a product with digital elements or Connected-product provideractivity Placing connected products on the market or Placing products with digital elements on the market

The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements across their lifecycle. Reporting of actively exploited vulnerabilities and serious incidents begins on 11 September 2026; full application follows on 11 December 2027.

Last verified 27 September 2026

Run these against your situation →

Key provisions

3 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 13Obligations of manufacturersWhen placing a product with digital elements on the market, manufacturers must ensure it has been designed, developed and produced in accordance with the essential cybersecurity requirements in Part I of Annex I.Manufacturer · Manufacturer of a product with digital elementsApplies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date
Art. 14Reporting obligations of manufacturersManufacturers must notify any actively exploited vulnerability, and severe incidents, simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform. Applies from 11 September 2026 (Art. 71(2)).Manufacturer · Manufacturer of a product with digital elementsApplies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date
Art. 16Establishment of a single reporting platformENISA establishes the single reporting platform for the notifications under Articles 14 and 15, and manages and maintains its day-to-day operations.not recordedApplies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date

Enforcement

No enforcement recorded

This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.

The whole enforcement observatory →

Evidence and sources

Every statement this site makes about CRA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

1 Interpretation
Interpretationinterpretation

The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VII

Read it in the brief →Last verified 27 August 2026

The full bibliography and the evidence method →

How it interacts

1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.