Glossary · Cross-regulation
Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847 setting mandatory cybersecurity requirements for products with digital elements sold in the EU.
Explained in depth: NIS2 overview
The Cyber Resilience Act regulates the security of products rather than organisations: hardware and software with digital elements, from IoT devices and routers to operating systems and business applications, must be designed, developed, and maintained securely to be sold in the EU. Manufacturers must handle vulnerabilities throughout a defined support period, provide security updates, and CE-mark products against the requirements. The CRA entered into force in December 2024 and applies in stages: reporting obligations for actively exploited vulnerabilities and severe incidents (to CSIRTs and ENISA) from September 2026, and the full requirements from 11 December 2027. It complements NIS2: NIS2 secures the organisations running critical services; the CRA secures the products they buy and deploy.
Why it matters
For NIS2-covered entities, the CRA will gradually make supply chain security easier, since products come with security attestations and update commitments. For software and device makers, it is the next major compliance deadline after NIS2 and DORA, and it reaches many companies those laws do not.
