The EU Cyber Resilience Act (CRA) is a comprehensive regulation that establishes cybersecurity requirements for products with digital elements sold in the European Union. Enacted in 2024, the CRA aims to ensure that digital products and services are secure by design and remain secure throughout their lifecycle.
Scope
Covers hardware and software products with digital elements, including IoT devices, software applications, and cloud services.
Requirements
Mandates security-by-design principles, vulnerability handling, and incident reporting throughout the product lifecycle.
Timeline
Compliance requirements will be phased in over several years, with full enforcement expected by 2027.