Back to Frameworks

EU Cyber Resilience Act

European Union
vRegulation (EU) 2024/2847 of 23 October 2024 (OJ L 2024/2847, 20.11.2024)
11 domains
140 controls

Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) introduces horizontal cybersecurity requirements for Products with Digital Elements (PDEs) placed on the Union market and for their manufacturers, importers and distributors. PDEs cover hardware, software and remote data processing solutions that are connected directly or indirectly to a device or network and intended to be placed on the market separately or alongside a product. The Regulation imposes: (a) Article 13 manufacturer obligations including cybersecurity risk assessment, due diligence on third-party components, a documented support period and security updates throughout, compliance with the essential cybersecurity requirements (Annex I Part I) and the vulnerability handling requirements (Annex I Part II); (b) Article 14 reporting obligations including a 24-hour early-warning notification of actively exploited vulnerabilities to ENISA + CSIRT, 72-hour update, final report, and a parallel 24h/72h severe-incident notification regime, channelled through the single reporting platform under Article 16; (c) Articles 18-25 obligations for authorised representatives, importers, distributors, open-source software stewards and security attestations; (d) Articles 27-34 conformity assessment (Module A self-assessment for default products; Modules B+C / Module H notified-body involvement for important products under Article 7 and critical products under Article 8, with mandatory European cybersecurity certification under Regulation (EU) 2019/881 for critical products as the conformity-assessment route); (e) Articles 35-51 notification of conformity-assessment bodies; (f) Articles 52-60 market surveillance and the Union safeguard procedure; (g) Article 64 penalties (up to EUR 15 million or 2.5% of worldwide annual turnover for breach of essential requirements). Entered into force 10 December 2024; main obligations apply from 11 December 2027 with the Article 14 reporting regime applying from 11 September 2026.

Verified

EU Cyber Resilience Act is a compliance framework from European Union with 11 domains and 140 controls that map to 15 other frameworks. The largest domains are Manufacturer obligations (Article 13) – EU Cyber Resilience Act (28 controls), Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act (22 controls), Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act (14 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act

14 controls
Controls in the Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 14 controls
CodeTitle
eu-cyber-resilience-act::Annex I Part I(1)Appropriate level of cybersecurity based on the risks
eu-cyber-resilience-act::Annex I Part I(2)(a)No known exploitable vulnerabilities at release
eu-cyber-resilience-act::Annex I Part I(2)(b)Secure by default configuration with reset to original state
eu-cyber-resilience-act::Annex I Part I(2)(c)Vulnerabilities addressable through security updates, automatic by default
eu-cyber-resilience-act::Annex I Part I(2)(d)Protection from unauthorised access and reporting of it
eu-cyber-resilience-act::Annex I Part I(2)(e)Confidentiality of stored, transmitted and processed data
eu-cyber-resilience-act::Annex I Part I(2)(f)Integrity of data, commands, programs and configuration
eu-cyber-resilience-act::Annex I Part I(2)(g)Data minimisation
eu-cyber-resilience-act::Annex I Part I(2)(h)Availability of essential functions, including after an incident
eu-cyber-resilience-act::Annex I Part I(2)(i)Minimising negative impact on other devices and networks
eu-cyber-resilience-act::Annex I Part I(2)(j)Limiting attack surfaces, including external interfaces
eu-cyber-resilience-act::Annex I Part I(2)(k)Reducing incident impact through exploitation mitigation
eu-cyber-resilience-act::Annex I Part I(2)(l)Security logging and monitoring with user opt-out
eu-cyber-resilience-act::Annex I Part I(2)(m)Secure permanent removal of data and settings, and secure transfer

Annex I Part II vulnerability handling requirements – EU Cyber Resilience Act

8 controls
Controls in the Annex I Part II vulnerability handling requirements – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 8 controls
CodeTitle
eu-cyber-resilience-act::Annex I Part II(1)Identify and document vulnerabilities and components, including an SBOM
eu-cyber-resilience-act::Annex I Part II(2)Address and remediate vulnerabilities without delay, security updates separate from features
eu-cyber-resilience-act::Annex I Part II(3)Effective and regular security testing and review
eu-cyber-resilience-act::Annex I Part II(4)Public disclosure of fixed vulnerabilities
eu-cyber-resilience-act::Annex I Part II(5)Coordinated vulnerability disclosure policy
eu-cyber-resilience-act::Annex I Part II(6)Facilitating vulnerability information sharing, with a contact address
eu-cyber-resilience-act::Annex I Part II(7)Secure distribution of updates
eu-cyber-resilience-act::Annex I Part II(8)Dissemination of security updates without delay and free of charge, with advisories

Annex II information and instructions to the user – EU Cyber Resilience Act

14 controls
Controls in the Annex II information and instructions to the user – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 14 controls
CodeTitle
eu-cyber-resilience-act::Annex II 1User information: manufacturer identity and contact
eu-cyber-resilience-act::Annex II 2User information: vulnerability contact point and CVD policy location
eu-cyber-resilience-act::Annex II 3User information: unique product identification
eu-cyber-resilience-act::Annex II 4User information: intended purpose, security environment and security properties
eu-cyber-resilience-act::Annex II 5User information: circumstances that may lead to significant cybersecurity risks
eu-cyber-resilience-act::Annex II 6User information: address of the EU declaration of conformity
eu-cyber-resilience-act::Annex II 7User information: type of support and end date of the support period
eu-cyber-resilience-act::Annex II 8(a)Instructions: secure commissioning and use through the lifetime
eu-cyber-resilience-act::Annex II 8(b)Instructions: how changes to the product affect data security
eu-cyber-resilience-act::Annex II 8(c)Instructions: installing security-relevant updates
eu-cyber-resilience-act::Annex II 8(d)Instructions: secure decommissioning and removal of user data
eu-cyber-resilience-act::Annex II 8(e)Instructions: turning off automatic security updates
eu-cyber-resilience-act::Annex II 8(f)Instructions: information integrators need
eu-cyber-resilience-act::Annex II 9User information: where the SBOM can be accessed, if offered

Annex VII technical documentation contents – EU Cyber Resilience Act

10 controls
Controls in the Annex VII technical documentation contents – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 10 controls
CodeTitle
eu-cyber-resilience-act::Annex VII 1Technical file: general description of the product
eu-cyber-resilience-act::Annex VII 2(a)Technical file: design and development information and system architecture
eu-cyber-resilience-act::Annex VII 2(b)Technical file: vulnerability handling process specifications
eu-cyber-resilience-act::Annex VII 2(c)Technical file: production and monitoring processes and their validation
eu-cyber-resilience-act::Annex VII 3Technical file: the cybersecurity risk assessment
eu-cyber-resilience-act::Annex VII 4Technical file: information used to set the support period
eu-cyber-resilience-act::Annex VII 5Technical file: standards, specifications and certification applied, or alternative solutions
eu-cyber-resilience-act::Annex VII 6Technical file: test reports
eu-cyber-resilience-act::Annex VII 7Technical file: copy of the EU declaration
eu-cyber-resilience-act::Annex VII 8Technical file: SBOM for authorities on reasoned request

Annex VIII conformity assessment modules – EU Cyber Resilience Act

6 controls
Controls in the Annex VIII conformity assessment modules – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 6 controls
CodeTitle
eu-cyber-resilience-act::Annex VIII Part IModule A: internal control
eu-cyber-resilience-act::Annex VIII Part IIModule B: EU-type examination application and manufacturer duties
eu-cyber-resilience-act::Annex VIII Part IIIModule C: conformity to type based on internal production control
eu-cyber-resilience-act::Annex VIII Part IV 3Module H: approved quality system
eu-cyber-resilience-act::Annex VIII Part IV 4Module H: surveillance access for the notified body
eu-cyber-resilience-act::Annex VIII Part IV 5-6Module H: marking, declaration and record retention

Annexes V and VI EU declaration of conformity contents – EU Cyber Resilience Act

7 controls
Controls in the Annexes V and VI EU declaration of conformity contents – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 7 controls
CodeTitle
eu-cyber-resilience-act::Annex V 1-2Declaration content: product identification and manufacturer
eu-cyber-resilience-act::Annex V 3Declaration content: sole responsibility statement
eu-cyber-resilience-act::Annex V 4-5Declaration content: object of the declaration and conformity statement
eu-cyber-resilience-act::Annex V 6Declaration content: standards, specifications or certification relied on
eu-cyber-resilience-act::Annex V 7Declaration content: notified body, procedure and certificate
eu-cyber-resilience-act::Annex V 8Declaration content: additional information, place, date and signature
eu-cyber-resilience-act::Annex VISimplified EU declaration of conformity wording

Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act

22 controls
Controls in the Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 22 controls
CodeTitle
eu-cyber-resilience-act::Art. 18(1)-(2)Written mandate for an authorised representative, and what it cannot cover
eu-cyber-resilience-act::Art. 18(3)Tasks of the authorised representative
eu-cyber-resilience-act::Art. 19(1)Importers place only conforming products on the market
eu-cyber-resilience-act::Art. 19(2)Importer checks before placing on the market
eu-cyber-resilience-act::Art. 19(3)Importer withholds non-conforming products and reports significant risk
eu-cyber-resilience-act::Art. 19(4)Importer name and contact details on the product
eu-cyber-resilience-act::Art. 19(5)Importer corrective action and vulnerability information to the manufacturer
eu-cyber-resilience-act::Art. 19(6)Importer retention of the declaration and access to technical documentation
eu-cyber-resilience-act::Art. 19(7)Importer cooperation with authorities
eu-cyber-resilience-act::Art. 19(8)Importer notice when the manufacturer ceases operations
eu-cyber-resilience-act::Art. 20(1)Distributors act with due care
eu-cyber-resilience-act::Art. 20(2)Distributor verification before making available
eu-cyber-resilience-act::Art. 20(3)Distributor withholds non-conforming products and reports significant risk
eu-cyber-resilience-act::Art. 20(4)Distributor corrective action and vulnerability information
eu-cyber-resilience-act::Art. 20(5)Distributor cooperation with authorities
eu-cyber-resilience-act::Art. 20(6)Distributor notice when the manufacturer ceases operations
eu-cyber-resilience-act::Art. 21Importers and distributors who become manufacturers
eu-cyber-resilience-act::Art. 22Substantial modification by any other person
eu-cyber-resilience-act::Art. 23Identification of economic operators in the supply chain
eu-cyber-resilience-act::Art. 24(1)Open-source steward cybersecurity policy
eu-cyber-resilience-act::Art. 24(2)Steward cooperation and documentation to authorities
eu-cyber-resilience-act::Art. 24(3)Steward reporting duties

Declaration, CE marking and technical documentation (Articles 28 to 31, 53) – EU Cyber Resilience Act

11 controls
Controls in the Declaration, CE marking and technical documentation (Articles 28 to 31, 53) – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 11 controls
CodeTitle
eu-cyber-resilience-act::Art. 28(1)-(2)Drawing up and maintaining the EU declaration of conformity
eu-cyber-resilience-act::Art. 28(3)Single declaration where several Union acts apply
eu-cyber-resilience-act::Art. 30(1)-(2)Affixing the CE marking
eu-cyber-resilience-act::Art. 30(3)CE marking before placing on the market
eu-cyber-resilience-act::Art. 30(4)Notified body number after the CE marking under module H
eu-cyber-resilience-act::Art. 31(1)Content of the technical documentation
eu-cyber-resilience-act::Art. 31(2)Technical documentation kept current through the support period
eu-cyber-resilience-act::Art. 31(3)Single technical documentation where other Union acts apply
eu-cyber-resilience-act::Art. 31(4)Language of documentation for the notified body
eu-cyber-resilience-act::Art. 33(5)Simplified technical documentation for micro and small enterprises
eu-cyber-resilience-act::Art. 53Granting authorities access to data and internal documentation

Manufacturer obligations (Article 13) – EU Cyber Resilience Act

28 controls
Controls in the Manufacturer obligations (Article 13) – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 28 controls
CodeTitle
eu-cyber-resilience-act::Art. 13(1)Design, development and production to Annex I Part I
eu-cyber-resilience-act::Art. 13(10)Supporting only the latest substantially modified software version
eu-cyber-resilience-act::Art. 13(11)Public software archives and the risk of unsupported versions
eu-cyber-resilience-act::Art. 13(12) first subparagraphTechnical documentation drawn up before placing on the market
eu-cyber-resilience-act::Art. 13(12) second subparagraphCarrying out the conformity assessment procedure
eu-cyber-resilience-act::Art. 13(12) third subparagraphEU declaration of conformity and CE marking after demonstrated conformity
eu-cyber-resilience-act::Art. 13(13)Retention of technical documentation and declaration
eu-cyber-resilience-act::Art. 13(14)Continued conformity of series production
eu-cyber-resilience-act::Art. 13(15)Product identification by type, batch or serial number
eu-cyber-resilience-act::Art. 13(16)Manufacturer name and contact details
eu-cyber-resilience-act::Art. 13(17)Single point of contact for users
eu-cyber-resilience-act::Art. 13(18)Information and instructions to the user per Annex II
eu-cyber-resilience-act::Art. 13(19)End date of the support period stated at purchase, and end-of-support notice
eu-cyber-resilience-act::Art. 13(2)Cybersecurity risk assessment used across the product lifecycle
eu-cyber-resilience-act::Art. 13(20)Copy or simplified version of the EU declaration with the product
eu-cyber-resilience-act::Art. 13(21)Corrective action on non-conformity
eu-cyber-resilience-act::Art. 13(22)Cooperation with market surveillance authorities
eu-cyber-resilience-act::Art. 13(23)Informing authorities and users before ceasing operations
eu-cyber-resilience-act::Art. 13(3)Content, documentation and update of the risk assessment
eu-cyber-resilience-act::Art. 13(4)Risk assessment in the technical documentation and justification of non-applicability
eu-cyber-resilience-act::Art. 13(5)Due diligence on third-party components, including open source
eu-cyber-resilience-act::Art. 13(6)Reporting component vulnerabilities upstream and sharing fixes
eu-cyber-resilience-act::Art. 13(7)Systematic documentation of cybersecurity aspects
eu-cyber-resilience-act::Art. 13(8) first subparagraphEffective vulnerability handling for the support period
eu-cyber-resilience-act::Art. 13(8) second subparagraphDetermining the support period
eu-cyber-resilience-act::Art. 13(8) sixth subparagraphPolicies and procedures for reported vulnerabilities, including coordinated disclosure
eu-cyber-resilience-act::Art. 13(8) third subparagraphMinimum support period of five years
eu-cyber-resilience-act::Art. 13(9)Security updates kept available for ten years

Placing on the market, classification and conformity routes – EU Cyber Resilience Act

8 controls
Controls in the Placing on the market, classification and conformity routes – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 8 controls
CodeTitle
eu-cyber-resilience-act::Art. 32(1)Choosing a conformity assessment procedure (default products)
eu-cyber-resilience-act::Art. 32(2)Conformity assessment for important class I products
eu-cyber-resilience-act::Art. 32(3)Conformity assessment for important class II products
eu-cyber-resilience-act::Art. 32(4)Conformity assessment for critical products
eu-cyber-resilience-act::Art. 32(5)Open-source products in Annex III using any procedure
eu-cyber-resilience-act::Art. 6Condition for making a product available on the market
eu-cyber-resilience-act::Art. 7(1)Classifying a product as important (Annex III, class I or II)
eu-cyber-resilience-act::Art. 8(1)Critical products and European cybersecurity certification

Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act

12 controls
Controls in the Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act domain of EU Cyber Resilience Act — 12 controls
CodeTitle
eu-cyber-resilience-act::Art. 14(1)Notifying actively exploited vulnerabilities to the CSIRT and ENISA
eu-cyber-resilience-act::Art. 14(2)(a)Early warning within 24 hours of awareness of an exploited vulnerability
eu-cyber-resilience-act::Art. 14(2)(b)Vulnerability notification within 72 hours
eu-cyber-resilience-act::Art. 14(2)(c)Final report on the exploited vulnerability within 14 days of a fix
eu-cyber-resilience-act::Art. 14(3)Notifying severe incidents affecting product security
eu-cyber-resilience-act::Art. 14(4)(a)Early warning of a severe incident within 24 hours
eu-cyber-resilience-act::Art. 14(4)(b)Incident notification within 72 hours
eu-cyber-resilience-act::Art. 14(4)(c)Final incident report within one month of the notification
eu-cyber-resilience-act::Art. 14(6)Intermediate reports on request
eu-cyber-resilience-act::Art. 14(7)Submitting through the right Member State end-point
eu-cyber-resilience-act::Art. 14(8)Informing impacted users of exploited vulnerabilities and severe incidents
eu-cyber-resilience-act::Art. 15Voluntary reporting of vulnerabilities, threats, incidents and near misses

Your Compliance Coverage

If you comply with EU Cyber Resilience Act, you already cover:

Maps to 15 other frameworks

164 total controls
IEC 62443
24 source controls mapped|30 target controls covered
15%
ETSI EN 303 645
18 source controls mapped|54 target controls covered
11%
NIST SP 800-218
13 source controls mapped|11 target controls covered
8%
ISO/IEC 30111:2019
11 source controls mapped|9 target controls covered
7%
ISO 27002:2022
7 source controls mapped|4 target controls covered
4%
NIST Cybersecurity Framework 2.0
6 source controls mapped|4 target controls covered
4%
ISO/IEC 29147:2018
5 source controls mapped|4 target controls covered
3%
EU Product Liability Directive (Directive (EU) 2024/2853)
3 source controls mapped|3 target controls covered
2%
GDPR
3 source controls mapped|1 target controls covered
2%
EU Machinery Regulation (Regulation (EU) 2023/1230)
2 source controls mapped|1 target controls covered
1%
EU General Product Safety Regulation (GPSR, Regulation 2023/988)
2 source controls mapped|2 target controls covered
1%
DORA
2 source controls mapped|1 target controls covered
1%
EU Medical Devices Regulation (MDR 2017/745)
1 source controls mapped|1 target controls covered
1%
EU AI Act
1 source controls mapped|1 target controls covered
1%
EU Data Act
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what EU Cyber Resilience Act overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is EU Cyber Resilience Act and who does it apply to?

EU Cyber Resilience Act is a compliance framework from European Union with 11 domains and 140 controls. Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) introduces horizontal cybersecurity requirements for Products with Digital Elements (PDEs) placed on the Union market and for their manufacturers, importers and distributors. PDEs cover hardware, software and remote data processing solutions that are connected directly or indirectly to a device or network and intended to be placed on the market separately or alongside a product. The Regulation imposes: (a) Article 13 manufacturer obligations including cybersecurity risk assessment, due diligence on third-party components, a documented support period and security updates throughout, compliance with the essential cybersecurity requirements (Annex I Part I) and the vulnerability handling requirements (Annex I Part II); (b) Article 14 reporting obligations including a 24-hour early-warning notification of actively exploited vulnerabilities to ENISA + CSIRT, 72-hour update, final report, and a parallel 24h/72h severe-incident notification regime, channelled through the single reporting platform under Article 16; (c) Articles 18-25 obligations for authorised representatives, importers, distributors, open-source software stewards and security attestations; (d) Articles 27-34 conformity assessment (Module A self-assessment for default products; Modules B+C / Module H notified-body involvement for important products under Article 7 and critical products under Article 8, with mandatory European cybersecurity certification under Regulation (EU) 2019/881 for critical products as the conformity-assessment route); (e) Articles 35-51 notification of conformity-assessment bodies; (f) Articles 52-60 market surveillance and the Union safeguard procedure; (g) Article 64 penalties (up to EUR 15 million or 2.5% of worldwide annual turnover for breach of essential requirements). Entered into force 10 December 2024; main obligations apply from 11 December 2027 with the Article 14 reporting regime applying from 11 September 2026. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does EU Cyber Resilience Act actually require?

EU Cyber Resilience Act has 140 controls organised across 11 domains. The largest domains are Manufacturer obligations (Article 13) – EU Cyber Resilience Act (28 controls), Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act (22 controls), Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of EU Cyber Resilience Act do I already cover?

EU Cyber Resilience Act maps to 15 other compliance frameworks. The top mapping partners are IEC 62443 (15% coverage), ETSI EN 303 645 (11% coverage), NIST SP 800-218 (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement EU Cyber Resilience Act?

Start your EU Cyber Resilience Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Cyber Resilience Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 140 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required