EU Cyber Resilience Act
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Conformity Assessment
| Code | Title |
|---|---|
| Annex VI | Simplified Technical Documentation for Microenterprises and SMEs |
| Art 27 | Presumption of Conformity with Harmonised Standards |
| Art 28 | EU Declaration of Conformity |
| Art 30 | CE Marking |
| Art 31 + Annex VII | Technical Documentation |
| Art 32 | Conformity Assessment Procedures |
| Art 32(2)-(3) | Conformity Assessment for Important and Critical PDE |
| Arts 35-45 | Notification of Conformity Assessment Bodies |
Essential Requirements
| Code | Title |
|---|---|
| Annex I Part I | Essential Cybersecurity Requirements (Properties) |
| Annex I Part II | Vulnerability Handling Requirements |
| Art 13(1) | Manufacturer Obligation: Design and Develop to Essential Requirements |
| Art 13(12) | Information and Instructions to Users (Annex II) |
| Art 13(2) | Cybersecurity Risk Assessment |
| Art 13(6) | Due Diligence on Third-Party Components |
| Art 13(8) | Support Period and Security Updates |
Market Surveillance
| Code | Title |
|---|---|
| Art 13(15)-(16) | Cooperation with Market Surveillance |
| Art 54 | Procedure for PDE Presenting a Significant Cybersecurity Risk |
| Art 64 | Penalties |
| Arts 46-49 | Market Surveillance: Powers and Cooperation |
Other
| Code | Title |
|---|---|
| Art 69 (Entry into force) | Application Dates and Transition |
| Recital 36 + NIS2 interplay | Relationship with NIS2 and Sector Legislation |
Reporting
| Code | Title |
|---|---|
| Art 14(1) | Early Warning: 24-hour Notification of Actively Exploited Vulnerability |
| Art 14(10)-(11) | Voluntary Notification and Protection of Reporting Persons |
| Art 14(2) | Vulnerability Notification: 72-hour Update |
| Art 14(3) | Final Report on Vulnerability |
| Art 14(4) | Severe Incident Reporting: 24/72-hour Notification |
| Art 14(8) | User Notification of Exploited Vulnerabilities and Severe Incidents |
| Art 52 | Union Single Reporting Platform |
Scope
| Code | Title |
|---|---|
| Art 13(19) | Authorised Representative for Non-EU Manufacturers |
| Art 19-21 | Importer Obligations |
| Art 2 | Scope: Products with Digital Elements (PDE) |
| Art 22-23 | Distributor Obligations |
| Art 24 | Cases Where Importers and Distributors Are Treated as Manufacturers |
| Art 24a (FOSS Stewards) | Open Source Software Stewards |
| Art 3 | Definitions: Manufacturer, Importer, Distributor, Substantial Modification |
| Art 6 | Important Products with Digital Elements (Class I and Class II) |
| Art 7 | Critical Products with Digital Elements |
Frequently Asked Questions
What is EU Cyber Resilience Act?
EU Cyber Resilience Act is a compliance framework from European Union with 6 domains and 37 controls. Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EU Cyber Resilience Act have?
EU Cyber Resilience Act has 37 controls organised across 6 domains. The largest domains are Scope (9 controls), Conformity Assessment (8 controls), Essential Requirements (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EU Cyber Resilience Act map to?
EU Cyber Resilience Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with EU Cyber Resilience Act compliance?
Start your EU Cyber Resilience Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Cyber Resilience Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required