Back to Frameworks

EU Cyber Resilience Act

European Union
6 domains
37 controls

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Conformity Assessment

8 controls
Controls in the Conformity Assessment domain of EU Cyber Resilience Act8 controls
CodeTitle
Annex VISimplified Technical Documentation for Microenterprises and SMEs
Art 27Presumption of Conformity with Harmonised Standards
Art 28EU Declaration of Conformity
Art 30CE Marking
Art 31 + Annex VIITechnical Documentation
Art 32Conformity Assessment Procedures
Art 32(2)-(3)Conformity Assessment for Important and Critical PDE
Arts 35-45Notification of Conformity Assessment Bodies

Essential Requirements

7 controls
Controls in the Essential Requirements domain of EU Cyber Resilience Act7 controls
CodeTitle
Annex I Part IEssential Cybersecurity Requirements (Properties)
Annex I Part IIVulnerability Handling Requirements
Art 13(1)Manufacturer Obligation: Design and Develop to Essential Requirements
Art 13(12)Information and Instructions to Users (Annex II)
Art 13(2)Cybersecurity Risk Assessment
Art 13(6)Due Diligence on Third-Party Components
Art 13(8)Support Period and Security Updates

Market Surveillance

4 controls
Controls in the Market Surveillance domain of EU Cyber Resilience Act4 controls
CodeTitle
Art 13(15)-(16)Cooperation with Market Surveillance
Art 54Procedure for PDE Presenting a Significant Cybersecurity Risk
Art 64Penalties
Arts 46-49Market Surveillance: Powers and Cooperation

Other

2 controls
Controls in the Other domain of EU Cyber Resilience Act2 controls
CodeTitle
Art 69 (Entry into force)Application Dates and Transition
Recital 36 + NIS2 interplayRelationship with NIS2 and Sector Legislation

Reporting

7 controls
Controls in the Reporting domain of EU Cyber Resilience Act7 controls
CodeTitle
Art 14(1)Early Warning: 24-hour Notification of Actively Exploited Vulnerability
Art 14(10)-(11)Voluntary Notification and Protection of Reporting Persons
Art 14(2)Vulnerability Notification: 72-hour Update
Art 14(3)Final Report on Vulnerability
Art 14(4)Severe Incident Reporting: 24/72-hour Notification
Art 14(8)User Notification of Exploited Vulnerabilities and Severe Incidents
Art 52Union Single Reporting Platform

Scope

9 controls
Controls in the Scope domain of EU Cyber Resilience Act9 controls
CodeTitle
Art 13(19)Authorised Representative for Non-EU Manufacturers
Art 19-21Importer Obligations
Art 2Scope: Products with Digital Elements (PDE)
Art 22-23Distributor Obligations
Art 24Cases Where Importers and Distributors Are Treated as Manufacturers
Art 24a (FOSS Stewards)Open Source Software Stewards
Art 3Definitions: Manufacturer, Importer, Distributor, Substantial Modification
Art 6Important Products with Digital Elements (Class I and Class II)
Art 7Critical Products with Digital Elements

Frequently Asked Questions

What is EU Cyber Resilience Act?

EU Cyber Resilience Act is a compliance framework from European Union with 6 domains and 37 controls. Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does EU Cyber Resilience Act have?

EU Cyber Resilience Act has 37 controls organised across 6 domains. The largest domains are Scope (9 controls), Conformity Assessment (8 controls), Essential Requirements (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does EU Cyber Resilience Act map to?

EU Cyber Resilience Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with EU Cyber Resilience Act compliance?

Start your EU Cyber Resilience Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Cyber Resilience Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required