EU Cyber Resilience Act
Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) introduces horizontal cybersecurity requirements for Products with Digital Elements (PDEs) placed on the Union market and for their manufacturers, importers and distributors. PDEs cover hardware, software and remote data processing solutions that are connected directly or indirectly to a device or network and intended to be placed on the market separately or alongside a product. The Regulation imposes: (a) Article 13 manufacturer obligations including cybersecurity risk assessment, due diligence on third-party components, a documented support period and security updates throughout, compliance with the essential cybersecurity requirements (Annex I Part I) and the vulnerability handling requirements (Annex I Part II); (b) Article 14 reporting obligations including a 24-hour early-warning notification of actively exploited vulnerabilities to ENISA + CSIRT, 72-hour update, final report, and a parallel 24h/72h severe-incident notification regime, channelled through the single reporting platform under Article 16; (c) Articles 18-25 obligations for authorised representatives, importers, distributors, open-source software stewards and security attestations; (d) Articles 27-34 conformity assessment (Module A self-assessment for default products; Modules B+C / Module H notified-body involvement for important products under Article 7 and critical products under Article 8, with mandatory European cybersecurity certification under Regulation (EU) 2019/881 for critical products as the conformity-assessment route); (e) Articles 35-51 notification of conformity-assessment bodies; (f) Articles 52-60 market surveillance and the Union safeguard procedure; (g) Article 64 penalties (up to EUR 15 million or 2.5% of worldwide annual turnover for breach of essential requirements). Entered into force 10 December 2024; main obligations apply from 11 December 2027 with the Article 14 reporting regime applying from 11 September 2026.
EU Cyber Resilience Act is a compliance framework from European Union with 11 domains and 140 controls that map to 15 other frameworks. The largest domains are Manufacturer obligations (Article 13) – EU Cyber Resilience Act (28 controls), Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act (22 controls), Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act (14 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex I Part I(1) | Appropriate level of cybersecurity based on the risks |
| eu-cyber-resilience-act::Annex I Part I(2)(a) | No known exploitable vulnerabilities at release |
| eu-cyber-resilience-act::Annex I Part I(2)(b) | Secure by default configuration with reset to original state |
| eu-cyber-resilience-act::Annex I Part I(2)(c) | Vulnerabilities addressable through security updates, automatic by default |
| eu-cyber-resilience-act::Annex I Part I(2)(d) | Protection from unauthorised access and reporting of it |
| eu-cyber-resilience-act::Annex I Part I(2)(e) | Confidentiality of stored, transmitted and processed data |
| eu-cyber-resilience-act::Annex I Part I(2)(f) | Integrity of data, commands, programs and configuration |
| eu-cyber-resilience-act::Annex I Part I(2)(g) | Data minimisation |
| eu-cyber-resilience-act::Annex I Part I(2)(h) | Availability of essential functions, including after an incident |
| eu-cyber-resilience-act::Annex I Part I(2)(i) | Minimising negative impact on other devices and networks |
| eu-cyber-resilience-act::Annex I Part I(2)(j) | Limiting attack surfaces, including external interfaces |
| eu-cyber-resilience-act::Annex I Part I(2)(k) | Reducing incident impact through exploitation mitigation |
| eu-cyber-resilience-act::Annex I Part I(2)(l) | Security logging and monitoring with user opt-out |
| eu-cyber-resilience-act::Annex I Part I(2)(m) | Secure permanent removal of data and settings, and secure transfer |
Annex I Part II vulnerability handling requirements – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex I Part II(1) | Identify and document vulnerabilities and components, including an SBOM |
| eu-cyber-resilience-act::Annex I Part II(2) | Address and remediate vulnerabilities without delay, security updates separate from features |
| eu-cyber-resilience-act::Annex I Part II(3) | Effective and regular security testing and review |
| eu-cyber-resilience-act::Annex I Part II(4) | Public disclosure of fixed vulnerabilities |
| eu-cyber-resilience-act::Annex I Part II(5) | Coordinated vulnerability disclosure policy |
| eu-cyber-resilience-act::Annex I Part II(6) | Facilitating vulnerability information sharing, with a contact address |
| eu-cyber-resilience-act::Annex I Part II(7) | Secure distribution of updates |
| eu-cyber-resilience-act::Annex I Part II(8) | Dissemination of security updates without delay and free of charge, with advisories |
Annex II information and instructions to the user – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex II 1 | User information: manufacturer identity and contact |
| eu-cyber-resilience-act::Annex II 2 | User information: vulnerability contact point and CVD policy location |
| eu-cyber-resilience-act::Annex II 3 | User information: unique product identification |
| eu-cyber-resilience-act::Annex II 4 | User information: intended purpose, security environment and security properties |
| eu-cyber-resilience-act::Annex II 5 | User information: circumstances that may lead to significant cybersecurity risks |
| eu-cyber-resilience-act::Annex II 6 | User information: address of the EU declaration of conformity |
| eu-cyber-resilience-act::Annex II 7 | User information: type of support and end date of the support period |
| eu-cyber-resilience-act::Annex II 8(a) | Instructions: secure commissioning and use through the lifetime |
| eu-cyber-resilience-act::Annex II 8(b) | Instructions: how changes to the product affect data security |
| eu-cyber-resilience-act::Annex II 8(c) | Instructions: installing security-relevant updates |
| eu-cyber-resilience-act::Annex II 8(d) | Instructions: secure decommissioning and removal of user data |
| eu-cyber-resilience-act::Annex II 8(e) | Instructions: turning off automatic security updates |
| eu-cyber-resilience-act::Annex II 8(f) | Instructions: information integrators need |
| eu-cyber-resilience-act::Annex II 9 | User information: where the SBOM can be accessed, if offered |
Annex VII technical documentation contents – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex VII 1 | Technical file: general description of the product |
| eu-cyber-resilience-act::Annex VII 2(a) | Technical file: design and development information and system architecture |
| eu-cyber-resilience-act::Annex VII 2(b) | Technical file: vulnerability handling process specifications |
| eu-cyber-resilience-act::Annex VII 2(c) | Technical file: production and monitoring processes and their validation |
| eu-cyber-resilience-act::Annex VII 3 | Technical file: the cybersecurity risk assessment |
| eu-cyber-resilience-act::Annex VII 4 | Technical file: information used to set the support period |
| eu-cyber-resilience-act::Annex VII 5 | Technical file: standards, specifications and certification applied, or alternative solutions |
| eu-cyber-resilience-act::Annex VII 6 | Technical file: test reports |
| eu-cyber-resilience-act::Annex VII 7 | Technical file: copy of the EU declaration |
| eu-cyber-resilience-act::Annex VII 8 | Technical file: SBOM for authorities on reasoned request |
Annex VIII conformity assessment modules – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex VIII Part I | Module A: internal control |
| eu-cyber-resilience-act::Annex VIII Part II | Module B: EU-type examination application and manufacturer duties |
| eu-cyber-resilience-act::Annex VIII Part III | Module C: conformity to type based on internal production control |
| eu-cyber-resilience-act::Annex VIII Part IV 3 | Module H: approved quality system |
| eu-cyber-resilience-act::Annex VIII Part IV 4 | Module H: surveillance access for the notified body |
| eu-cyber-resilience-act::Annex VIII Part IV 5-6 | Module H: marking, declaration and record retention |
Annexes V and VI EU declaration of conformity contents – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Annex V 1-2 | Declaration content: product identification and manufacturer |
| eu-cyber-resilience-act::Annex V 3 | Declaration content: sole responsibility statement |
| eu-cyber-resilience-act::Annex V 4-5 | Declaration content: object of the declaration and conformity statement |
| eu-cyber-resilience-act::Annex V 6 | Declaration content: standards, specifications or certification relied on |
| eu-cyber-resilience-act::Annex V 7 | Declaration content: notified body, procedure and certificate |
| eu-cyber-resilience-act::Annex V 8 | Declaration content: additional information, place, date and signature |
| eu-cyber-resilience-act::Annex VI | Simplified EU declaration of conformity wording |
Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Art. 18(1)-(2) | Written mandate for an authorised representative, and what it cannot cover |
| eu-cyber-resilience-act::Art. 18(3) | Tasks of the authorised representative |
| eu-cyber-resilience-act::Art. 19(1) | Importers place only conforming products on the market |
| eu-cyber-resilience-act::Art. 19(2) | Importer checks before placing on the market |
| eu-cyber-resilience-act::Art. 19(3) | Importer withholds non-conforming products and reports significant risk |
| eu-cyber-resilience-act::Art. 19(4) | Importer name and contact details on the product |
| eu-cyber-resilience-act::Art. 19(5) | Importer corrective action and vulnerability information to the manufacturer |
| eu-cyber-resilience-act::Art. 19(6) | Importer retention of the declaration and access to technical documentation |
| eu-cyber-resilience-act::Art. 19(7) | Importer cooperation with authorities |
| eu-cyber-resilience-act::Art. 19(8) | Importer notice when the manufacturer ceases operations |
| eu-cyber-resilience-act::Art. 20(1) | Distributors act with due care |
| eu-cyber-resilience-act::Art. 20(2) | Distributor verification before making available |
| eu-cyber-resilience-act::Art. 20(3) | Distributor withholds non-conforming products and reports significant risk |
| eu-cyber-resilience-act::Art. 20(4) | Distributor corrective action and vulnerability information |
| eu-cyber-resilience-act::Art. 20(5) | Distributor cooperation with authorities |
| eu-cyber-resilience-act::Art. 20(6) | Distributor notice when the manufacturer ceases operations |
| eu-cyber-resilience-act::Art. 21 | Importers and distributors who become manufacturers |
| eu-cyber-resilience-act::Art. 22 | Substantial modification by any other person |
| eu-cyber-resilience-act::Art. 23 | Identification of economic operators in the supply chain |
| eu-cyber-resilience-act::Art. 24(1) | Open-source steward cybersecurity policy |
| eu-cyber-resilience-act::Art. 24(2) | Steward cooperation and documentation to authorities |
| eu-cyber-resilience-act::Art. 24(3) | Steward reporting duties |
Declaration, CE marking and technical documentation (Articles 28 to 31, 53) – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Art. 28(1)-(2) | Drawing up and maintaining the EU declaration of conformity |
| eu-cyber-resilience-act::Art. 28(3) | Single declaration where several Union acts apply |
| eu-cyber-resilience-act::Art. 30(1)-(2) | Affixing the CE marking |
| eu-cyber-resilience-act::Art. 30(3) | CE marking before placing on the market |
| eu-cyber-resilience-act::Art. 30(4) | Notified body number after the CE marking under module H |
| eu-cyber-resilience-act::Art. 31(1) | Content of the technical documentation |
| eu-cyber-resilience-act::Art. 31(2) | Technical documentation kept current through the support period |
| eu-cyber-resilience-act::Art. 31(3) | Single technical documentation where other Union acts apply |
| eu-cyber-resilience-act::Art. 31(4) | Language of documentation for the notified body |
| eu-cyber-resilience-act::Art. 33(5) | Simplified technical documentation for micro and small enterprises |
| eu-cyber-resilience-act::Art. 53 | Granting authorities access to data and internal documentation |
Manufacturer obligations (Article 13) – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Art. 13(1) | Design, development and production to Annex I Part I |
| eu-cyber-resilience-act::Art. 13(10) | Supporting only the latest substantially modified software version |
| eu-cyber-resilience-act::Art. 13(11) | Public software archives and the risk of unsupported versions |
| eu-cyber-resilience-act::Art. 13(12) first subparagraph | Technical documentation drawn up before placing on the market |
| eu-cyber-resilience-act::Art. 13(12) second subparagraph | Carrying out the conformity assessment procedure |
| eu-cyber-resilience-act::Art. 13(12) third subparagraph | EU declaration of conformity and CE marking after demonstrated conformity |
| eu-cyber-resilience-act::Art. 13(13) | Retention of technical documentation and declaration |
| eu-cyber-resilience-act::Art. 13(14) | Continued conformity of series production |
| eu-cyber-resilience-act::Art. 13(15) | Product identification by type, batch or serial number |
| eu-cyber-resilience-act::Art. 13(16) | Manufacturer name and contact details |
| eu-cyber-resilience-act::Art. 13(17) | Single point of contact for users |
| eu-cyber-resilience-act::Art. 13(18) | Information and instructions to the user per Annex II |
| eu-cyber-resilience-act::Art. 13(19) | End date of the support period stated at purchase, and end-of-support notice |
| eu-cyber-resilience-act::Art. 13(2) | Cybersecurity risk assessment used across the product lifecycle |
| eu-cyber-resilience-act::Art. 13(20) | Copy or simplified version of the EU declaration with the product |
| eu-cyber-resilience-act::Art. 13(21) | Corrective action on non-conformity |
| eu-cyber-resilience-act::Art. 13(22) | Cooperation with market surveillance authorities |
| eu-cyber-resilience-act::Art. 13(23) | Informing authorities and users before ceasing operations |
| eu-cyber-resilience-act::Art. 13(3) | Content, documentation and update of the risk assessment |
| eu-cyber-resilience-act::Art. 13(4) | Risk assessment in the technical documentation and justification of non-applicability |
| eu-cyber-resilience-act::Art. 13(5) | Due diligence on third-party components, including open source |
| eu-cyber-resilience-act::Art. 13(6) | Reporting component vulnerabilities upstream and sharing fixes |
| eu-cyber-resilience-act::Art. 13(7) | Systematic documentation of cybersecurity aspects |
| eu-cyber-resilience-act::Art. 13(8) first subparagraph | Effective vulnerability handling for the support period |
| eu-cyber-resilience-act::Art. 13(8) second subparagraph | Determining the support period |
| eu-cyber-resilience-act::Art. 13(8) sixth subparagraph | Policies and procedures for reported vulnerabilities, including coordinated disclosure |
| eu-cyber-resilience-act::Art. 13(8) third subparagraph | Minimum support period of five years |
| eu-cyber-resilience-act::Art. 13(9) | Security updates kept available for ten years |
Placing on the market, classification and conformity routes – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Art. 32(1) | Choosing a conformity assessment procedure (default products) |
| eu-cyber-resilience-act::Art. 32(2) | Conformity assessment for important class I products |
| eu-cyber-resilience-act::Art. 32(3) | Conformity assessment for important class II products |
| eu-cyber-resilience-act::Art. 32(4) | Conformity assessment for critical products |
| eu-cyber-resilience-act::Art. 32(5) | Open-source products in Annex III using any procedure |
| eu-cyber-resilience-act::Art. 6 | Condition for making a product available on the market |
| eu-cyber-resilience-act::Art. 7(1) | Classifying a product as important (Annex III, class I or II) |
| eu-cyber-resilience-act::Art. 8(1) | Critical products and European cybersecurity certification |
Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act
| Code | Title |
|---|---|
| eu-cyber-resilience-act::Art. 14(1) | Notifying actively exploited vulnerabilities to the CSIRT and ENISA |
| eu-cyber-resilience-act::Art. 14(2)(a) | Early warning within 24 hours of awareness of an exploited vulnerability |
| eu-cyber-resilience-act::Art. 14(2)(b) | Vulnerability notification within 72 hours |
| eu-cyber-resilience-act::Art. 14(2)(c) | Final report on the exploited vulnerability within 14 days of a fix |
| eu-cyber-resilience-act::Art. 14(3) | Notifying severe incidents affecting product security |
| eu-cyber-resilience-act::Art. 14(4)(a) | Early warning of a severe incident within 24 hours |
| eu-cyber-resilience-act::Art. 14(4)(b) | Incident notification within 72 hours |
| eu-cyber-resilience-act::Art. 14(4)(c) | Final incident report within one month of the notification |
| eu-cyber-resilience-act::Art. 14(6) | Intermediate reports on request |
| eu-cyber-resilience-act::Art. 14(7) | Submitting through the right Member State end-point |
| eu-cyber-resilience-act::Art. 14(8) | Informing impacted users of exploited vulnerabilities and severe incidents |
| eu-cyber-resilience-act::Art. 15 | Voluntary reporting of vulnerabilities, threats, incidents and near misses |
Your Compliance Coverage
If you comply with EU Cyber Resilience Act, you already cover:
IEC 62443
15%
24 controls mapped
Compare →ETSI EN 303 645
11%
18 controls mapped
Compare →NIST SP 800-218
8%
13 controls mapped
Compare →+ 12 more: ISO/IEC 30111:2019 (7%), ISO 27002:2022 (4%)
See all 15 mapped frameworks ↓Maps to 15 other frameworks
Coverage is not the same as your position
This page shows what EU Cyber Resilience Act overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is EU Cyber Resilience Act and who does it apply to?
EU Cyber Resilience Act is a compliance framework from European Union with 11 domains and 140 controls. Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) introduces horizontal cybersecurity requirements for Products with Digital Elements (PDEs) placed on the Union market and for their manufacturers, importers and distributors. PDEs cover hardware, software and remote data processing solutions that are connected directly or indirectly to a device or network and intended to be placed on the market separately or alongside a product. The Regulation imposes: (a) Article 13 manufacturer obligations including cybersecurity risk assessment, due diligence on third-party components, a documented support period and security updates throughout, compliance with the essential cybersecurity requirements (Annex I Part I) and the vulnerability handling requirements (Annex I Part II); (b) Article 14 reporting obligations including a 24-hour early-warning notification of actively exploited vulnerabilities to ENISA + CSIRT, 72-hour update, final report, and a parallel 24h/72h severe-incident notification regime, channelled through the single reporting platform under Article 16; (c) Articles 18-25 obligations for authorised representatives, importers, distributors, open-source software stewards and security attestations; (d) Articles 27-34 conformity assessment (Module A self-assessment for default products; Modules B+C / Module H notified-body involvement for important products under Article 7 and critical products under Article 8, with mandatory European cybersecurity certification under Regulation (EU) 2019/881 for critical products as the conformity-assessment route); (e) Articles 35-51 notification of conformity-assessment bodies; (f) Articles 52-60 market surveillance and the Union safeguard procedure; (g) Article 64 penalties (up to EUR 15 million or 2.5% of worldwide annual turnover for breach of essential requirements). Entered into force 10 December 2024; main obligations apply from 11 December 2027 with the Article 14 reporting regime applying from 11 September 2026. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EU Cyber Resilience Act actually require?
EU Cyber Resilience Act has 140 controls organised across 11 domains. The largest domains are Manufacturer obligations (Article 13) – EU Cyber Resilience Act (28 controls), Authorised representatives, importers, distributors and open-source stewards (Articles 18 to 24) – EU Cyber Resilience Act (22 controls), Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EU Cyber Resilience Act do I already cover?
EU Cyber Resilience Act maps to 15 other compliance frameworks. The top mapping partners are IEC 62443 (15% coverage), ETSI EN 303 645 (11% coverage), NIST SP 800-218 (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EU Cyber Resilience Act?
Start your EU Cyber Resilience Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Cyber Resilience Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 140 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required