EU Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is a landmark piece of legislation, ratified by the European Commission in November 2024 (Regulation (EU) 2024/2847). It will come fully into effect in December 2027. This regulation mandates that any company selling products or services with digital elements within the EU must comply with the legislation to obtain the CE mark.

The CRA Encompasses Two Sets of Requirements

Essential Cybersecurity Requirements (ECR)

These functional security requirements establish a security baseline for products and services within Europe.

Company Requirements

These requirements ensure that companies follow security practices and procedures, including:

  • A development process to eliminate known, exploitable security vulnerabilities upon product release
  • Ownership of vulnerabilities throughout the product's life cycle:
    • Transparency in notifying potential issues
    • Mitigation strategies