Skip to main content

📣 Submit your proposal: OpenSSF Community Day Korea

EU Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) law entered into force (EIF) on December 10, 2024, when it was published as Regulation (EU) 2024/2847 in the Official Journal of the European Union. Some CRA requirements become mandatory on 2026-09-11, and the CRA will fully apply three years later, on 2027-12-11. The CRA will obligate all products with digital elements, including their remote data processing, put on the European market to follow this regulation.

The CRA intends to address threats and vulnerabilities by establishing standardized frameworks for cybersecurity requirements as part of a wider set of European product legislation. It regulates so-called “products with digital elements”, or PDE for short, and its horizontal nature gives it a big scope, including a wide set of hardware and software, but excluding medical devices, cars and other product types with their own safety and security rules. The primary goal is to reduce the costs for data breaches and increase customer trust in products with a digital element.

EU CRAfish logo

CRA Resources

CRA News and Updates

CRA Blog

Dec 17, 2024 | Christian Horchert

CRA Expert Group Composition

Here's a little breakdown of the current CRA expert group composition by country and category. The biggest non-institutional groups are companies, and trade and business associations, most of which are listed as European. Not sure why Philips is listed as a trade organisation, I would put them into the same… Read more.
CRABlog2

Dec 11, 2024 | OpenSSF

Understanding the CRA: OpenSSF’s Role in the Cyber Resilience Act Implementation – Part 2

In Part 1, we provided a general overview of the CRA and highlighted OpenSSF’s current activities related to its implementation. In Part 2, we’ll take a closer look at the three-year implementation timeline and what lies ahead. Read more.
UnderstandingCRA1

Nov 25, 2024 | OpenSSF

Understanding the CRA: OpenSSF’s Role in the Cyber Resilience Act Implementation – Part 1

With publishing as Regulation (EU) 2024/2847 in the Official Journal of the European Union, the Cyber Resilience Act (CRA) enters into force (EIF) on December 10, 2024. The CRA will fully apply three years later, on December 11, 2027. The CRA will obligate all products with digital elements, including their… Read more.