PRACTICE NOTES
This Practice Note sets out the essentials of Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA): its background, timeline, aims, and how it aligns with other EU laws.
For details on the CRA’s scope or core duties for economic operators, see the following Practice Notes:
The EU Cyber Resilience Act—scope and classification of products
The EU Cyber Resilience Act—obligations, compliance and enforcement
Regulation (EU) 2024/2847, known as the CRA, is the first EU measure to set mandatory cybersecurity requirements for ‘products with digital elements’ across the EU. From December 2027, products that do not satisfy these requirements cannot be placed on the EU market. Accordingly, compliance will be crucial for market entry for both hardware and software. Manufacturers, importers and distributors will have extensive cybersecurity responsibilities and risk significant fines for
EU Law