Regulation · CELEX 32024R2847
Regulation (EU) 2024/2847 — Cyber Resilience Act
View official text on EUR-Lex →2 obligations
CRA-013-1 · Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13(1)-(5) / Annex I Part I
Essential cybersecurity requirements — product design and properties
When placing a product with digital elements on the market, ensure it is designed, developed and produced to provide an appropriate level of cybersecurity based on risk. Based on the Article 13(2) cybersecurity risk assessment and where applicable: ship without known exploitable vulnerabilities; ship with a secure-by-default configuration (with reset capability); ensure vulnerabilities can be addressed via security updates (including automatic updates with opt-out, enabled by default where applicable, with update notifications and postponement options); protect against unauthorised access (authentication/identity/access-management controls, with reporting on possible unauthorised access); protect the confidentiality of stored/transmitted/processed data (e.g. encryption at rest/in transit); protect the integrity of data, commands, programs and configuration against unauthorised manipulation (with corruption reporting); minimise processed data to what's necessary (data minimisation); protect the availability of essential/basic functions including resilience against denial-of-service; minimise negative impact on other devices'/networks' availability; limit attack surfaces including external interfaces; reduce incident impact via exploitation-mitigation techniques; provide security-related information via internal activity recording/monitoring (with user opt-out); and let users securely and easily permanently remove all data/settings, with secure transfer where applicable.
Not yet applicable
CRA-013-1 · Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13(1)-(5) / Annex I Part I
Essential cybersecurity requirements — product design and properties
When placing a product with digital elements on the market, ensure it is designed, developed and produced to provide an appropriate level of cybersecurity based on risk. Based on the Article 13(2) cybersecurity risk assessment and where applicable: ship without known exploitable vulnerabilities; ship with a secure-by-default configuration (with reset capability); ensure vulnerabilities can be addressed via security updates (including automatic updates with opt-out, enabled by default where applicable, with update notifications and postponement options); protect against unauthorised access (authentication/identity/access-management controls, with reporting on possible unauthorised access); protect the confidentiality of stored/transmitted/processed data (e.g. encryption at rest/in transit); protect the integrity of data, commands, programs and configuration against unauthorised manipulation (with corruption reporting); minimise processed data to what's necessary (data minimisation); protect the availability of essential/basic functions including resilience against denial-of-service; minimise negative impact on other devices'/networks' availability; limit attack surfaces including external interfaces; reduce incident impact via exploitation-mitigation techniques; provide security-related information via internal activity recording/monitoring (with user opt-out); and let users securely and easily permanently remove all data/settings, with secure transfer where applicable.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 11 Dec 2027
- Source
- CRA.txt:2379-2444
How this is verified
The product's documented cybersecurity risk assessment (Article 13(2)) addresses each applicable Annex I Part I (2)(a)-(m) property, with implementation evidence for each addressed requirement and a documented justification for any requirement treated as inapplicable
Not yet applicable — this obligation's main application date (11 Dec 2027) is well over a year away as of this corpus's last-verified date; evidence collection shouldn't start until closer to that date. Which Annex I(2) items are 'applicable' to a given product is a risk-assessment-driven, product-specific determination pending compliance-expert review.
Last verified against primary law 23 Jul 2026
CRA-013-2 · Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13(6)/(8) / Annex I Part II
Vulnerability handling requirements for products with digital elements
Manufacturers shall: identify and document vulnerabilities and components, including a machine-readable software bill of materials covering at least top-level dependencies; address and remediate vulnerabilities without delay, providing security updates (separated from functionality updates where technically feasible); apply effective, regular security tests and reviews; once a fix is available, share and publicly disclose vulnerability information (description, affected-product identification, impact, severity, remediation guidance) — with a duly justified delay option where publication risk outweighs benefit until users can patch; put in place and enforce a coordinated vulnerability disclosure policy; facilitate information-sharing about potential vulnerabilities including in third-party components, with a reporting contact address; provide secure update-distribution mechanisms ensuring timely, and where applicable automatic, fixes; and disseminate available security updates without delay and — unless otherwise agreed for a tailor-made product — free of charge, with advisory guidance for users.
Not yet applicable
CRA-013-2 · Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13(6)/(8) / Annex I Part II
Vulnerability handling requirements for products with digital elements
Manufacturers shall: identify and document vulnerabilities and components, including a machine-readable software bill of materials covering at least top-level dependencies; address and remediate vulnerabilities without delay, providing security updates (separated from functionality updates where technically feasible); apply effective, regular security tests and reviews; once a fix is available, share and publicly disclose vulnerability information (description, affected-product identification, impact, severity, remediation guidance) — with a duly justified delay option where publication risk outweighs benefit until users can patch; put in place and enforce a coordinated vulnerability disclosure policy; facilitate information-sharing about potential vulnerabilities including in third-party components, with a reporting contact address; provide secure update-distribution mechanisms ensuring timely, and where applicable automatic, fixes; and disseminate available security updates without delay and — unless otherwise agreed for a tailor-made product — free of charge, with advisory guidance for users.
- Applies to
- All in-scope organisations
- Severity if failed
- Critical
- Applies from
- 11 Dec 2027
- Source
- CRA.txt:2445-2480
How this is verified
A machine-readable SBOM exists covering top-level dependencies, vulnerabilities are remediated without delay via separated security updates, regular security testing occurs, fixed vulnerabilities are disclosed with remediation guidance (or delay is justified), a coordinated vulnerability disclosure policy is enforced with a reporting contact, and security updates are distributed securely and, where applicable, free of charge without delay
Not yet applicable — this obligation's main application date (11 Dec 2027) is well over a year away as of this corpus's last-verified date, though the closely related Article 14 reporting clock applies far sooner (11 Sep 2026).
Last verified against primary law 23 Jul 2026