// definition
CRA
Cyber Resilience Act
freshreviewed 0 days ago
Short definition
Regulation (EU) 2024/2847 on cybersecurity for products with digital elements. Since 11 September 2026, manufacturers within its scope must report actively exploited vulnerabilities and severe incidents affecting the security of their products. The main security requirements and the specific regime for open-source software stewards apply from 11 December 2027.
risk atlas
Knowledge map
Intuition
Regulatory reporting begins while the technical response is still being prepared.
Related analyses
Primary sources
- Regulation (EU) 2024/2847, Cyber Resilience ActArticles 14, 24 and 71: reporting, stewards and application dates.