Skip to main content
    Pritect

    Regulation

    CRA
    From legal text to evidence

    The Cyber Resilience Act puts cybersecurity requirements on products with digital elements sold in the EU. It reaches hardware and software placed on the market, and it makes the manufacturer answerable for security across the whole supported lifetime of a product rather than only at the point of sale.

    Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

    CELEX
    32024R2847
    Official Journal
    OJ L, 2024/2847, 20.11.2024
    Articles
    71
    Jurisdiction
    🇪🇺 Europe
    Status
    Partly in force
    Read the text on EUR-Lex

    From the Official Journal to a tracked obligation

    Three stages, and the legal text is not rewritten at any of them.

    1. 01

      The article

      The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.

    2. 02

      The clause

      Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.

    3. 03

      Your obligation

      You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.

    Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.

    Key dates

    Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.

    1. 23 Oct 2024

      Adopted by the Parliament and the Council

    2. 20 Nov 2024

      Published in the Official Journal

    3. 10 Dec 2024

      Entered into force

      Art. 71(1)

    4. 11 Sep 2026

      Manufacturer reporting obligations apply from

      Art. 71(2)

    5. 11 Dec 2027

      General application begins

      Art. 71(2)

    The articles that create work

    The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.

    71
    Articles
    3
    Tracked

    The regulation runs to 71 articles, and its substantive security requirements sit in an annex rather than in the articles. Pritect decomposes 3 units clause by clause into obligations you can adopt, own and evidence: the essential cybersecurity requirements of Annex I, both the product properties in Part I and the vulnerability handling duties in Part II, together with the manufacturer reporting obligations. The rest are deliberately not decomposed. Articles 1 to 13 set the subject matter, scope, definitions, the treatment of important and critical products and the general obligations of manufacturers, and Articles 15 to 71 cover voluntary reporting, the other economic operators, conformity assessment and CE marking, notified bodies, market surveillance, penalties and the final provisions. The set grows as the catalogue is extended.

    Manufacturer reporting

    Chapter II, Art. 14

    • Art. 14Reporting obligations of manufacturers

    Essential cybersecurity requirements

    Annex I, Parts I and II

    • Annex I, Part ICybersecurity requirements relating to the properties of products with digital elements
    • Annex I, Part IIVulnerability handling requirements

    Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.

    Common questions

    The questions teams ask first, answered plainly.

    Who does the CRA apply to?
    It applies to manufacturers of products with digital elements made available on the EU market, and places narrower duties on importers and distributors. A product with digital elements is any software or hardware, and its remote data processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Open-source software supplied outside a commercial activity is treated separately.
    When does it start to apply?
    The regulation is already in force, but its obligations are staggered and the dates are in the timeline above. The manufacturer reporting obligations of Article 14 begin before the general date of application, so the notification duties bite first. Pritect tracks which date governs each product you have recorded.
    What has to be reported, and to whom?
    Article 14 requires a manufacturer to notify an actively exploited vulnerability, and a severe incident affecting the security of a product, to the CSIRT designated as coordinator and to ENISA through the single reporting platform. An early warning comes first and a fuller notification follows. The users of the product have to be informed as well.
    Do we need a software bill of materials?
    Yes. Annex I, Part II requires manufacturers to identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used and machine-readable format, covering at the very least the top-level dependencies of the product.
    How long do we have to provide security updates?
    For the support period, which the manufacturer determines to reflect how long the product is expected to be in use, and which the regulation expects to be at least five years unless the product is expected to be in use for a shorter time. Security updates must remain available throughout that period. Pritect records the support period per product so the obligation has an end date rather than an assumption.

    This page summarises publicly available legal text so you can orient yourself. It is not legal advice.

    See it against your own records

    Bring one processing activity, one supplier and one open request. We will show you where each of them lands.