Regulation
CRA
From legal text to evidence
The Cyber Resilience Act puts cybersecurity requirements on products with digital elements sold in the EU. It reaches hardware and software placed on the market, and it makes the manufacturer answerable for security across the whole supported lifetime of a product rather than only at the point of sale.
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
- CELEX
- 32024R2847
- Official Journal
- OJ L, 2024/2847, 20.11.2024
- Articles
- 71
- Jurisdiction
- 🇪🇺 Europe
- Status
- Partly in force
From the Official Journal to a tracked obligation
Three stages, and the legal text is not rewritten at any of them.
- 01
The article
The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.
- 02
The clause
Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.
- 03
Your obligation
You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.
Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.
Key dates
Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.
23 Oct 2024
Adopted by the Parliament and the Council
20 Nov 2024
Published in the Official Journal
10 Dec 2024
Entered into force
Art. 71(1)
11 Sep 2026
Manufacturer reporting obligations apply from
Art. 71(2)
11 Dec 2027
General application begins
Art. 71(2)
The articles that create work
The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.
The regulation runs to 71 articles, and its substantive security requirements sit in an annex rather than in the articles. Pritect decomposes 3 units clause by clause into obligations you can adopt, own and evidence: the essential cybersecurity requirements of Annex I, both the product properties in Part I and the vulnerability handling duties in Part II, together with the manufacturer reporting obligations. The rest are deliberately not decomposed. Articles 1 to 13 set the subject matter, scope, definitions, the treatment of important and critical products and the general obligations of manufacturers, and Articles 15 to 71 cover voluntary reporting, the other economic operators, conformity assessment and CE marking, notified bodies, market surveillance, penalties and the final provisions. The set grows as the catalogue is extended.
Manufacturer reporting
Chapter II, Art. 14
- Art. 14Reporting obligations of manufacturers
Essential cybersecurity requirements
Annex I, Parts I and II
- Annex I, Part ICybersecurity requirements relating to the properties of products with digital elements
- Annex I, Part IIVulnerability handling requirements
Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.
Where the work lives in Pritect
Each obligation lands in a suite that already does that job, on one shared record rather than a spreadsheet per article.
Common questions
The questions teams ask first, answered plainly.
- Who does the CRA apply to?
- It applies to manufacturers of products with digital elements made available on the EU market, and places narrower duties on importers and distributors. A product with digital elements is any software or hardware, and its remote data processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Open-source software supplied outside a commercial activity is treated separately.
- When does it start to apply?
- The regulation is already in force, but its obligations are staggered and the dates are in the timeline above. The manufacturer reporting obligations of Article 14 begin before the general date of application, so the notification duties bite first. Pritect tracks which date governs each product you have recorded.
- What has to be reported, and to whom?
- Article 14 requires a manufacturer to notify an actively exploited vulnerability, and a severe incident affecting the security of a product, to the CSIRT designated as coordinator and to ENISA through the single reporting platform. An early warning comes first and a fuller notification follows. The users of the product have to be informed as well.
- Do we need a software bill of materials?
- Yes. Annex I, Part II requires manufacturers to identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used and machine-readable format, covering at the very least the top-level dependencies of the product.
- How long do we have to provide security updates?
- For the support period, which the manufacturer determines to reflect how long the product is expected to be in use, and which the regulation expects to be at least five years unless the product is expected to be in use for a shorter time. Security updates must remain available throughout that period. Pritect records the support period per product so the obligation has an end date rather than an assumption.
This page summarises publicly available legal text so you can orient yourself. It is not legal advice.
See it against your own records
Bring one processing activity, one supplier and one open request. We will show you where each of them lands.