Independent information resource Product security · EU CRA
Start here / 01

What is the Cyber Resilience Act?

A product-focused introduction to the EU framework for the cybersecurity of products with digital elements.

IN BRIEF

The CRA is Regulation (EU) 2024/2847. It sets horizontal cybersecurity requirements for relevant hardware and software made available on the EU market and places duties on economic operators.

01 / 03

The question to ask first

Is a product with digital elements being made available on the Union market, and does its intended or reasonably foreseeable use include a direct or indirect connection to a device or network? Scope also depends on exclusions and the circumstances of supply.

  • Identify the product and its components.
  • Map the route to the EU market.
  • Check connections, commercial activity and any applicable exclusion.
02 / 03

Who should use this resource?

Manufacturers, software teams, importers, distributors and governance teams can use the guides to organise questions and evidence. The applicable duties differ by role.

03 / 03

What follows scope?

Manufacturers address cybersecurity risk, essential requirements, technical documentation, conformity and vulnerability handling. Importers and distributors have distinct verification and response duties.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.