CRA Reference Library

Official text from EU Regulation 2024/2847 (Cyber Resilience Act). Full transparency - verify our guidance against the actual law.

Cyber Resilience Act - Official Reference

Cyber Resilience Act (CRA)

REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

Official Journal Reference

Official Journal of the European Union L, 2024/2847, 20.11.2024

CELEX Number

32024R2847

Why We Provide This

Transparency is essential for compliance. Every requirement in this toolkit is based on the actual CRA regulation text. Use this reference library to verify our guidance and understand exactly what the law requires.

Regulation Structure

71
Total Articles
8
Annexes
21
Essential Requirements

Key Articles in This Library

Article 1 Subject matter

This Regulation lays down: (a) rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products; (b) essential cybersecurity requirements for the design, development and production of products with digital elements, and…

Article 2 Scope

1. This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network. 2. This Regulation does not apply to p…

Article 3 Definitions

For the purposes of this Regulation, the following definitions apply: (1) ‘product with digital elements’ means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; (2) ‘remote d…

Article 13 Obligations of manufacturers

1. When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I. 2. For the purpose of complying with paragraph 1,…

Article 14 Reporting obligations of manufacturers

1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.

Article 24 Obligations of open-source software stewards

1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.

Article 28 EU declaration of conformity

1. The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated. 2. The EU declaration of conformity shall have…

Article 32 Conformity assessment procedures for products with digital elements

1. The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.

Article 64 Penalties

1. Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.

Key Annexes in This Library

ANNEX I ESSENTIAL CYBERSECURITY REQUIREMENTS
ANNEX II INFORMATION AND INSTRUCTIONS TO THE USER
ANNEX III IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
ANNEX IV CRITICAL PRODUCTS WITH DIGITAL ELEMENTS
ANNEX V EU DECLARATION OF CONFORMITY
ANNEX VI SIMPLIFIED EU DECLARATION OF CONFORMITY
ANNEX VII CONTENT OF THE TECHNICAL DOCUMENTATION
ANNEX VIII CONFORMITY ASSESSMENT PROCEDURES