CRA Reference Library
Official text from EU Regulation 2024/2847 (Cyber Resilience Act). Full transparency - verify our guidance against the actual law.
- Article 1
- Article 2
- Article 3
- Article 4
- Article 5
- Article 6
- Article 7
- Article 8
- Article 9
- Article 10
- Article 11
- Article 12
- Article 13
- Article 14
- Article 15
- Article 16
- Article 17
- Article 18
- Article 19
- Article 20
- Article 21
- Article 22
- Article 23
- Article 24
- Article 25
- Article 26
- Article 27
- Article 28
- Article 29
- Article 30
- Article 31
- Article 32
- Article 33
- Article 34
- Article 35
- Article 36
- Article 37
- Article 38
- Article 39
- Article 40
- Article 41
- Article 42
- Article 43
- Article 44
- Article 45
- Article 46
- Article 47
- Article 48
- Article 49
- Article 50
- Article 51
- Article 52
- Article 53
- Article 54
- Article 55
- Article 56
- Article 57
- Article 58
- Article 59
- Article 60
- Article 61
- Article 62
- Article 63
- Article 64
- Article 65
- Article 66
- Article 67
- Article 68
- Article 69
- Article 70
- Article 71
View the complete regulation on EUR-Lex:
Open EUR-Lex →Cyber Resilience Act - Official Reference
Cyber Resilience Act (CRA)
REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
Official Journal of the European Union L, 2024/2847, 20.11.2024
32024R2847
Why We Provide This
Transparency is essential for compliance. Every requirement in this toolkit is based on the actual CRA regulation text. Use this reference library to verify our guidance and understand exactly what the law requires.
Regulation Structure
Key Articles in This Library
This Regulation lays down: (a) rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products; (b) essential cybersecurity requirements for the design, development and production of products with digital elements, and…
1. This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network. 2. This Regulation does not apply to p…
For the purposes of this Regulation, the following definitions apply: (1) ‘product with digital elements’ means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; (2) ‘remote d…
1. When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I. 2. For the purpose of complying with paragraph 1,…
1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.
1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.
1. The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated. 2. The EU declaration of conformity shall have…
1. The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.
1. Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.
Key Annexes in This Library
Related EU Regulations
Some products may need to comply with multiple EU regulations. Use the quick-reference page to compare the most common overlaps.
NIS2, AI Act, GDPR, Machinery Regulation, and GPSR overlap guidance.
Cybersecurity requirements for machinery, robotics, and industrial IoT. Applies from 20 January 2027.