← All frameworks
Cyber
EU Cyber Resilience Act (CRA)
European Commission · Brussels, EU · effective In force 2024 (obligations phase to 2027)
481 days until Full CRA obligations apply (12/11/2027)
Binding cybersecurity requirements for products with digital elements — including AI-enabled software and connected devices. Secure-by-design, vulnerability handling and CE-mark conformity.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Manufacturers of products with digital elements sold in the EU
- ▸AI/software vendors, IoT & connected-device makers
Penalties
Up to €15M or 2.5% of global annual turnover.
Key obligations
Secure by design
Cybersecurity built in across the product lifecycle.
Vulnerability handling
Coordinated disclosure and free security updates.
SBOM & documentation
Software bill of materials and technical documentation.
Incident reporting
Report actively exploited vulnerabilities to ENISA within 24h.
Sectors in scope
Software / SaaSIoT & devicesIndustrial / OTAutomotiveMedical devices
Threats & cybersecurity it addresses
Supply-chain compromiseUnpatched vulnerabilitiesAI model / weight tamperingExploited connected devices
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 2, 21, 39 (Rainbow Stack)
Governed MCP tools — open source, pip/npx install