← All frameworks
Cyber

EU Cyber Resilience Act (CRA)

European Commission · Brussels, EU · effective In force 2024 (obligations phase to 2027)
481 days until Full CRA obligations apply (12/11/2027)

Binding cybersecurity requirements for products with digital elements — including AI-enabled software and connected devices. Secure-by-design, vulnerability handling and CE-mark conformity.

Who must comply
  • Manufacturers of products with digital elements sold in the EU
  • AI/software vendors, IoT & connected-device makers
Penalties

Up to €15M or 2.5% of global annual turnover.

Key obligations
Secure by design
Cybersecurity built in across the product lifecycle.
Vulnerability handling
Coordinated disclosure and free security updates.
SBOM & documentation
Software bill of materials and technical documentation.
Incident reporting
Report actively exploited vulnerabilities to ENISA within 24h.
Sectors in scope
Software / SaaSIoT & devicesIndustrial / OTAutomotiveMedical devices
Threats & cybersecurity it addresses
Supply-chain compromiseUnpatched vulnerabilitiesAI model / weight tamperingExploited connected devices
Crosswalks — comply once, cover many
NIS2DORAEU AI Act →ISO 42001
CSOAI Layer 0 mapping

Charter Art. 2, 21, 39 (Rainbow Stack)

Governed MCP tools — open source, pip/npx install