Glossary · Industrial cybersecurity
Cyber Resilience Act (CRA)
Also known as: CRA, Regulation (EU) 2024/2847
German: Cyber Resilience Act (CRA)
The Cyber Resilience Act, Regulation (EU) 2024/2847, is EU legislation establishing cybersecurity requirements for products with digital elements across their lifecycle, from design through vulnerability handling and security updates during the support period. It entered into force on December 10, 2024.
- Cybersecurity
- EU
- Compliance
In one sentence
The Cyber Resilience Act (CRA) sets EU cybersecurity requirements for products with digital elements, from design to vulnerability handling and updates.
Example
A machine builder whose packaging machines have an Ethernet interface and remote service must plan a support period, publish a vulnerability disclosure policy and supply security updates for the machine’s control software.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
- CRA product categories: default, important and criticalWhich CRA products need a notified body, and how many products fall into the stricter categories?UKDeutsch
- The Radio Equipment Directive: when sector law absorbs aspect requirementsWhy does the cybersecurity part of the Radio Equipment Directive create parallel compliance paths?UKDeutsch
- Machinery Regulation and CRA: coupled through standards, not cross-referencesWhy can the Machinery Regulation and the Cyber Resilience Act not simply refer to each other?UKDeutsch
- The SBOM under BSI TR-03183-2: an inventory, not a vulnerability reportWhat does BSI TR-03183-2 require of a software bill of materials, and how does it relate to the CRA?UKDeutsch
- Receiving vulnerability reports under BSI TR-03183-3: report, notification, advisoryWhat does BSI TR-03183-3 expect a manufacturer to have in place before the first vulnerability report arrives?UKDeutsch
- Module H under the CRA: BSI TR-03183-H builds full quality assurance on ISO/IEC 27001How can a manufacturer demonstrate CRA conformity through its processes rather than product by product, and what does BSI TR-03183-H add?UKDeutsch
- BSI guidance on the CRA: context-dependent, not contradictoryWhen two pieces of BSI guidance on the Cyber Resilience Act seem irreconcilable, is the guidance contradictory?UKDeutsch
How it applies
- Dates: In force since December 10, 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from September 11, 2026; the main obligations from December 11, 2027.
- Requirements: Essential cybersecurity requirements for product design, a secure default configuration, vulnerability handling, and security updates for a defined support period. Conformity is shown with CE marking, as for machinery.
- Machinery: Machines with software and connectivity are typically products with digital elements. The CRA covers cybersecurity; the Machinery Regulation covers protection against corruption where it affects safety. Both must be addressed.
- Technical documentation: The CRA requires technical documentation and user information on security, including the support period and how to install updates. Security documentation becomes part of the product documentation.
CRA vs. IEC 62443
The CRA is law and sets outcomes. IEC 62443 is a standards series describing how to achieve industrial cybersecurity. Harmonized standards for the CRA are being developed; applying IEC 62443 helps, but does not by itself demonstrate conformity with the CRA.