Security
Regulation (EU) 2024/2847
Cyber Resilience Act
Cyber Resilience Act
Connected products — from baby monitors to industrial sensors — must ship with security updates and without known gaping holes.
Does this hit me?
Over time, cheap connected junk should get safer. You should be able to see how long a product will still get security fixes.
Check in the wizardPick a country in the header to see who enforces this at home. Union text is not the last word for directives.
Next switch-on: in 15 months · 11 Dec 2027 — Cyber Resilience Act — main product duties
How it rolls in
Dec 2024
Entered into force.
2026
Some reporting duties begin.
Dec 2027
Main product requirements apply.
Why it exists
Gadgets were sold with default passwords and no patch path. When they get hacked, the cost lands on households and networks, not the factory that shipped them.
What actually changes
- Products with digital elements need secure-by-default design.
- Manufacturers must provide security updates for a support period.
- Reporting of actively exploited vulnerabilities.
- CE marking will include these cyber requirements.
How it hits you
Over time, cheap connected junk should get safer. You should be able to see how long a product will still get security fixes.
For citizens
What this does to everyday life
Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.
Gadgets that still get patches
Connected products sold in the EU will have to ship without gaping holes and with a stated security-update period. Baby monitors and cheap cameras are the morality tale.
Rights you actually get
- A support period you can read before you buy, as the rules apply.
- Market surveillance can pull unsafe digital products like unsafe toys.
Costs and trade-offs
- The cheapest unpatchable gadgets should get harder to sell. That is a feature.
What you can do
- Prefer products that state how long security updates last. Change default passwords on everything you already own.
What you can ignore
- You are not the manufacturer of a device you only use at home.
If something goes wrong
Retailer and manufacturer first; national market surveillance / consumer protection.
More citizen notes across files: For people
Heard this? Not quite.
Claim: Open-source is illegal.
The Act distinguishes manufacturers who place products on the market from unpaid maintainers. Stewardship rules exist so open-source does not get crushed.
Latest official statements
All EU NewsNo tagged Commission, Parliament or Council statement in the current feeds.
Board one-pager
Board one-pager
Who this is for: EU critical entities and ICT providers. Regulation (EU) 2024/2847. in 15 months · 11 Dec 2027.
Scope
- You manufacture, import, or brand software or connected hardware sold in the EU (with listed exclusions such as some medical/aviation products that have their own regimes).
First 90 days
- This year: Classify products (default vs important/critical) and set a support-period policy.
- This year: Stand up vulnerability intake (security@) and coordinated disclosure.
Penalties: Up to €15 million or 2.5% of worldwide turnover for the gravest manufacturer failures.
For companies
How to stay on the right side of this file
Practical order of work, not a substitute for counsel. Manufacturers, importers, and distributors of products with digital elements placed on the EU market.
You are probably
In if you make, import or distribute a product with digital elements on the Union market.
Effort
A class-I device with a real update channel: a product programme. A class that needs a notified body: plan years, not sprints.
Budget
Security engineering and a support window on the P&L. Not a sticker.
Roles in this file
The same company can wear more than one hat. Classify before you buy a tool.
Manufacturer
You put your name or trademark on it, or substantially modify it.
Essential cybersecurity requirements, SBOM-grade transparency, vulnerability handling, CE.
Importer
You land a third-country product.
Check conformity, keep the file, do not box-shift a known gap.
Are you in scope?
Build toward- You manufacture, import, or brand software or connected hardware sold in the EU (with listed exclusions such as some medical/aviation products that have their own regimes).
Usually not, if
- Pure service providers with no product; unpaid maintainers who do not place a product on the market.
First moves
- This yearClassify products (default vs important/critical) and set a support-period policy.Product security
- This yearStand up vulnerability intake (security@) and coordinated disclosure.PSIRT
- If you only resell, demand the manufacturer's CE file. If you badge the product, you may become the manufacturer.
If you skip this
- No stated support period.
- A vulnerability inbox that goes to marketing.
- Importer of record with no file.
Done looks like
- A written support period.
- A vulnerability intake that a researcher can find.
- A technical file that lists known residual risks.
Keep this evidence
- SBOM or equivalent component list.
- Conformity assessment.
- Vulnerability handling policy.
- Update history.
Ask vendors
- How long will you ship security updates, and is that written in the contract?
Where programmes usually break
- Default passwords that cannot be changed. This is the textbook fail.
Call counsel when
- Annex class is unclear.
- Open-source components with no maintainer.
- A substantial modification that makes you the manufacturer.
Enforcement
Up to €15 million or 2.5% of worldwide turnover for the gravest manufacturer failures.
Market surveillance authorities; Commission for some implementing acts.
Need a stack, not one file? Open the company desk
Professional briefing
Legal architecture and duties
For counsel, compliance, and policy teams. Not advice. The Official Journal still wins.
- Instrument
- Regulation
- Legal basis
- Art 114 TFEU · Regulation (EU) 2024/2847
- Application
- Entered into force 10 December 2024. Main obligations apply 36 months later (11 December 2027). Reporting of actively exploited vulnerabilities and severe incidents applies earlier (21 months). Products with digital elements placed on the market after the application date must comply; there are limited transitional rules for products already certified under other schemes.
A product-safety regulation for hardware and software with a direct or indirect data connection. Manufacturers must build security by default, handle vulnerabilities for a stated support period, and CE-mark against essential cybersecurity requirements. Importers and distributors have gatekeeper duties. This is the ‘secure products’ twin of NIS2’s ‘secure operators’.
How the file is built
Products with digital elements
Any software or hardware product and remote data processing solutions, including standalone software. Annexes classify important (Class I/II) and critical products with extra conformity routes.
Essential requirements (Annex I)
No known exploitable vulnerabilities at placing; secure by default; minimise attack surface; encryption and access control; SBOM-like transparency; vulnerability handling for the support period.
Support period
Determined by the manufacturer as proportionate to expected use, with a floor (generally at least five years except for products expected to be in use for less). Must be stated.
Operators
| Role | Who | Core duties |
|---|---|---|
| Manufacturer | Places the product on the market under its name or trademark, including some software publishers and, in specified cases, substantial modifiers. | Design, assessment, technical file, CE, vulnerability handling, reporting to ENISA/CSIRT, support period. |
| Importer | Places a third-country product on the Union market. | Verify conformity, keep documentation, monitoring. |
| Distributor / open-source steward | Makes available; steward is a tailored role for certain free software. | Due care; steward obligations are lighter than manufacturer but real. |
Scope
Placing on the Union market. Extra-territorial for non-EU manufacturers selling into the EU (via importers).
In
- Products with digital elements (connected or with a logical connection).
- Remote data processing that supports the product.
- Important and critical product categories in the annexes (browsers, password managers, firewalls, hypervisors, smart meters, etc.).
Out, or narrower than assumed
- Products already regulated for cybersecurity under lex specialis (e.g. certain medical devices, aviation, cars — check the list).
- Pure SaaS that is not a product with digital elements — many cloud services are NIS2, not CRA; hybrid products can be both.
- Spare parts solely to repair products placed before application, under conditions.
Operative provisions
| Anchor | Rule | What it does in practice |
|---|---|---|
| Annex I | Essential cybersecurity requirements and vulnerability-handling requirements. | Default passwords and unpatchable IoT fail as a design, not as an incident. |
| Reporting | Notify actively exploited vulnerabilities and severe incidents on a tight clock (early warning 24h). | PSIRT must exist before 2026/27, not after the first CVE. |
| CE / conformity | Self-assessment for default products; third-party for many important Class II and critical products. | Notified-body capacity is a programme risk. |
Secondary law and guidance
- Harmonised standards (CEN-CENELEC) — the practical meaning of Annex I.
- Commission guidance on support periods and open-source stewards.
- Delegated acts adjusting product annexes.
National layer. Market surveillance is national (as for CE products). Penalties are set nationally within the Regulation’s frame. CSIRT/ENISA receive vulnerability reports.
How it sits with other files
Operators demand CRA-compliant products in procurement; manufacturers of important products may also be NIS2 digital providers.
An AI system that is also a product with digital elements carries both CE stories.
Security of processing (Art 32) and CRA essential requirements overlap on devices that process personal data.
Enforcement and private rights
Who
Market-surveillance authorities; notifying bodies; ENISA for aggregated reporting.
Tools
Withdrawal, recall, fines, publication. Customs can stop non-CE connected products.
Private rights
Product-liability claims for insecure products will be easier on the facts once CRA standards exist.
Risk register
| Risk | Signal | Control |
|---|---|---|
| Unpatchable catalogue | Consumer IoT with no update path and a 2-year SKU life | Kill or redesign before the application date; state a real support period. |
| SBOM theatre | Component list with no vulnerability-handling process | PSIRT, CVE intake, and update pipeline as a single system. |
| Importer of last resort | EU subsidiary putting its name on a white-label device | That subsidiary is the manufacturer — budget the technical file. |
Open issues
- Harmonised standards delivery before 2027.
- How far ‘substantial modification’ turns a downstream customiser into a manufacturer.
- Open-source steward vs manufacturer boundary.
Primary sources
Products with digital elements need security by design and a support window that is written down, not hoped.
You feel it now
In force; main obligations from 2027, reporting earlier for some.
Next
Support-period statements in the technical file become a sales term.
Where it lands
| Channel | People | Companies |
|---|---|---|
| The gadget | You should see how long updates last. A router that will never be patched is the target. | Manufacturers, importers, distributors. Annex class drives conformity. |
Who gains
Buyers of connected kit; downstream manufacturers who inherit a support date.
Who pays
Importers of unpatchable white-label devices.
Files this pulls with it
- GPSR — Safety and security of a connected consumer product can both bite.
- Product Liability Directive — Unpatched software after 2026 is easier to argue in court.
Who pays
Manufacturers and importers of products with digital elements.
Who benefits
Households and networks that currently inherit unpatched devices.
Read the official text