EUImpact
All laws

Security

Regulation (EU) 2024/2847

Cyber Resilience Act

Cyber Resilience Act

Coming into playin 15 months · 11 Dec 2027

Connected products — from baby monitors to industrial sensors — must ship with security updates and without known gaping holes.

Does this hit me?

Over time, cheap connected junk should get safer. You should be able to see how long a product will still get security fixes.

Check in the wizard

Pick a country in the header to see who enforces this at home. Union text is not the last word for directives.

Next switch-on: in 15 months · 11 Dec 2027Cyber Resilience Act — main product duties

How it rolls in

  1. Dec 2024

    Entered into force.

  2. 2026

    Some reporting duties begin.

  3. Dec 2027

    Main product requirements apply.

Why it exists

Gadgets were sold with default passwords and no patch path. When they get hacked, the cost lands on households and networks, not the factory that shipped them.

What actually changes

  • Products with digital elements need secure-by-default design.
  • Manufacturers must provide security updates for a support period.
  • Reporting of actively exploited vulnerabilities.
  • CE marking will include these cyber requirements.

How it hits you

Over time, cheap connected junk should get safer. You should be able to see how long a product will still get security fixes.

Everyday people4/5
Organisations4/5

For citizens

What this does to everyday life

Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.

Gadgets that still get patches

Connected products sold in the EU will have to ship without gaping holes and with a stated security-update period. Baby monitors and cheap cameras are the morality tale.

Rights you actually get

  • A support period you can read before you buy, as the rules apply.
  • Market surveillance can pull unsafe digital products like unsafe toys.

Costs and trade-offs

  • The cheapest unpatchable gadgets should get harder to sell. That is a feature.

What you can do

  • Prefer products that state how long security updates last. Change default passwords on everything you already own.

What you can ignore

  • You are not the manufacturer of a device you only use at home.

If something goes wrong

Retailer and manufacturer first; national market surveillance / consumer protection.

More citizen notes across files: For people

Heard this? Not quite.

Claim: Open-source is illegal.

The Act distinguishes manufacturers who place products on the market from unpaid maintainers. Stewardship rules exist so open-source does not get crushed.

Latest official statements

All EU News

No tagged Commission, Parliament or Council statement in the current feeds.

Read the official text