Cyber Resilience Act

Regulation 2024/2847
European Union regulation
Text with EEA relevance
TitleRegulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
Made byEuropean Parliament, EU Council
Made underTreaty on the Functioning of the European Union, and in particular Article 114 thereof
Journal referenceOJ L, 2024/2847, 20.11.2024
History
Date made23 October 2024
Entry into force12 November 2024
Applies from11 December 2027
Current legislation

The Cyber Resilience Act (CRA) is an EU regulation for improving cybersecurity and cyber resilience in the EU through common cybersecurity standards for products with digital elements in the EU, such as required incident reports and automatic security updates. Products with digital elements mainly are hardware and software whose "intended and foreseeable use includes direct or indirect data connection to a device or network".

After its proposal on 15 September 2022 by the European Commission, multiple open source organizations criticized CRA for creating a "chilling effect on open source software development". The European Commission reached political agreement on the CRA on 1 December 2023, after a series of amendments. The revised bill introduced the "open source steward", a new economic concept, and received relief from many open source organizations due to its exception for open-source software, while Debian criticized its effect on small businesses and redistributors. The CRA agreement received formal approval by the European Parliament in March 2024. It was adopted by the Council on 10 October 2024.