CRA regulation

Regulation (EU) 2024/2847 of the European Parliament and of the Council

of 23 October 2024

on horizontal cybersecurity requirements for products with digital elements

and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Economic and Social Committee(1)OJ C 100, 16.3.2023, p. 101.,

After consulting the Committee of the Regions,

Acting in accordance with the ordinary legislative procedure(2)Position of the European Parliament of 12 March 2024 (not yet published in the Official Journal) and decision of the Council of 10 October 2024.,

Whereas:

Open full page
Recital 1 Addressing two major problems with products

Cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; is one of the key challenges for the Union. The number and variety of connected devices will rise exponentially in the coming years. Cyberattacks represent a matter of public interest as they have a critical impact not only on the Union’s economy, but also on democracy as well as consumer means a natural person who acts for purposes which are outside that person’s trade, business, craft or profession; safety and health. It is therefore necessary to strengthen the Union’s approach to cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881;, address cyber resilience at Union level and improve the functioning of the internal market by laying down a uniform legal framework for essential cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements for placing products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; on the Union market. Two major problems adding costs for users and society should be addressed: a low level of cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, reflected by widespread vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; and the insufficient and inconsistent provision of security updates to address them, and an insufficient understanding and access to information by users, preventing them from choosing products with adequate cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; properties or using them in a secure manner.

Recital 2 Purpose of this regulation

This Regulation aims to set the boundary conditions for the development of secure products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; by ensuring that hardware means a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data; and software means the part of an electronic information system which consists of computer code; products are placed on the market with fewer vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; and that manufacturers means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; take security seriously throughout a product’s lifecycle. It also aims to create conditions allowing users to take cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; into account when selecting and using products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, for example by improving transparency with regard to the support period means the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I; for products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; made available on the market.

Recital 3 Existing horizontal rules do not directly cover products

Relevant Union law in force comprises several sets of horizontal rules that address certain aspects linked to cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; from different angles, including measures to improve the security of the digital supply chain. However, existing Union law related to cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881;, including Regulation (EU) 2019/881 of the European Parliament and of the Council(3)Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15). and Directive (EU) 2022/2555 of the European Parliament and of the Council(4)Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80)., does not directly cover mandatory requirements for the security of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;.

HAVE ADOPTED THIS REGULATION:

  1. Chapter IGeneral provisions
  2. Chapter IIObligations of economic operators and provisions in relation to free and open-source software
  3. Chapter IIIConformity of the product with digital elements
  4. Chapter IVNotification of conformity assessment bodies
  5. Chapter VMarket surveillance and enforcement
  6. Chapter VIDelegated powers and committee procedure
  7. Chapter VIIConfidentiality and penalties
  8. Chapter VIIITransitional and final provisions
Annexes(1 – 8)
  1. Annex IEssential cybersecurity requirements
  2. Annex IIInformation and instructions to the user
  3. Annex IIIImportant products with digital elements
  4. Annex IVCritical products with digital elements
  5. Annex VEU declaration of conformity
  6. Annex VISimplified EU declaration of conformity
  7. Annex VIIContent of the technical documentation
  8. Annex VIIIConformity assessment procedures

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Strasbourg, 23 October 2024.

For the European Parliament

The President

R. METSOLA

For the Council

The President

ZSIGMOND B. P.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod