Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit regulation
Edit regulation
Name
Short name (English)
Short name (German)
Full name (English)
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
Full name (German)
Verordnung (EU) 2024/2847 des Europäischen Parlaments und des Rates vom 23. Oktober 2024 über horizontale Cybersicherheitsanforderungen für Produkte mit digitalen Elementen und zur Änderung der Verordnungen (EU) Nr. 168/2013 und (EU) 2019/1020 und der Richtlinie (EU) 2020/1828 (Cyberresilienz-Verordnung)
Reference number
Source URL
Jurisdiction
Afghanistan
Albania
Algeria
Andorra
Angola
Antigua and Barbuda
Argentina
Armenia
Australia
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Brazil
Brunei
Bulgaria
Burkina Faso
Burundi
Cabo Verde
Cambodia
Cameroon
Canada
Central African Republic
Chad
Chile
China
Colombia
Comoros
Congo (Democratic Republic of the)
Congo (Republic of the)
Costa Rica
Côte d'Ivoire
Croatia
Cuba
Cyprus
Czechia
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
European Union
Fiji
Finland
France
Gabon
Gambia
Georgia
Germany
Ghana
Greece
Grenada
Guatemala
Guinea
Guinea-Bissau
Guyana
Haiti
Holy See
Honduras
Hungary
Iceland
India
Indonesia
Iran
Iraq
Ireland
Israel
Italy
Jamaica
Japan
Jordan
Kazakhstan
Kenya
Kiribati
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Lithuania
Luxembourg
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Mauritania
Mauritius
Mexico
Micronesia
Moldova
Monaco
Mongolia
Montenegro
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands
New Zealand
Nicaragua
Niger
Nigeria
North Korea
North Macedonia
Norway
Oman
Pakistan
Palau
Palestine State
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Poland
Portugal
Qatar
Romania
Russia
Rwanda
Saint Kitts and Nevis
Saint Lucia
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
South Korea
South Sudan
Spain
Sri Lanka
Sudan
Suriname
Sweden
Switzerland
Syria
Taiwan
Tajikistan
Tanzania
Thailand
Timor-Leste
Togo
Tonga
Trinidad and Tobago
Tunisia
Türkiye
Turkmenistan
Tuvalu
Uganda
Ukraine
United Arab Emirates
United Kingdom
United States of America
Uruguay
Uzbekistan
Vanuatu
Venezuela
Vietnam
Yemen
Zambia
Zimbabwe
Topic
AI
Anti-Corruption
Antitrust
Case Law
Compliance
Consumer Law
Corporate Law
Cybersecurity
Data Protection
Digital Platforms
Energy
Environment
Export Control
Financial Market
Health & Safety
Industry-Specific Regulation
IP & Licensing
Labor Law
Mobility & Transport
Money Laundering
Product Liability
Product Safety
Public Procurement
Real Estate & Construction
Regulatory Guidelines
Sanctions
Supply Chain
Sustainability
Tax
Telecommunications
Trade
Whistleblowing
Instrument type
Delegated Act
Directive
Implementing Act
Law
Proposal
Regulation
Standard / Guidance
Status
Idea
Consultation
Draft
Adopted
Published
In force
Repealed
Entered into force on
Repealed on
Repealed by
AFIR
Chemicals Climate Protection Ordinance
CSRD
CRA
EED
EnEfG
EntgTranspG
Energy Labelling Ordinance (Germany)
EPBD
GEG (Building Modernisation Act)
GEIG
LSV
NIS2
PPWR
UGB (sustainability reporting)
EU Energy Labelling Regulation
F-gas Regulation
Modified date
Listed at
Description (English)
The Cyber Resilience Act sets uniform Union-wide cybersecurity requirements for products with digital elements — hardware and software whose intended purpose or foreseeable use includes a data connection to a device or network. Manufacturers must design such products in line with the essential requirements of Annex I, assess cybersecurity risks, handle vulnerabilities throughout a defined support period of at least five years, carry out a conformity assessment, affix the CE marking and supply user information. Authorised representatives, importers and distributors carry graduated verification, documentation and cooperation duties. As a regulation it applies directly, without national transposition. It entered into force on 10 December 2024 and becomes applicable in stages: Chapter IV on the notification of conformity assessment bodies from 11 June 2026, the reporting obligations for actively exploited vulnerabilities and severe incidents from 11 September 2026, and all remaining provisions from 11 December 2027. There is no size threshold. Products already covered by sector-specific Union law — including vehicle components under Regulation (EU) 2019/2144, medical devices, in vitro diagnostics, civil aviation certified products and marine equipment — are excluded. Infringements can attract fines of up to EUR 15 million or 2.5 % of worldwide annual turnover.
Description (German)
Die Cyberresilienz-Verordnung legt unionsweit einheitliche Cybersicherheitsanforderungen für Produkte mit digitalen Elementen fest — für Hardware und Software, deren bestimmungsgemäßer Zweck oder vorhersehbare Verwendung eine Datenverbindung mit einem Gerät oder Netz einschließt. Sie verpflichtet Hersteller, solche Produkte nach den grundlegenden Anforderungen des Anhangs I zu konzipieren, Cybersicherheitsrisiken zu bewerten, Schwachstellen über einen festgelegten Unterstützungszeitraum von mindestens fünf Jahren zu behandeln, die Konformität zu bewerten, die CE-Kennzeichnung anzubringen und Nutzerinformationen beizufügen. Bevollmächtigte, Einführer und Händler treffen abgestufte Prüf-, Dokumentations- und Mitwirkungspflichten. Als Verordnung gilt sie unmittelbar, ohne nationales Umsetzungsgesetz. In Kraft getreten ist sie am 10. Dezember 2024, anwendbar wird sie gestaffelt: Kapitel IV über die Notifizierung von Konformitätsbewertungsstellen ab dem 11. Juni 2026, die Meldepflichten für aktiv ausgenutzte Schwachstellen und schwerwiegende Sicherheitsvorfälle ab dem 11. September 2026 und alle übrigen Vorschriften ab dem 11. Dezember 2027. Produkte, die vor dem 11. Dezember 2027 in den Verkehr gebracht wurden, unterliegen den Anforderungen nur bei einer wesentlichen Änderung nach diesem Tag; die Meldepflichten gelten für sie dagegen uneingeschränkt. Eine Größenschwelle kennt die Verordnung nicht. Ausgenommen sind Produkte, die bereits sektorspezifisch geregelt sind — darunter Kraftfahrzeugteile im Anwendungsbereich der Verordnung (EU) 2019/2144, Medizinprodukte, In-vitro-Diagnostika, zivilluftfahrtzertifizierte Produkte und Schiffsausrüstung. Verstöße können mit Geldbußen bis zu 15 Mio. EUR oder 2,5 Prozent des weltweiten Jahresumsatzes geahndet werden.
Cancel
Delete this regulation