EU Resilience & Security Acts
CRA
Cyber Resilience Act
Law / regulation
EU
European Union
Since 2024
Cybersecurity requirements for products with digital elements placed on the EU market: secure-by-design obligations, vulnerability handling for the support period, and reporting of actively exploited vulnerabilities.
It puts an SBOM obligation into EU law for the first time, which is why SPDX and CycloneDX moved from good practice to procurement requirement.
At a glance
- Category
- EU Resilience & Security Acts
- Jurisdiction
- EU
- Governance
- European Union
- Status
- Regulation (EU) 2024/2847; reporting from September 2026, main obligations from December 2027
- First released
- 2024
Links
Related regulation
Other entries under EU Resilience & Security Acts.
See CRA in context
Open the interactive Data Landscape for Regulation to compare CRA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.