EU Resilience & Security Acts

CRA

Cyber Resilience Act

Law / regulation EU European Union Since 2024

Cybersecurity requirements for products with digital elements placed on the EU market: secure-by-design obligations, vulnerability handling for the support period, and reporting of actively exploited vulnerabilities.

It puts an SBOM obligation into EU law for the first time, which is why SPDX and CycloneDX moved from good practice to procurement requirement.

At a glance

Category
EU Resilience & Security Acts
Jurisdiction
EU
Governance
European Union
Status
Regulation (EU) 2024/2847; reporting from September 2026, main obligations from December 2027
First released
2024

Links

Related regulation

Other entries under EU Resilience & Security Acts.

See CRA in context

Open the interactive Data Landscape for Regulation to compare CRA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.