Laden...
Laden...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
CRA
EU regulation setting mandatory cybersecurity requirements for products with digital elements placed on the EU market, across their lifecycle.
The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, introduces mandatory cybersecurity requirements for products with digital elements — hardware and software — placed on the EU market. It addresses the inconsistent security of connected products and the lack of timely updates, and requires security to be built in and maintained across a product's whole lifecycle.
Manufacturers must meet essential cybersecurity requirements, handle vulnerabilities, and affix the CE marking; some critical products require third-party conformity assessment. The CRA entered into force on 10 December 2024; its main obligations apply from 11 December 2027, with vulnerability and incident reporting obligations applying earlier, from 11 September 2026. It complements the NIS2 Directive.
Design, develop, and produce products with digital elements to meet the essential cybersecurity requirements.
Identify, document, and remediate vulnerabilities and provide security updates across the product lifecycle.
Carry out conformity assessment (third-party where required) and affix the CE marking before placing products on the market.
Report actively exploited vulnerabilities and severe incidents to authorities within defined timeframes.
Lees meer
Anove scant uw stack tegen CRA en meer dan 260 andere kaders in enkele minuten.