Source: OJ L 2024/2847, 20.11.2024

Current language: EN

CRA regulation

REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

of 23 October 2024

on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Economic and Social Committee(1)OJ C 100, 16.3.2023, p. 101.,

After consulting the Committee of the Regions,

Acting in accordance with the ordinary legislative procedure(2)Position of the European Parliament of 12 March 2024 (not yet published in the Official Journal) and decision of the Council of 10 October 2024.,

Whereas:

Open full page
Recital 1Addressing two major problems with products

Cybersecurity is one of the key challenges for the Union. The number and variety of connected devices will rise exponentially in the coming years. Cyberattacks represent a matter of public interest as they have a critical impact not only on the Union’s economy, but also on democracy as well as consumer safety and health. It is therefore necessary to strengthen the Union’s approach to cybersecurity, address cyber resilience at Union level and improve the functioning of the internal market by laying down a uniform legal framework for essential cybersecurity requirements for placing products with digital elements on the Union market. Two major problems adding costs for users and society should be addressed: a low level of cybersecurity of products with digital elements, reflected by widespread vulnerabilities and the insufficient and inconsistent provision of security updates to address them, and an insufficient understanding and access to information by users, preventing them from choosing products with adequate cybersecurity properties or using them in a secure manner.

Recital 2Purpose of this regulation

This Regulation aims to set the boundary conditions for the development of secure products with digital elements by ensuring that hardware and software products are placed on the market with fewer vulnerabilities and that manufacturers take security seriously throughout a product’s lifecycle. It also aims to create conditions allowing users to take cybersecurity into account when selecting and using products with digital elements, for example by improving transparency with regard to the support period for products with digital elements made available on the market.

Recital 3Existing horizontal rules do not directly cover products

Relevant Union law in force comprises several sets of horizontal rules that address certain aspects linked to cybersecurity from different angles, including measures to improve the security of the digital supply chain. However, existing Union law related to cybersecurity, including Regulation (EU) 2019/881 of the European Parliament and of the Council(3)Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15). and Directive (EU) 2022/2555 of the European Parliament and of the Council(4)Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80)., does not directly cover mandatory requirements for the security of products with digital elements.

HAVE ADOPTED THIS REGULATION:

  1. Chapter IGeneral provisions
  2. Chapter IIObligations of economic operators and provisions in relation to free and open-source software
  3. Chapter IIIConformity of the product with digital elements
  4. Chapter IVNotification of conformity assessment bodies
  5. Chapter VMarket surveillance and enforcement
  6. Chapter VIDelegated powers and committee procedure
  7. Chapter VIIConfidentiality and penalties
  8. Chapter VIIITransitional and final provisions
Annexes(1 – 8)
  1. Annex IESSENTIAL CYBERSECURITY REQUIREMENTS
  2. Annex IIINFORMATION AND INSTRUCTIONS TO THE USER
  3. Annex IIIIMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
  4. Annex IVCRITICAL PRODUCTS WITH DIGITAL ELEMENTS
  5. Annex VEU DECLARATION OF CONFORMITY
  6. Annex VISIMPLIFIED EU DECLARATION OF CONFORMITY
  7. Annex VIICONTENT OF THE TECHNICAL DOCUMENTATION
  8. Annex VIIICONFORMITY ASSESSMENT PROCEDURES

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Strasbourg, 23 October 2024.

For the European Parliament

The President

R. METSOLA

For the Council

The President

ZSIGMOND B. P.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod