Skip to main content
Shaping Europe’s digital future

Cyber Resilience Act - Implementation

Introducing the Cyber Resilience Act: the EU's new plan to make sure all digital products on the EU market are safe from cyber threats. This important rulebook covers the security of products considering their lifecycle. It requires that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.

Cyber Resilience Act banner

Overview

100%
0
Top

Cybersecurity is a collective effort. The European Commission is closely working with the industry, Member States, and the European Union Agency for Cybersecurity (ENISA) on the implementation of the Cyber Resilience Act (CRA).

100%
1
Left

How it works

""

Manufacturers

Learn more on new rules for suppliers of hardware products and software developers subject to the CRA

50%
0
Top
""

Member States

Learn more about market surveillance and the role of Member States

50%
0
Top
""

Small and medium-sized enterprises (SMEs)

Learn more about funding and tools available to support SMEs and start-ups

50%
0
Top
""

Open-source community

Learn more about the role of the open-source community for the implementation of the CRA

50%
0
Top

How we will achieve our objectives

""

Standardisation

Learn more about the standards development activities supporting the CRA

100%
1
Left
""

Reporting obligations

Understand the reporting obligations established by the CRA and the Single Reporting Platform

100%
1
Left
""

Conformity assessment

Find out more about the rules and actors involved in conformity assessment

100%
1
Left

Progress so far

Monitor, follow and stay updated on the progress of new initiatives, deliverables and legislation. 

 

  •  
    28 November 2025

    Implementing act on technical descriptions related to important and critical products 

  •  
    11 December 2025
    Delegated act on CSIRTs withholding notifications to be disseminated through the Single Reporting Platform (adopted, publication pending objection period)
  •  
    11 June 2026

    Entry into application of the provisions on the notification of Conformity Assessment Bodies. Member States to designate notifying authorities

  •  
    27 July 2026

    First set of Commission guidance on the Cyber Resilience Act implementation 
     

  •  
    Q3 2026

    First standardisation deliverables (horizontal and product-specific standards)
     

  •  
    11 September 2026

    Entry into application of reporting obligations

  •  
  • Q4 2026

    Delegated Act specifying the presumption of conformity for the European Cybersecurity Certification scheme on Common Critera (EUCC) with the CRA

  •  
    11 December 2026

    Notification of sufficient Conformity Assessment Bodies across Member States
     

  •  
    30 October 2027

    More standardisation deliverables
     

  •  
    11 December 2027

    Full application of the Cyber Resilience Act
     

100%
0
Left

Join the CRA community 

If you want to stay informed about the CRA implementation, you can sign up for updates.

100%
0
Left