Introducing the Cyber Resilience Act: the EU's new plan to make sure all digital products on the EU market are safe from cyber threats. This important rulebook covers the security of products considering their lifecycle. It requires that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.
Overview
Cybersecurity is a collective effort. The European Commission is closely working with the industry, Member States, and the European Union Agency for Cybersecurity (ENISA) on the implementation of the Cyber Resilience Act (CRA).
How it works
Manufacturers
Learn more on new rules for suppliers of hardware products and software developers subject to the CRA
Small and medium-sized enterprises (SMEs)
Learn more about funding and tools available to support SMEs and start-ups
Open-source community
Learn more about the role of the open-source community for the implementation of the CRA
How we will achieve our objectives
Standardisation
Learn more about the standards development activities supporting the CRA
Reporting obligations
Understand the reporting obligations established by the CRA and the Single Reporting Platform
Conformity assessment
Find out more about the rules and actors involved in conformity assessment
Cyber Resilience Act: the essentials
Summary of the legal text - learn more about the main legal provisions of the CRA
Progress so far
Monitor, follow and stay updated on the progress of new initiatives, deliverables and legislation.
-
28 November 2025
Implementing act on technical descriptions related to important and critical products
-
11 December 2025Delegated act on CSIRTs withholding notifications to be disseminated through the Single Reporting Platform (adopted, publication pending objection period)
-
11 June 2026
Entry into application of the provisions on the notification of Conformity Assessment Bodies. Member States to designate notifying authorities
-
Q3 2026
First standardisation deliverables (horizontal and product-specific standards)
-
11 September 2026
Entry into application of reporting obligations
-
Q4 2026
Delegated Act specifying the presumption of conformity for the European Cybersecurity Certification scheme on Common Critera (EUCC) with the CRA
-
11 December 2026
Notification of sufficient Conformity Assessment Bodies across Member States
-
30 October 2027
More standardisation deliverables
-
11 December 2027
Full application of the Cyber Resilience Act
Read more information
Join the CRA community
If you want to stay informed about the CRA implementation, you can sign up for updates.