Skip to main content

Regulation (EU) 2024/2847 (Cyber Resilience Act)

Regulation (EU) 2024/2847, the Cyber Resilience Act, sets cybersecurity requirements for products with digital elements placed on the EU market. Its obligations are addressed to the manufacturer of the product, distinct from the deployer or operator that runs it. This page indexes the Annex I requirements relevant to development, and the Annex II documentation requirement.

Requirement groupThemes
Annex I Part I Essential cybersecurity requirementsT4 Secure coding and code quality
T6 Automated security verification
T7 Testing and acceptance
T14 Security updates and supported versions
Annex I Part II Vulnerability handling requirementsT7 Testing and acceptance
T11 Third-party components and supply chain
T12 Build and release integrity
T13 Vulnerability handling and disclosure
T14 Security updates and supported versions
Annex II Information and instructions to the userthe platform documentation as a whole

Annex I duties fall on the manufacturer placing the product on the market, not the deployer — the exception to this page's deployer framing. Reporting obligations apply from 11 September 2026, and the remaining obligations from 11 December 2027.