Regulation (EU) 2024/2847 (Cyber Resilience Act)
Regulation (EU) 2024/2847, the Cyber Resilience Act, sets cybersecurity requirements for products with digital elements placed on the EU market. Its obligations are addressed to the manufacturer of the product, distinct from the deployer or operator that runs it. This page indexes the Annex I requirements relevant to development, and the Annex II documentation requirement.
| Requirement group | Themes |
|---|---|
| Annex I Part I Essential cybersecurity requirements | T4 Secure coding and code quality T6 Automated security verification T7 Testing and acceptance T14 Security updates and supported versions |
| Annex I Part II Vulnerability handling requirements | T7 Testing and acceptance T11 Third-party components and supply chain T12 Build and release integrity T13 Vulnerability handling and disclosure T14 Security updates and supported versions |
| Annex II Information and instructions to the user | the platform documentation as a whole |
Annex I duties fall on the manufacturer placing the product on the market, not the deployer — the exception to this page's deployer framing. Reporting obligations apply from 11 September 2026, and the remaining obligations from 11 December 2027.