Skip to content
European UnionEuropean UnionLawLawRegulation (EU) 2024/2847

Cyber Resilience Act

Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU, including vulnerability handling and incident reporting duties for manufacturers.

Where it stands

In forceIntroducedCommitteeFloorLawIn force

Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents applySep 112 weeks ago

Body
European Parliament and Council
Session
9th parliamentary term
Introduced
Sep 15, 2022
In effect since
Dec 10, 20241 year ago

Timeline

  1. Dec 11, 2027 in 1 year

    Main obligations scheduled to apply

  2. Sep 11 2 weeks ago

    Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents apply

  3. Jun 11 3 months ago

    Chapter IV (notification of conformity assessment bodies) applies

  4. Dec 10, 2024 1 year ago

    Enters into force

  5. Nov 20, 2024 1 year ago

    Published in the Official Journal

  6. Oct 23, 2024 1 year ago

    Final act signed

  7. Oct 10, 2024 1 year ago

    Council adopts the act

  8. Mar 12, 2024 2 years ago

    Parliament adopts its first reading position

  9. Jan 23, 2024 2 years ago

    ITRE committee approves the text agreed in trilogue

  10. Jul 19, 2023 3 years ago

    ITRE committee vote and decision to open negotiations

  11. Sep 15, 2022 4 years ago

    Commission proposal COM(2022) 454 published, procedure 2022/0272(COD)