Cyber Resilience Act
Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU, including vulnerability handling and incident reporting duties for manufacturers.
Where it stands
In forceIntroducedCommitteeFloorLawIn forceArticle 14 reporting obligations for actively exploited vulnerabilities and severe incidents applySep 112 weeks ago
- Body
- European Parliament and Council
- Session
- 9th parliamentary term
- Introduced
- Sep 15, 2022
- In effect since
- Dec 10, 20241 year ago
Timeline
Dec 11, 2027 in 1 year
Sep 11 2 weeks ago
Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents apply
Jun 11 3 months ago
Chapter IV (notification of conformity assessment bodies) applies
Dec 10, 2024 1 year ago
Nov 20, 2024 1 year ago
Oct 23, 2024 1 year ago
Oct 10, 2024 1 year ago
Mar 12, 2024 2 years ago
Jan 23, 2024 2 years ago
Jul 19, 2023 3 years ago
Sep 15, 2022 4 years ago
Commission proposal COM(2022) 454 published, procedure 2022/0272(COD)