Conditional requirement
Cyber Resilience Act (CRA)
Cyber Resilience Act (CRA) — conditional requirement, European Union. It binds manufacturers of products with digital elements placed on the EU market.
- Jurisdiction
- European Union
- Record class
- Conditional requirement
- Instrument
- Reporting
- Last verified
Where this applies
This record is scoped to European Union. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Regulation (EU) 2024/2847 (in force 10 December 2024)
Who it binds
Manufacturers of products with digital elements placed on the EU market.
What it requires
Chapter IV (Arts 35–51, notification of conformity-assessment bodies) has applied since 11 June 2026, so CRA notified bodies can already be designated. Reporting obligations apply from 11 September 2026, and the main obligations from 11 December 2027.
Route to the authority
Last verified:
Related records and requirements
- Technology and Data — Applies to manufacturers of products with digital elements placed on the EU market. Reporting obligations apply from 11 September 2026; the main obligations apply from 11 December 2027; conformity-assessment-body notification has applied since 11 June 2026.
- Manufacturing and Industry — Applies to manufacturers of products with digital elements placed on the EU market. Reporting obligations apply from 11 September 2026; the main obligations apply from 11 December 2027; conformity-assessment-body notification has applied since 11 June 2026.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.