Definition · AI governance
Cyber Resilience Act
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, is a European Union law setting cybersecurity requirements for hardware and software products that connect to a device or network. The Act requires manufacturers to design those products to essential cybersecurity requirements, handle vulnerabilities throughout a support period, and report actively exploited vulnerabilities and severe incidents.
Last reviewed
Key points
- The Cyber Resilience Act is Regulation (EU) 2024/2847. It covers hardware and software products that connect to a device or network.
- Manufacturers must meet essential cybersecurity requirements where applicable, such as shipping without known exploitable vulnerabilities, and fix vulnerabilities for a support period of normally at least five years.
- Manufacturers must report actively exploited vulnerabilities and severe incidents to the EU cybersecurity agency ENISA and a designated national security response team, with an early warning within 24 hours of becoming aware.
- Most duties apply from 11 December 2027. The reporting duty applies from 11 September 2026.
- A high-risk AI system in the CRA's scope that meets its essential requirements, with its declaration of conformity showing the Article 15 level, is deemed to meet EU AI Act Article 15 on cybersecurity, not on accuracy or robustness.
The Cyber Resilience Act (CRA) applies to “products with digital elements”: hardware or software, including separately sold components, whose use involves a connection to a device or network. Some products regulated elsewhere are excluded, including medical devices, motor vehicles, certified aviation products and marine equipment.
What manufacturers must do
- Build it secure. Assess the product’s cybersecurity risks, then meet the essential requirements in Annex I. Where they apply, these include shipping “without known exploitable vulnerabilities” and with “a secure by default configuration”.
- Keep it secure. Handle vulnerabilities for a support period that matches the product’s expected use, and at least five years unless it is expected to be in use for less. Keep a software bill of materials covering at least top-level dependencies, and run a coordinated vulnerability disclosure policy.
- Report. Tell the national computer security incident response team acting as coordinator, and ENISA, the EU cybersecurity agency, about any actively exploited vulnerability or severe incident affecting product security. An early warning is due within 24 hours of becoming aware; a fuller notification and a final report follow.
Products in listed “important” or “critical” categories can face stricter conformity assessment than an internal check by the manufacturer.
Why it matters for AI
An AI system sold as a software or hardware product can fall within the CRA, and Article 12 links the CRA to Article 15 of the EU AI Act. A high-risk AI system that meets the CRA’s essential requirements, with its declaration of conformity showing the level of cybersecurity Article 15 requires, is deemed to meet Article 15’s cybersecurity requirements. Article 15’s accuracy and robustness requirements still apply.
For such a system, Recital 51 asks the CRA risk assessment to consider AI-specific vulnerabilities such as data poisoning. The 2026 Digital Omnibus on AI restated the Article 12 rule in the AI Act as Article 42(3).
Questions and answers
When does the Cyber Resilience Act apply?
The Cyber Resilience Act applies in full from 11 December 2027. Its duty to report actively exploited vulnerabilities and severe incidents, Article 14, applies from 11 September 2026. The rules on bodies that assess products, Articles 35 to 51, apply from 11 June 2026.
Does the Cyber Resilience Act cover SaaS?
Not as such. Recital 12 of the Act says cloud services designed and developed outside a product manufacturer's responsibility are out of scope. It points to a separate law, Directive (EU) 2022/2555, which covers Software as a Service from providers that are medium-sized or larger. A cloud feature built by or for a product's manufacturer is in scope when the product cannot perform one of its functions without it, such as remote control of a smart home device.
Does meeting the Cyber Resilience Act satisfy EU AI Act Article 15?
Only in part. A high-risk AI system in the Act's scope that meets its essential requirements, with its declaration of conformity showing the Article 15 level of cybersecurity, is deemed to meet Article 15's cybersecurity requirements. Article 15's accuracy and robustness requirements still apply separately.
What are the fines under the Cyber Resilience Act?
Breaching the essential requirements in Annex I or the manufacturer duties in Articles 13 and 14 can bring a fine of up to 15 million euros or, for a company, up to 2.5 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), title and Articles 2(1), 3(1) and 3(2)European Union, 20 Nov 2024
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71, and its EUR-Lex document informationEuropean Union, 20 Nov 2024
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), recitals and Article 1 point 18European Union, 24 Jul 2026