Cyber Resilience Act
In short: The Cyber Resilience Act (CRA) obliges manufacturers to design products with digital elements securely from the start and to maintain them.
In more detail: It entered into force in December 2024; most duties apply from December 2027. Reporting duties for exploited vulnerabilities start earlier.
In Depth
Contents
Security requirements, update duty over the product lifetime, vulnerability management, CE marking. Open-source projects with a commercial background are also affected. See NIS-2, open source, zero-day vulnerabilities.
See also: NIS2, Open Source, Zero-Day Vulnerabilities