Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Regulations

Cyber Resilience Act (CRA)

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the European regulation that sets cybersecurity requirements for products with digital elements placed on the EU market, hardware and software alike, from connected devices to operating systems and applications. Manufacturers must design products securely, handle vulnerabilities throughout a support period, provide security updates, report actively exploited vulnerabilities and severe incidents, and affix the CE marking after conformity assessment. Reporting obligations apply from 11 September 2026, the main obligations from 11 December 2027.

Who it binds

Primarily manufacturers, meaning whoever develops a product or has it developed and markets it under their name, including open-source stewards in a lighter regime; importers and distributors carry verification duties. Products are classed by risk: a default class with self-assessment, important products in two classes with stricter assessment, and critical products that may require European certification. Software as a service is out unless it is part of remote data processing that a product depends on.

The obligations

Annex I sets the essential requirements: secure-by-default configuration, protection against unauthorized access, confidentiality and integrity, attack-surface limitation, security updates, and a vulnerability handling process with a software bill of materials, coordinated disclosure and a policy for reporting. The support period is set by the product’s expected lifetime, five years at minimum for most products. Actively exploited vulnerabilities and severe incidents are reported to ENISA and the national CSIRT with an early warning within 24 hours, a notification within 72 hours and a final report within 14 days.

What it changes for a security program

For a manufacturer, product security stops being an engineering preference and becomes a compliance obligation with evidence: a risk assessment per product, a documented vulnerability handling process, a tested update mechanism and technical documentation the market surveillance authority can request. For a buyer, the CE marking and the manufacturer’s vulnerability policy become inputs to third-party risk, and a product that has left its support period becomes a security exception with an expiry.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.