現在、規制ニュースは英語のみの提供となっております。ご迷惑をおかけしておりますが何卒ご理解の程よろしくお願いいたします。詳細等ご確認したい場合は弊社問い合わせ先にご連絡ください。

Cyber Resilience Act (CRA) officially adopted

EU (RE-D)
EU (RE-D)
, 2024-10-14
The European Union passed the Cyber Resilience Act (CRA) on 10 October 2024 to strengthen the cybersecurity of connected devices.
Shield icon

Cybersecurity for IoT Devices

The CRA establishes mandatory security requirements for digital products manufactured, imported, or sold in the EU, ensuring consistent safety across the lifecycle of these devices.

Key points:

  • Security requirements: Manufacturers must ensure that their products meet the cybersecurity criteria and remain secure throughout their entire lifecycle.

  • CE marking: Connected products must bear the CE marking certifying compliance with the cybersecurity standards.

  • Reporting requirements: Vulnerabilities and cyber incidents must be reported within 24 hours; detailed reports will follow within 72 hours to ENISA.

  • Updates and support: Manufacturers are obliged to provide free security updates during the expected lifespan of the products.

Timetable: The CRA will come into full effect from November 2027, while the first reporting requirements will apply from August 2026.

Source and further links: