Cyber Resilience Act (CRA)
About the Cyber Resilience Act (CRA)
Full name: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828
Type: Regulation
Objective and key elements:
- Setting horizontal baseline of rules for security in the internal market
- Increasing the overall level of cybersecurity of all products with digital elements by introducing essential cybersecurity requirements for such products
- Security updates to be made available for at least 5 years
- Reporting obligations for manufacturers in case of security incidents
- Possibility to recall products not fulfilling the requirements
Relevant to: Manufacturers, importers, and distributors of products and software including digital elements (excluding services, such as SaaS and certain specifically regulated products (e.g. cars)).
Status: In force, will apply from 11 December 2027.
Next steps: Chapter IV entered into application on 11 June 2026. Article 14 will apply from 11 September 2026. Full application from 11 December 2027.
Earlier versions:
- Text adopted by the Council on 10 October 2024 is available here
- Text adopted by the Parliament on 12 March 2024 is available here
- The Council’s proposed amendments on 13 July 2023 is available here
- Commission proposal published on 15 September 2022 is available here
Guidance:
- European Commission: Cyber Resilience Act – Questions and Answers
- Commission guidance on the application of the Cyber Resilience Act (CRA)
Hannes Snellman blog posts:
(Last updated 29 July 2026)
Implemented in Finland as:
- Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista
- Laki eräiden tuotteiden markkinavalvonnasta annetun lain 1 ja 4 §:n muuttamisesta
- Laki kyberturvallisuuslain 20 ja 28 §:n muuttamisesta
- Laki sähköisen viestinnän palveluista annetun lain muuttamisesta
- Laki sakon täytäntöönpanosta annetun lain 1 §:n muuttamisesta
Status:
- In force since 1 June 2026.
Supervisory authority: National Cyber Security Center Finland (NCSC-FI) at the Finnish Transport and Communications Agency Traficom
(Last updated 29 July 2026)
