The Cyber Resilience Act (CRA) entered into force on 10 December 2024. This new regulation will apply directly across EU member states from 11 December 2027, without requiring transposition into national law.
The requirement for manufacturers to notify severe incidents and actively exploited vulnerabilities will apply earlier, from 11 September 2026.
The CRA establishes baseline cybersecurity requirements for products with digital elements (hardware and software) applicable from the design phase to the product’s expected use.
Products that do not comply with the requirements introduced by the regulation will be prohibited from accessing the EU market.
Cullen International published an infographic providing an overview of the main obligations introduced by the CRA.
Clients of our European Digital Economy service, can also access it directly on our client portal via the following link:
more news
21 August 26
Sustainability targets of car manufacturers
Our latest benchmark summarises the sustainability targets put in place by the major car manufacturers.
19 August 26
Regulating submarine cable infrastructure
Our latest Global Trends benchmark analyses policies and regulations of relevance to international submarine cables used for electronic communications in 17 jurisdictions around the world.
18 August 26
Countries around the world take different approaches to data centre development
Cullen International’s new benchmark provides insights into how 19 countries, including 13 in Europe, have introduced rules to incentivise and/or regulate the development of data centres.