The Cyber Resilience Act (CRA) entered into force on 10 December 2024. This new regulation will apply directly across EU member states from 11 December 2027, without requiring transposition into national law.
The requirement for manufacturers to notify severe incidents and actively exploited vulnerabilities will apply earlier, from 11 September 2026.
The CRA establishes baseline cybersecurity requirements for products with digital elements (hardware and software) applicable from the design phase to the product’s expected use.
Products that do not comply with the requirements introduced by the regulation will be prohibited from accessing the EU market.
Cullen International published an infographic providing an overview of the main obligations introduced by the CRA.
Clients of our European Digital Economy service, can also access it directly on our client portal via the following link:
more news
21 September 26
EU Kids Act: EU Commission unveils gradual and differentiated approach to protect children online, including a social media delay
As announced by EU Commissioner Von der Leyen in her State of the Union address, the EU Commission unveiled a gradual and differentiated approach to protect children online, where “each age benefits from a tailored protection level”. Read our full analysis.
18 September 26
EU Timeline: regulatory milestones for the remainder of 2026
This edition of Cullen International’s EU Timeline highlights key policy and regulatory developments foreseen at EU level until the end of 2026.
17 September 26
Electric power backup and other redundancy requirements for telecoms operators across Europe
Our latest European Benchmark explores electric power backup and other redundancy requirements for mobile network operators to ensure service continuity during power outages, natural disasters, and other events impacting the operation of telecoms networks.