Regulation (EU) 2024/2847
The Cyber Resilience Act at a glance
The Regulation reads best as four layers. The scope layer decides whether a product is covered at all: Articles 2 and 3 plus the recitals. The duties layer says who owes what: Article 13 carries the manufacturer duty set and Article 14 the reporting duty set, with importers, distributors, representatives and open-source stewards following in Chapter II. The conformity layer turns duties into procedure: standards, declarations, CE marking, notified bodies. The enforcement layer covers market surveillance and penalties.
The annexes carry the operational substance. Annex I Part I holds the secure-by-design product properties F-017 and Part II the vulnerability-handling process items F-018. Annex III lists the important products in class I and class II F-023 F-024, Annex IV the critical products F-025, and which conformity assessment route a product may use follows from that classification F-026.
Reading order that works
Scope, then classification, then duties, then procedure. Most wrong conclusions about this Regulation come from reading a duty before establishing scope, or from reading a class list without the implementing act that sharpens it.
Verified facts this page relies on
- F-003 The Regulation applies in full from 11 December 2027. Art. 71(2)
- F-017 Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m). Annex I Part I
- F-018 Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8). Annex I Part II
- F-023 Annex III Class I — important products, class I (items 1–19). Annex III Class I; Implementing Regulation (EU) 2025/2392
- F-024 Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392
- F-025 Annex IV — critical products (items 1–3). Annex IV; Implementing Regulation (EU) 2025/2392
- F-026 Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Chapters
| Chapter | Articles |
|---|---|
| Chapter | Article 1 – Article 71 |
sha256:27b7c6c64c773001… · CELEX 32024R2847