InsideCRA
InsideCRA › Regulation

Regulation (EU) 2024/2847

The Cyber Resilience Act at a glance

The Regulation reads best as four layers. The scope layer decides whether a product is covered at all: Articles 2 and 3 plus the recitals. The duties layer says who owes what: Article 13 carries the manufacturer duty set and Article 14 the reporting duty set, with importers, distributors, representatives and open-source stewards following in Chapter II. The conformity layer turns duties into procedure: standards, declarations, CE marking, notified bodies. The enforcement layer covers market surveillance and penalties.

The annexes carry the operational substance. Annex I Part I holds the secure-by-design product properties F-017 and Part II the vulnerability-handling process items F-018. Annex III lists the important products in class I and class II F-023 F-024, Annex IV the critical products F-025, and which conformity assessment route a product may use follows from that classification F-026.

Reading order that works

Scope, then classification, then duties, then procedure. Most wrong conclusions about this Regulation come from reading a duty before establishing scope, or from reading a class list without the implementing act that sharpens it.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Chapters

ChapterArticles
Chapter Article 1 – Article 71
BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847
Continue in the reference: Regulation map · topics · timeline.