Navigating the European Cyber Resilience Act: key dates and obligations

DLA Piper
Contact

DLA Piper

[co-authors: Yaël Hirsch, Evelina Dimitrova, Aurélie Borgat, Sarah Squercioni, Alexandre Coudreau]

First introduced in December 2020 by the European Commission, the European Cyber Resilience Act (“ CRA”) regulation was published in the Official Journal on November 20th. It will come into force on December 10, 2024, but will not be immediately applicable. Most obligations will only apply as from December 2027, with the exception, for example, of serious incident notification obligations, which will apply from September 2026. The CRA will apply to all member states and the companies operating in them.

The official regulation is available here: Regulation – 2024/2847 – EN – EUR-Lex

The purpose of this regulation is to reinforce the cybersecurity of “products with digital components”. This includes connected devices (watches, connected toys, voice assistants etc.) and certain software (operating systems, firewalls, etc.), whether or not they are integrated into physical devices. Software made available in SaaS mode is excluded from the CRA in certain cases.

The CRA imposes new obligations not only on manufacturers, but also on all those involved in the design, development and sale of a product containing digital elements. For example, manufacturers must ensure that vulnerabilities in their products are dealt with for at least 5 years (unless the product’s lifespan is shorter), while importers and distributors of digitally-enabled products must check the conformity of documentation provided upstream of the production chain. Certain products (such as smart cards, connected toys or security software) are subject to specific reinforced measures due to their criticality.

DLA Piper’s team of intellectual property, data protection & cybersecurity and technology lawyers will publish articles to help you understand these new regulations.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© DLA Piper

Written by:

DLA Piper
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

DLA Piper on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide