Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Industrial cybersecurity

Cyber Resilience Act (CRA)

Also known as: CRA, Regulation (EU) 2024/2847

German: Cyber Resilience Act (CRA)

The Cyber Resilience Act, Regulation (EU) 2024/2847, is EU legislation establishing cybersecurity requirements for products with digital elements across their lifecycle, from design through vulnerability handling and security updates during the support period. It entered into force on December 10, 2024.

  • Cybersecurity
  • EU
  • Compliance

In one sentence

The Cyber Resilience Act (CRA) sets EU cybersecurity requirements for products with digital elements, from design to vulnerability handling and updates.

Example

A machine builder whose packaging machines have an Ethernet interface and remote service must plan a support period, publish a vulnerability disclosure policy and supply security updates for the machine’s control software.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Dates: In force since December 10, 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from September 11, 2026; the main obligations from December 11, 2027.
  • Requirements: Essential cybersecurity requirements for product design, a secure default configuration, vulnerability handling, and security updates for a defined support period. Conformity is shown with CE marking, as for machinery.
  • Machinery: Machines with software and connectivity are typically products with digital elements. The CRA covers cybersecurity; the Machinery Regulation covers protection against corruption where it affects safety. Both must be addressed.
  • Technical documentation: The CRA requires technical documentation and user information on security, including the support period and how to install updates. Security documentation becomes part of the product documentation.

CRA vs. IEC 62443

The CRA is law and sets outcomes. IEC 62443 is a standards series describing how to achieve industrial cybersecurity. Harmonized standards for the CRA are being developed; applying IEC 62443 helps, but does not by itself demonstrate conformity with the CRA.

By knowledge.aitechdoc.world · Published September 25, 2026 · Last reviewed

Source: Regulation (EU) 2024/2847 (Cyber Resilience Act)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!