The Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for hardware and software "products with digital elements" placed on the EU market, including vulnerability handling and incident reporting obligations for manufacturers.
2 deadlines tracked. Dates are the legally binding application dates.
Any manufacturer that sells software or connected hardware in the EU, including small software vendors and open-source projects run commercially. Non-commercial open source is largely exempt.
Manufacturers, importers and distributors of software and connected hardware sold in the EU, including small SaaS vendors that ship client software, IoT makers and app developers.