European Union: Implemented Regulation 2024/2847 amending the Cyber Resilience Act (2020/1828) including reporting obligations of manufacturers

Description

Implemented Regulation 2024/2847 amending the Cyber Resilience Act (2020/1828) including reporting obligations of manufacturers

On 11 September 2026, Regulation 2024/2847 concerning horizontal cybersecurity requirements for products with digital components, which amends Regulations (EU) No 168/2013 and (EU) No 2019/1020 as well as the Cyber Resilience Act (2020/1828), enters into force. The aforementioned EU Regulation (2024/2847) pertaining to the Cyber Resilience Act aspires to enhance the cybersecurity framework for products with digital components by establishing uniform cybersecurity requirements across the European Union. The regulation is applicable to all products featuring digital elements, including both hardware and software, that are made available on the EU market, with the exception of those regulated under specific existing legislation, such as medical devices and motor vehicles. Manufacturers are mandated to report actively exploited vulnerabilities and significant incidents to the relevant authorities, facilitated by a reporting platform managed by the European Union Agency for Cybersecurity (ENISA). Furthermore, member states are required to appoint market surveillance authorities to oversee compliance and enforce the regulation. These authorities are empowered to conduct surveillance activities and coordinated efforts to verify compliance and address instances of non-compliance. Non-compliance with the regulation may result in administrative fines reaching up to EUR 15,000,000 or 2.5% of the global annual turnover, whichever amount is greater.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
supranational
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2022-03-16
in consultation

On 16 March 2022, the European Commission launched a public consultation for the Cyber Resilience A…

2022-05-25
processing consultation

On 25 May 2022, the European Commission closed the public consultation for the Cyber Resilience Act…

2022-09-15
under deliberation

On 15 September 2022, the European Commission introduced a proposal for the "Cyber Resilience Act" …

2023-07-19
under deliberation

On 19 July 2023, the Council of the European Union reached a common position on the proposed Cybers…

2023-11-30
under deliberation

On 30 November 2023, the Council of the European Union and the European Parliament reached a common…

2024-03-12
under deliberation

On 12 March 2024, the European Parliament adopted the text provisionally agreed on the regulation r…

2024-10-10
adopted

On 10 October 2024, the Council of the EU adopted the regulation on Cybersecurity Requirements for …

2024-12-10
in grace period

On 10 December 2024, the Cyber Resilience Act entered into force with a grace period. The Cyber Res…

2026-06-11
in force

On 11 June 2026, Regulation 2024/2847 on horizontal cybersecurity requirements for products with di…

2026-09-11
in force

On 11 September 2026, Regulation 2024/2847 concerning horizontal cybersecurity requirements for pro…

2027-12-11
in force

On 11 December 2027, Regulation 2024/2847 on horizontal cybersecurity requirements for products wit…