EU Cyber Resilience Act
Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.
Regulation (EU) 2024/2847 · European Commission — Cyber Resilience Act
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
EU Cyber Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; essential requirements not modelled as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Essential cybersecurity requirements · Vulnerability handling · Conformity assessment · Software bill of materials
- Applies to
- hardware · software · IoT · technology · EU
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11.Expected: 2027-12-11 (main obligations)
03Version ledger
| Regulation (EU) 2024/2847 | Current edition | date not published |
05Change history
06Related frameworks
- CSA CCM and CAIQv4.1
Also applies to technology · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
- CSA STARSTAR Level 1 and Level 2
Also applies to technology · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.
- NIST SSDFv1.1
Also applies to technology · The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.
- ISO/IEC 420012023
Also applies to technology · The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.