Skip to main content
—
Framework library
Framework module · eu-cyber-resilience-act

EU Cyber Resilience Act

Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.

Regulation (EU) 2024/2847 · European Commission — Cyber Resilience Act

Standing today
Directory entry

00Answer

from the registry record
What is EU Cyber Resilience Act?
Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.
Who does EU Cyber Resilience Act apply to?
EU Cyber Resilience Act applies to hardware, software, IoT, technology, EU, per European Commission — Cyber Resilience Act.
What is the current version of EU Cyber Resilience Act?
The current edition is Regulation (EU) 2024/2847, issued by European Commission — Cyber Resilience Act. Source: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act.
What does an assessment under EU Cyber Resilience Act require?
No control catalog has been ingested for EU Cyber Resilience Act yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

EU Cyber Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; essential requirements not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Essential cybersecurity requirements · Vulnerability handling · Conformity assessment · Software bill of materials
Applies to
hardware · software · IoT · technology · EU
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11.Expected: 2027-12-11 (main obligations)

03Version ledger

1 edition
Regulation (EU) 2024/2847Current editiondate not published

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to technology · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.

  2. CSA STARSTAR Level 1 and Level 2

    Also applies to technology · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.

  3. Also applies to technology · The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.

  4. Also applies to technology · The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.

EU Cyber Resilience Act | ControlFrame