Framework module · eu-cyber-resilience-act
EU Cyber Resilience Act
Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.
Regulation (EU) 2024/2847 · European Commission — Cyber Resilience Act
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
EU Cyber Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Named and tracked only; essential requirements not modelled as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Essential cybersecurity requirements · Vulnerability handling · Conformity assessment · Software bill of materials
- Applies to
- hardware · software · IoT · technology · EU
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11.Expected: 2027-12-11 (main obligations)
03Version ledger
1 edition
| Regulation (EU) 2024/2847 | Current edition | date not published |