Framework library
Framework module · eu-cyber-resilience-act

EU Cyber Resilience Act

Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.

Regulation (EU) 2024/2847 · European Commission — Cyber Resilience Act

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

EU Cyber Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Named and tracked only; essential requirements not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Essential cybersecurity requirements · Vulnerability handling · Conformity assessment · Software bill of materials
Applies to
hardware · software · IoT · technology · EU
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11.Expected: 2027-12-11 (main obligations)

03Version ledger

1 edition
Regulation (EU) 2024/2847Current editiondate not published
EU Cyber Resilience Act — framework module | ControlFrame