Law / European Union

Cyber Resilience Act, Essential Requirements and Manufacturer Obligations

Regulation (EU) 2024/2847, Art. 13 and Annex I

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 451 days, effective 11 December 2027.

A product security requirements rule binding public and private bodies.

As of 8 September 2026.

What it requires

  • This duty does not yet bind: the essential cybersecurity requirements of Annex I and the manufacturer duties of Article 13 apply to a product with digital elements placed on the EU market from 11 December 2027.
  • It does not reach free and open source software that is not monetized by its manufacturer, or a remote data processing service the product does not need in order to perform one of its own functions.
  • Once it applies, design, develop, and produce the product so it ships without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, and encryption of data at rest and in transit.
  • Maintain a support period of at least five years, or the product's expected use time if shorter, handle vulnerabilities in the product and its components throughout that period, and keep each security update available for ten years after release or for the remainder of the support period, whichever is longer.
  • Put in place a coordinated vulnerability disclosure policy and a contact channel for reporting a vulnerability, and disclose the end date of the support period to the buyer at the time of purchase.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 64(2): non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 carries a higher tier of up to EUR 15,000,000 or 2.5 percent of worldwide annual turnover, whichever is higher. A separate, lower tier under Article 64(3) covers other listed obligations (Articles 18 to 23, 28, and others) at up to EUR 10,000,000 or 2 percent, and Article 64(4) caps the supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities at up to EUR 5,000,000 or 1 percent. Article 64(10) exempts manufacturers qualifying as microenterprises or small enterprises from the administrative fines for missing the Article 14(2)(a) or 14(4)(a) 24-hour deadline, and exempts open-source software stewards from administrative fines entirely.

Rule
Higher of
As of
8 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
2.5

Who enforces it

Enforcement body

The market surveillance authority designated by each EU Member State under Article 52 of the Regulation, coordinated through the dedicated administrative cooperation group (ADCO).

Settledness

As of
8 September 2026
Guidance link
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
Guidance body
European Commission, Directorate-General for Communications Networks, Content and Technology (DG CONNECT)
Open questions
Does a remote data processing service the manufacturer markets alongside the product, but which the product's core function does not depend on, fall within Article 3(2)'s definition of remote data processing, or does it sit outside Annex I because the product can still perform its intended function without it?

What it reaches

Obligation class

Security, Governance, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 13 requires a manufacturer placing a product with digital elements on the EU market to design, develop and produce it in accordance with the essential cybersecurity requirements of Annex I, Part I, which include shipping without known exploitable vulnerabilities, a secure default configuration, protection against unauthorised access, encryption of data at rest and in transit, data minimisation, and resilience against denial-of-service and other attacks.

Annex I, Part II requires the manufacturer to identify and document vulnerabilities, including through a software bill of materials, remediate them without delay, operate a coordinated vulnerability disclosure policy, and provide security updates free of charge for a support period the manufacturer must set at not less than five years, or the product's expected use time if shorter, keeping each update available for ten years after release or for the remainder of the support period, whichever is longer.

The Regulation does not reach free and open source software that its manufacturer does not monetise, and its remote data processing requirements reach only a processing solution the manufacturer designed the product to need in order to perform one of its own functions, not a service the product could operate without.

Article 65 makes Directive (EU) 2020/1828 on representative actions apply to an infringement of this Regulation that harms, or may harm, the collective interests of consumers, letting a qualified consumer-protection entity, not an individual consumer, bring that action.

When LexLint raises it

  • distributes_software_product
  • ships_mobile_app

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2024/2847

Back to the example  ·  Lint your app