Skip to content
Wednesday 2026-09-09 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

Definition

Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA), formally known as Regulation (EU) 2024/2847, is a comprehensive European Union regulation designed to improve the cybersecurity of products with digital elements. It establishes mandatory security requirements for manufacturers, importers, and distributors placing hardware and software products on the EU market, ensuring that cybersecurity is integrated throughout the entire product lifecycle.

Updated

At its core, the CRA aims to protect consumers and businesses by ensuring that connected devices—ranging from simple IoT (Internet of Things) sensors to complex software applications—are secure by design. This means manufacturers must conduct rigorous cybersecurity risk assessments, provide security updates for at least five years, and deliver a Software Bill of Materials (SBOM), which is a formal record containing the details and supply chain relationships of various components used in building software.

A critical component of the regulation is Article 14, which mandates strict reporting obligations for security incidents. Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform (SRP). This platform serves as a centralized hub where manufacturers submit notifications to a designated coordinator, who then disseminates the information to the European Union Agency for Cybersecurity (ENISA) and other relevant national Computer Security Incident Response Teams (CSIRTs).

The scope of the CRA is broad, explicitly covering modern digital infrastructure. Products with digital elements (PDEs)—any software or hardware that connects to a device or network—include AI agents, Model Context Protocol (MCP) servers, and inference endpoints. Because these technologies process data and interact with other systems, they are classified as software products under the regulation, meaning their developers must adhere to the same high standards of transparency and rapid incident response as traditional hardware manufacturers.

For example, imagine a company develops an AI agent that helps users manage their email. Under the CRA, this agent is considered a product with digital elements. If the company discovers that a hacker is actively exploiting a vulnerability in the agent’s code to steal user data, they must act immediately. According to Article 14, they are required to submit an ‘early warning’ to the ENISA Single Reporting Platform within 24 hours of becoming aware of the exploitation. Following this, they must provide a detailed notification within 72 hours and eventually submit a final report once a corrective measure, such as a security patch, is available.

The CRA represents a significant shift in how the EU approaches product cybersecurity, moving from voluntary guidelines to legally binding requirements. With penalties reaching up to €15 million or 2.5% of global annual turnover, manufacturers have strong incentives to comply. The regulation aims to create a more secure digital ecosystem across Europe, protecting consumers and businesses alike from the growing threat landscape.

Maintained by Theodore Wren · updated 2d ago