# Cyber Resilience Act

**What is the Cyber Resilience Act?**

The Cyber Resilience Act, Regulation (EU) 2024/2847, sets security requirements for products with digital elements. It addresses those who bring such products to market: manufacturers, importers and distributors.

For most businesses the most important point is a reassuring one. Anyone who merely uses software is not placed under duties by the regulation. The duties fall on the economic operators who make a product available.

Care is needed where that line blurs. Anyone who sells a bought in product under their own name or trademark counts as a manufacturer under Article 21. The same applies under Article 22 where a product is substantially modified and then made available. Businesses that pass on devices or software carrying their own logo should have this examined.

On the dates. The regulation entered into force on 10 December 2024. The reporting duties of manufacturers for actively exploited vulnerabilities and severe incidents under Article 14 apply from 11 September 2026. The remaining duties apply from 11 December 2027. This is our interpretation of the regulation and not legal advice.

## Related terms
- [NIS2](https://vetosec.at/en/it-security/nis2/)
- [Vulnerability and vulnerability assessment](https://vetosec.at/en/it-security/schwachstelle/)
- [Patch management and updates](https://vetosec.at/en/it-security/patch-management/)
- [Supply chain attack](https://vetosec.at/en/it-security/supply-chain-angriff/)

## Source
https://vetosec.at/en/it-security/cyber-resilience-act/ (vetosec, recht)
