EU Cyber Resilience Act (CRA)
EU Cyber Resilience Act (CRA) 是什么?
EU Cyber Resilience Act (CRA)EU Regulation 2024/2847 imposing security-by-design, vulnerability handling, and conformity-assessment obligations on essentially all products with digital elements sold in the EU, with main obligations applying from December 2027.
The EU Cyber Resilience Act (Regulation 2024/2847) is the first horizontal EU cybersecurity law applying to products. It entered into force in December 2024 with a phased timeline: vulnerability-reporting obligations from September 2026 and the full set of essential requirements from 11 December 2027. The CRA covers 'products with digital elements' — software, hardware, or both, including IoT devices, libraries, and many SaaS-tied products — placed on the EU market. Manufacturers must perform a cybersecurity risk assessment, deliver products free of known exploitable vulnerabilities, ship secure-by-default configurations, support security updates for at least five years (or product life if shorter), maintain an SBOM, handle vulnerabilities including coordinated disclosure, and report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours. Open-source software is largely excluded from manufacturer obligations but introduces 'open-source software stewards' as a lighter category. Penalties reach €15 million or 2.5 % of worldwide annual turnover. The CRA is widely expected to reshape OSS funding, embedded device security, and vendor risk programs through the late 2020s.
● 示例
- 01
An IoT camera manufacturer issues a CRA-mandated 24-hour ENISA notification when an actively exploited bug is reported on its firmware.
- 02
A SaaS vendor adds a 5-year security-update commitment and a CycloneDX SBOM to its product documentation to align with CRA essential requirements.
● 常见问题
EU Cyber Resilience Act (CRA) 是什么?
EU Regulation 2024/2847 imposing security-by-design, vulnerability handling, and conformity-assessment obligations on essentially all products with digital elements sold in the EU, with main obligations applying from December 2027. 它属于网络安全的 合规与框架 分类。
EU Cyber Resilience Act (CRA) 是什么意思?
EU Regulation 2024/2847 imposing security-by-design, vulnerability handling, and conformity-assessment obligations on essentially all products with digital elements sold in the EU, with main obligations applying from December 2027.
EU Cyber Resilience Act (CRA) 是如何工作的?
The EU Cyber Resilience Act (Regulation 2024/2847) is the first horizontal EU cybersecurity law applying to products. It entered into force in December 2024 with a phased timeline: vulnerability-reporting obligations from September 2026 and the full set of essential requirements from 11 December 2027. The CRA covers 'products with digital elements' — software, hardware, or both, including IoT devices, libraries, and many SaaS-tied products — placed on the EU market. Manufacturers must perform a cybersecurity risk assessment, deliver products free of known exploitable vulnerabilities, ship secure-by-default configurations, support security updates for at least five years (or product life if shorter), maintain an SBOM, handle vulnerabilities including coordinated disclosure, and report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours. Open-source software is largely excluded from manufacturer obligations but introduces 'open-source software stewards' as a lighter category. Penalties reach €15 million or 2.5 % of worldwide annual turnover. The CRA is widely expected to reshape OSS funding, embedded device security, and vendor risk programs through the late 2020s.
如何防御 EU Cyber Resilience Act (CRA)?
针对 EU Cyber Resilience Act (CRA) 的防御通常结合技术控制与运营实践,详见上方完整定义。
EU Cyber Resilience Act (CRA) 还有哪些其他名称?
常见的别称包括: CRA, Regulation EU 2024/2847。
● 相关术语
- compliance№ 816
NIS2 指令
欧盟第 2022/2555 号指令,提高了欧盟范围内基本实体和重要实体的网络安全基线要求和事件报告义务。
- compliance№ 387
DORA 条例
欧盟第 2022/2554 号《数字运营韧性法案》,自 2025 年 1 月 17 日起适用于金融业。
- compliance№ 620
ISO/IEC 27001
信息安全管理体系(ISMS)要求的国际标准,组织可据此通过正式认证。
- appsec№ 1185
软件物料清单(SBOM)
以机器可读形式正式描述构成一款软件的组件、库与依赖项及其版本与关系的清单。
- attacks№ 244
协调式漏洞披露 (CVD)
漏洞发现者、受影响厂商以及有时的协调方共同就时间表达成一致后再公开披露安全漏洞的流程。
- appsec№ 1094
安全编码
在编写源代码时遵循防御性模式、语言特定规则与公认指南,以最大程度减少安全缺陷的实践。