Cyber Resilience Act anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

CRA Anchors

Primary text

  • Regulation (EU) 2024/2847 — Cyber Resilience Act. Published OJEU 20 November 2024.

Adjacent regulation

  • NIS2 (Dir 2022/2555) — operator cybersecurity.
  • EU AI Act (Reg 2024/1689) — high-risk AI products.
  • MDR (Reg 2017/745) — medical devices (CRA excludes).
  • UN R155 / R156 — vehicles (CRA excludes).
  • Product Liability Directive (Dir 2024/2853) — product liability including AI.

Reference standards

  • EN 18031 — cybersecurity for radio equipment (RED Delegated Act).
  • ETSI EN 303 645 — consumer IoT cybersecurity baseline.
  • ISO/IEC 27034 — application security.
  • ISO/IEC 15408 (Common Criteria) — IT product security evaluation.

Operating bodies

  • European Commission — DG CNECT.
  • ENISA — implementation guidance.
  • Member State market surveillance authorities — enforcement.
  • Notified Bodies for third-party conformity assessment of important / critical products.

Reference resources

  • digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

See also