Essential cybersecurity requirements for products, including state-of-the-art encryption of data at rest and in transit.
At a glance
| Type | EU regulation |
|---|---|
| Jurisdiction | EU |
| Who it applies to | Manufacturers, importers and distributors of products with digital elements (hardware and software) placed on the EU market. |
Cryptography requirements
| Reference | Requirement | What a scan and inventory can evidence |
|---|---|---|
| Annex I, Part I (2)(e) | Protect the confidentiality of stored, transmitted or otherwise processed data, e.g. by encrypting relevant data at rest or in transit by state-of-the-art mechanisms. |
|
Key dates
- Vulnerability and incident reporting obligations (Art. 14) apply.
- Full application of the regulation.
Sources
- Regulation (EU) 2024/2847 — Cyber Resilience Act · European Union
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.