pqcstatus
Regulation & guidance

Cyber Resilience Act (Regulation (EU) 2024/2847): cryptography requirements and deadlines

EU regulation

Essential cybersecurity requirements for products, including state-of-the-art encryption of data at rest and in transit.

At a glance

TypeEU regulation
JurisdictionEU
Who it applies toManufacturers, importers and distributors of products with digital elements (hardware and software) placed on the EU market.

Cryptography requirements

ReferenceRequirementWhat a scan and inventory can evidence
Annex I, Part I (2)(e)Protect the confidentiality of stored, transmitted or otherwise processed data, e.g. by encrypting relevant data at rest or in transit by state-of-the-art mechanisms.
  • Cryptographic inventory
  • TLS configuration
  • Cryptography policy

Key dates

  1. Vulnerability and incident reporting obligations (Art. 14) apply.
  2. Full application of the regulation.

Sources

  1. Regulation (EU) 2024/2847 — Cyber Resilience Act · European Union

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Who must comply with Cyber Resilience Act (Regulation (EU) 2024/2847)?

Manufacturers, importers and distributors of products with digital elements (hardware and software) placed on the EU market.

What does Cyber Resilience Act (Regulation (EU) 2024/2847) require for cryptography?

Annex I, Part I (2)(e): Protect the confidentiality of stored, transmitted or otherwise processed data, e.g. by encrypting relevant data at rest or in transit by state-of-the-art mechanisms.

What are the key dates of Cyber Resilience Act (Regulation (EU) 2024/2847)?

September 11, 2026: Vulnerability and incident reporting obligations (Art. 14) apply. December 11, 2027: Full application of the regulation.