Skip to content

Standard

Cyber Resilience Act

EU Regulation 2024/2847 requiring cybersecurity measures for digital products, including vulnerability handling and 24-hour exploit reporting.

Known aliases

  • 02024R2847
  • EU Cyber Resilience Act
  • Regulation (EU) 2024/2847

Current stories

productConfirmed2 publishers

CISA wants NetScaler owners to check for intruders before installing Citrix's zero-day fixes

Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence70
securityOne report1 publisher

The Cyber Resilience Act counts the hosted backend as part of the product

Regulation (EU) 2024/2847 defines a product with digital elements to include the remote data processing its functions depend on, and it makes vulnerability handling an essential requirement for as long as the product is expected to be in use.

Publishers:eur-lex.europa.eu

Reality

Evidence84
Adoption
Insufficient
Hype gap0
Incentives22
Confidence70
productOne report1 publisher

One CRA report now reaches every member state where the product is available

ENISA's Single Reporting Platform went live on 11 September 2026, the day manufacturers' Article 14 duty applied. The coordinating CSIRT is set by where a company is established, and open-source stewards have until December 2027.

Publishers:enisa.europa.eu

Reality

Evidence66
Adoption22
Hype gap+12
Incentives55
Confidence62