Chapter I - GENERAL PROVISIONS
1

Article 1

Subject matter

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Article 1 defines the subject matter of the EU CRA: uniform cybersecurity requirements for products with digital elements made available on the EU market. The regulation addresses manufacturers, importers, and distributors across the entire product lifecycle.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

This Regulation lays down:

a)

rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;

b)

essential cybersecurity requirements for the design, development and production of products with digital elements, and obligations for economic operators in relation to those products with respect to cybersecurity;

c)

essential cybersecurity requirements for the vulnerability handling processes put in place by manufacturers to ensure the cybersecurity of products with digital elements during the time the products are expected to be in use, and obligations for economic operators in relation to those processes;

d)

rules on market surveillance, including monitoring, and enforcement of the rules and requirements referred to in this Article.

Common Manufacturer Questions

What does Article 1 of the EU CRA cover?

Article 1 defines the scope of the entire regulation: cybersecurity requirements for products with digital elements and their manufacturers across the product lifecycle — from placing on the market to end of support.

Which actors does the CRA address?

Directly addressed actors are manufacturers, importers, and distributors of products with digital elements placed on the EU market. The CRA also indirectly affects suppliers (through SBOM requirements) and end customers (through transparency obligations).

Is the CRA horizontal or sector-specific?

Horizontal. It applies across all industries to every product with digital elements — from smart home devices to industrial controllers. Sector-specific exemptions apply only where other EU cybersecurity frameworks already cover the products (medical devices, vehicles, aviation).

Related Recitals

(7)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex