Skip to main content
  1. Index/

EU Cyber Resilience Act (CRA)

Table of Contents

The Cyber Resilience Act (CRA) is a European Union regulation — not a voluntary standard — that entered into force on 10 December 2024 and will be fully applicable on 11 December 2027. It is issued by the European Commission and co-legislated by the European Parliament and Council; it is not a certification scheme but a horizontal product-safety law, comparable in structure to the CE-marking directives for physical goods. The CRA applies to all manufacturers, importers, and distributors of “products with digital elements” — any software or hardware product containing a data connection — that is made available on the EU single market, regardless of where the manufacturer is headquartered. Compliance is mandatory: non-compliant products cannot legally be placed on the EU market after the deadline, and penalties can reach €15 million or 2.5 % of global annual turnover. Key intermediate deadlines include 11 September 2026 (manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours) and 11 June 2026 (conformity assessment body framework becomes operational). Products already on the market before 11 December 2027 are exempt from the full requirements unless they undergo a “substantial modification,” but they are subject to the vulnerability reporting obligation from September 2026 onward.

Red Hat is directly in scope of the CRA as a manufacturer of products with digital elements (RHEL, OpenShift, Ansible Automation Platform, and the broader portfolio). Red Hat publicly states it is aligning its mature secure-by-design lifecycle with CRA mandates and has published a dedicated compliance page on its Customer Portal. Concretely, Red Hat already provides machine-readable security advisories (CSAF/VEX), SBOMs for container images, Sigstore-based artifact signing, and SLSA-compliant build pipelines via the Trusted Software Supply Chain portfolio — all of which map to CRA essential requirements around vulnerability handling, transparency, and supply-chain integrity. Red Hat also acts as an open source software steward for upstream projects like Fedora and Ansible, a role explicitly recognized by the CRA with lighter (but non-zero) obligations. Through leadership in the Eclipse Open Regulatory Compliance (ORC) Working Group and the OpenSSF, Red Hat has helped shape CRA implementing standards so they reflect how open source software is actually developed — ensuring that compliance obligations fall on commercial manufacturers rather than volunteer maintainers. For Red Hat customers, the practical implication is that Red Hat’s products are being engineered to ship with the technical documentation, conformity evidence, and vulnerability-handling processes the CRA demands, reducing the customers’ own burden when integrating Red Hat software into their CE-marked products or fulfilling their downstream obligations.

Additional Information
#

Related

NIS2 Directive

The NIS2 Directive (EU 2022/2555) is an EU directive — the successor to the original NIS1 of 2016 — that entered into force on 16 January 2023 with a transposition deadline of 17 October 2024, meaning each EU Member State was required to adopt it into national law by that date and enforce it from 18 October 2024 onward. NIS2 is issued by the European Parliament and Council; as a directive (not a regulation), its exact requirements vary by Member State, but the baseline obligations are binding. It applies to medium and large organizations (50+ employees or €10M+ annual turnover) operating in 18 critical sectors including energy, transport, health, banking, digital infrastructure, ICT service management, public administration, and manufacturing. Entities are classified as essential (proactive supervision, fines up to €10M or 2 % of global turnover) or important (reactive supervision, fines up to €7M or 1.4 % of turnover). Compliance is mandatory — management bodies are personally liable for overseeing cybersecurity risk management. Key obligations include implementing proportionate technical and organizational security measures, conducting supply chain risk assessments, reporting significant incidents to the national CSIRT within 24 hours (early warning), 72 hours (full notification), and one month (final report), and cooperating with national cybersecurity authorities. Member States were required to publish their lists of essential and important entities by 17 April 2025.

EU Cloud Services Scheme (EUCS)

The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is not yet adopted — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, voluntary certification that would harmonize the fragmented national cloud certifications (such as France’s SecNumCloud or Germany’s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the “high” assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.

EU Cybersecurity Act (CSA)

The EU Cybersecurity Act (CSA) — Regulation (EU) 2019/881 — was adopted by the European Council in April 2019 and fully entered into force on 28 June 2021. It is a European regulation (directly applicable in all Member States without transposition) that serves two primary functions: it strengthened and made permanent the mandate of ENISA (the EU Agency for Cybersecurity), and it established a voluntary EU-wide cybersecurity certification framework for ICT products, services, and processes. The CSA is not itself a certification scheme but rather the legal foundation upon which specific schemes are built — currently EUCC (adopted January 2024), EUCS (cloud, under development), EU5G (5G networks, under development), EUDI Wallets, and EUMSS (managed security services). Each scheme defines assurance levels (basic, substantial, high), evaluation methodologies, and mutual recognition rules so that a certificate issued in one Member State is valid across the entire EU. The CSA applies to any entity — manufacturer, service provider, or operator — that voluntarily seeks EU cybersecurity certification for its offerings, though sector-specific regulations (NIS2, CRA, DORA) may make certification effectively mandatory for certain use cases. A recast of the CSA (CSA2) was proposed by the European Commission on 20 January 2026, aiming to strengthen certification mandates, reinstate sovereignty requirements in cloud certification, and reinforce ENISA’s supervisory role.