European regulation imposing cybersecurity requirements on products with digital elements throughout their life cycle, with CE marking and an obligation to supply updates.
DORA and NIS2 impose obligations on those who use digital products; the Cyber Resilience Act addresses those who make them. It sets essential security requirements for any product with digital elements placed on the Union market, from a home router to a commercial software library: design free of known exploitable vulnerabilities, secure configuration by default, vulnerability handling over an announced support period, and provision of a software bill of materials. It requires the manufacturer to report actively exploited vulnerabilities and severe incidents. And it places all of it under the CE marking regime, hence under withdrawal from the market in case of breach. For insurance, two consequences emerge. Product liability underwriting gains an objective benchmark where it previously had only professional custom. And cyber loss experience should move upstream, a product defect becoming a regulatory breach by the manufacturer rather than mere negligence by the end user.
Regulation (EU) 2024/2847, in force since December 10, 2024. Reporting obligations for actively exploited vulnerabilities apply from September 11, 2026, and the regulation in full from December 11, 2027. The staggered calendar gives manufacturers three years to fold the software bill of materials and the support period into their production cycle, which is short for a sector where components stay in service fifteen years.
CRA, Cyber Resilience Act, règlement (UE) 2024/2847, sécurité des produits comportant des éléments numériques