This page lists the binding legal acts that underpin CRA implementation. Practical guidance and supporting material have separate pages so that their legal status is not confused with legislation.
Core legal act
- Regulation (EU) 2024/2847 – Cyber Resilience Act – the binding basis; use EUR-Lex to check corrigenda, amendments and any consolidated text.
Delegated and implementing acts
- Delegated Regulation (EU) 2025/1535 – a specific exclusion for certain products covered by Regulation (EU) No 168/2013.
- Implementing Regulation (EU) 2025/2392 – technical descriptions of important and critical product categories; examples in the annexes are not exhaustive.
- Delegated Regulation (EU) 2026/881 – conditions for applying grounds to delay dissemination of notifications.
Related legal frameworks
- Market Surveillance Regulation (EU) 2019/1020.
- NIS2 Directive (EU) 2022/2555.
- Cybersecurity Act – Regulation (EU) 2019/881.
- Representative Actions Directive (EU) 2020/1828.
- Blue Guide 2022/C 247/01 – non-binding guidance on EU product rules.
Practical explanations and supporting sources
- European Commission guidance – implementation guidance and FAQs with date and legal-status information.
- ENISA guidance and tools – the SRP and operational reporting instructions.
- Technical standards and presumption of conformity – standardisation status and verification of Official Journal citations.
- NBÚ materials – verified national explanations and presentations.
Reading status correctly: legislation is binding within its scope. Guidance, FAQs, a developing standard or a presentation is not itself legislation. For a decision, always check the current version, date and exact provision.
Legal links reviewed 4 September 2026.