# EU Cyber Resilience Act 2024/2847

> The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements. For Provael the relevant story is its own software-security posture — SBOM, coordinated vulnerability handling, secure-by-default, and a defined support period — not the policy-attack result.

Regulation/standard: Regulation (EU) 2024/2847
Timing: Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.

## What it is

- Regulation (EU) 2024/2847 imposes security-by-design, vulnerability handling and reporting duties on products with digital elements placed on the EU market.
- It mandates an SBOM, coordinated vulnerability disclosure, and security updates over a defined support period.
- Reporting duties phase in ahead of full application.

## Where a red-team result fits

- **Vulnerability handling** — A coordinated vulnerability-disclosure process and an SBOM are baseline expectations — Provael ships both, and publishes a security.txt.

## What Provael maps to it

- An SBOM published with each release.
- A coordinated vulnerability-disclosure policy and RFC 9116 security.txt.
- Secure-by-default posture: no telemetry and no network egress by default.

## Dates (verified 6 Jul 2026)

- Reporting obligations (Art. 14) apply: 11 September 2026
- Full application: 11 December 2027

## Sources

- Regulation (EU) 2024/2847 (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- Cyber Resilience Act (European Commission): https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

Canonical: https://www.provael.com/compliance/eu-cyber-resilience-act

---
Provael · Prove it. Prevail. · Apache-2.0 · https://github.com/provael/provael
Not legal advice; verify regulatory dates against the primary source.
