ソース文書

本サイトのすべての義務・シナリオ・ツール出力はこれらの公式ソースに基づいています。

規則

タイトルCELEX / ELIステータスバージョン日付
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)

Entered into force 11 December 2024. Full application 11 December 2027. Art. 14 vulnerability reporting applies from 11 September 2026.

32024R2847In force2024-11-20
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)32022L2555In force2022-12-27
Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)32016R0679In force2016-05-04
Regulation (EU) 2024/1689 — Artificial Intelligence Act

Crosswalk relevant for AI-containing PDEs classified as high-risk AI systems.

32024R1689In force2024-07-12

付属書

タイトルCELEX / ELIステータスバージョン日付
CRA Annex I — Essential cybersecurity requirements

Part I: security properties. Part II: vulnerability handling.

32024R2847In force2024-11-20
CRA Annex II — Information and instructions to the user32024R2847In force2024-11-20
CRA Annex III — Important products with digital elements (Class I and Class II)32024R2847In force2024-11-20
CRA Annex IV — Critical products with digital elements32024R2847In force2024-11-20
CRA Annex V — EU Declaration of Conformity32024R2847In force2024-11-20
CRA Annex VI — Conformity assessment procedures

Modules A (internal control), B+C (EU type-examination), H (full quality assurance).

32024R2847In force2024-11-20
CRA Annex VII — Technical documentation32024R2847In force2024-11-20
CRA Annex VIII — Information for conformity assessment bodies32024R2847In force2024-11-20

委員会ガイダンス

タイトルCELEX / ELIステータスバージョン日付
Commission Communication — Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act)

Ares(2026)2319816. Non-binding draft guidance (~70 pages). Not yet adopted. Content tagged with status: draft-guidance in the rules engine until final adoption. Key sections: §3 commercial activity, §6 product classification, §8 RDPS test, substantial modification framework.

Draft2026-03-01
ENISA — Cyber Resilience Act: Guidance for Manufacturers

ENISA landing page; links to individual guidance documents. Hash-watched daily.

In force
ENISA — Single Reporting Platform for CRA Art. 14 vulnerability and incident reports

Reporting platform information; URL subject to change as platform is built out.

In force
The 'Blue Guide' on the implementation of EU product rules 2022

OJ C 247, 29.6.2022. Defines placing on the market, economic operators, conformity assessment, CE marking; all concepts carried into CRA.

In force2022-06-29

調和規格

関連規則・法令

タイトルCELEX / ELIステータスバージョン日付
Commission Delegated Regulation (EU) 2022/30 supplementing RED Directive with regard to cybersecurity

Art. 3(3)(d)(e)(f) RED cybersecurity requirements. For some radio products, CRA takes precedence; crosswalk documented in Phase 14.

32022R0030In force2022-01-29
Source documents — CRAコンプライアンスハブ