Compliance & regulation
The EU law that makes makers of connected products and software build them secure and keep fixing their flaws.
Formal
Regulation (EU) 2024/2847, in force since 10 December 2024, setting basic security requirements for products with digital elements sold in the EU. Reporting of actively exploited flaws and severe incidents applies from 11 September 2026; all other duties, including the CE mark, from 11 December 2027.
In plain English
Like the safety rules for toys or kettles, but for the software inside things - a gadget that is easy to break into counts as unsafe to sell.
In practice
A Danish maker of smart door locks ships them without a default password, keeps a list of every software part inside, promises five years of free security updates and, on learning a flaw is being exploited, warns the authorities within 24 hours.
Why it matters
Buyers cannot judge the security of a camera, router or app, and makers used to pay little when it failed; the CRA shifts that cost to the maker, with fines of up to 15 million euro or 2.5% of global turnover.