Council of the European Union Adopts the Cyber Resilience Act


On October 10, 2024, the Council of the European Union (the “Council”) adopted the EU’s new regulation on horizontal cybersecurity requirements for products with digital elements (the “Cyber Resilience Act”). The Cyber Resilience Act regulates cybersecurity issues in the design, development, production, manufacturing, and making available on the market, of hardware and software products that are connected, directly or indirectly, to another device or to a network (such as connected home cameras, fridges, TVs, toys and other IoT products).

The Council’s adoption is the final stage of the EU legislative process (following earlier approval by the European Parliament). As a next step, the Cyber Resilience Act will be published in the EU’s Official Journal and will enter into force 20 days after such publication (the “Effective Date”). The majority of the provisions will become applicable 36 months after the Effective Date, with some exceptions such as the rules on incident reporting which become applicable 21 months after the Effective Date. As a regulation, the Cybersecurity Resilience Act will apply directly in all EU Member States.

The key obligations of the Cyber Resilience Act include: 

Non-compliance with the requirements of the Cyber Resilience Act may result in administrative fines of up to €15 million or 2.5% of a company’s global annual turnover for the previous fiscal year, whichever is higher.

Read the: Council’s Press Release and the Cyber Resilience Act.


Copyright © 2025, Hunton Andrews Kurth LLP. All Rights Reserved.
National Law Review, Volume XIV, Number 291