The Cyber Resilience Act (CRA) is a regulation which establishes mandatory cyber security standards for all hardware and software products connected to a network or device. It requires manufacturers to implement strict vulnerability management, deliver timely security updates, and undertake conformity assessment procedures to ensure compliance. The CRA will allow the purchasers of products with digital elements to be properly informed about the cyber security of the products they buy and use.
The CRA entered into force on 10 December 2024 in Ireland. It is being implemented on a phased basis over three years and will apply in full from 11 December 2027.
In order to fully implement the CRA, Ireland must designate certain entities to fulfil the responsibilities of the regulation including a Notifying Authority with responsibility for establishing and overseeing the procedures for assessing, designating, notifying and monitoring Conformity Assessment Bodies (CABs), and a Market Surveillance Authority or Authorities, for enforcement and monitoring purposes.
Officials in my department are currently finalising arrangements to achieve these designations as soon as possible. Once the decision to designate the Notifying Authority has been approved by Government, I will be in a position to notify the European Commission of the decision.