Article content
In briefShow moreShow lessThe Council adopted the Cyber Resilience Act with common security requirements for products with digital elements.
- The Council adopted the Cyber Resilience Act with common security requirements for products with digital elements.
- Responsibility moves clearly into the product lifecycle and supply chain.
- EEA-relevant EU product regulation; adoption in the EU did not itself make it Norwegian law. EEA incorporation and national implementation steps remain relevant.
What happened
The Council adopted the Cyber Resilience Act with common security requirements for products with digital elements. It follows software and hardware from design and development through vulnerability handling, security updates and market surveillance.
Responsibility moves clearly into the product lifecycle and supply chain. Manufacturers must document security, while importers and distributors must verify requirements and marking.
Legal status in Norway
EEA-relevant EU product regulation; adoption in the EU did not itself make it Norwegian law. EEA incorporation and national implementation steps remain relevant.
What the sources clarify
The regulation covered hardware and software connected directly or indirectly to a device or network, with exclusions where sector-specific EU rules already imposed cybersecurity requirements, including medical devices, vehicles and aviation products. CE marking would signal conformity in the market. Most requirements would apply 36 months after entry into force, with some provisions earlier. Product teams therefore needed vulnerability handling and security updates tied to versions actually in use, while importers and distributors had to verify more than the presence of a CE mark on packaging.
The product inventory should connect each product to software components, a vulnerability-reporting channel, its support period and responsibility for security updates. When a component flaw appears, the manufacturer must locate affected versions and communicate through the distribution chain. Importers and distributors therefore need contractual access to conformity records, contacts and remediation status.
Practical implications
Before a product is launched or imported, the decision owner should see its support period, open vulnerabilities, update mechanism and conformity evidence. Missing component and version information should be treated as a market risk because the organisation otherwise cannot locate affected customers or demonstrate remediation.
Sources
Council of the European Union: “Cyber Resilience Act: Council adopts new law,” 10 October 2024.
EUR-Lex: “Regulation (EU) 2024/2847 — Official Journal text,” 20 November 2024.
For discussion
Where is the largest gap between documented control and actual practice?

