EU Cyber Resilience Act

Statute European Union · 2024

The EU Cyber Resilience Act is the first horizontal law to impose cybersecurity obligations on products with digital elements across their whole lifecycle — secure-by-design and secure-by-default requirements, a mandatory coordinated vulnerability disclosure policy, vulnerability handling and security updates for the support period, an SBOM for the top-level dependencies, and reporting of actively exploited vulnerabilities and severe incidents to ENISA. Unlike the sectoral data mandates, it compels no API; it compels a set of provable processes, several of which are naturally expressed as machine-readable artifacts.

Horizontal regime. It binds companies by what they do with data, software or customers, not by the sector they sit in. The industries below are where it creates specific, additional duties — not the limit of who has to comply.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.

Implemented by these standards

A regulation is the law; a standard is the machine-readable contract that satisfies it. Almost every regime in this catalog restricts an interface rather than requiring one — where a standard exists, it is the part a provider can actually publish.