# EU Cyber Resilience Act (Regulation 2024/2847)

Framework id: `cra`. Product Regulation. Publisher: European Parliament and Council. Version: 2024/2847. Region: EU. Mapping licence: CC BY-SA 4.0.
Source text: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (36, average coverage 51%)
- CRA.Art14 Reporting obligations — 24-hour early warning, 72-hour notification, final report (14 days after a fix for an exploited vulnerability, one month for a severe incident): IR-01, IR-05, IR-06, IR-08, PM-15, SI-05 (40%)
- CRA.I.1 General obligation — products designed, developed, and produced ensuring appropriate cybersecurity: SA-01, SA-02, SA-03, SA-04, SA-08, SA-10, SA-11, SA-15, SA-17, PL-08, PM-07, PM-30, SR-01, SR-02, SR-03 (72%)
- CRA.I.2a No known exploitable vulnerabilities at market availability: RA-05, SA-11, SA-15, SI-02, CA-02, CA-08, SR-06 (65%)
- CRA.I.2b Secure by default configuration with reset capability: CM-02, CM-06, CM-07, SA-04, SA-08, SC-28, SI-07 (78%)
- CRA.I.2c Vulnerabilities addressable through security updates — where applicable, automatic updates on by default with an opt-out: SI-02, MA-01, MA-02, CM-03, SA-22, SI-07 (60%)
- CRA.I.2d Protection from unauthorised access — authentication, identity management, report unauthorised access: AC-01, AC-02, AC-03, AC-06, AC-07, AC-17, IA-01, IA-02, IA-03, IA-04, IA-05, IA-06, IA-08, IA-11, IA-12, AU-02, AU-03, AU-06, SI-04 (85%)
- CRA.I.2e Data confidentiality — encrypt relevant data at rest and in transit, state of the art: SC-08, SC-12, SC-13, SC-28, MP-04, MP-05, SA-04 (88%)
- CRA.I.2f Data integrity — protect stored/transmitted data, commands, programs, configuration; report corruption: SC-08, SI-07, SI-10, SA-10, SC-16, AU-09, AU-10 (80%)
- CRA.I.2g Data minimisation — only adequate, relevant, limited data processed: PT-02, PT-03, PT-06, PM-25, SA-08, SI-12, SI-19 (82%)
- CRA.I.2h Availability — protect essential and basic functions, denial-of-service resilience: CP-01, CP-02, CP-07, CP-09, CP-10, SC-05, SC-06, SI-13, SI-17 (75%)
- CRA.I.2i Minimise negative impact on the availability of services provided by other devices or networks: SC-07, SC-44, SI-03, SI-04, CA-03, SA-09, SC-47 (55%)
- CRA.I.2j Attack surface reduction — limit external interfaces to minimum necessary: CM-07, SC-07, SA-08, AC-04, SC-41, SA-04 (78%)
- CRA.I.2k Incident impact reduction — exploitation mitigation mechanisms: SI-16, SC-03, SC-39, SC-24, SC-29, SC-30, SC-34, SC-35, SA-20, IR-04 (70%)
- CRA.I.2l Monitoring and logging — record and monitor internal activity, user opt-out: AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-08, AU-09, AU-11, AU-12, AU-14, SI-04, SI-11 (80%)
- CRA.I.2m Secure data removal — permanent deletion and secure transfer capability: MP-06, SI-12, SI-18, SI-19, MP-05 (72%)
- CRA.II.1 SBOM and vulnerability identification — document vulnerabilities and components, machine-readable SBOM: CM-08, SA-04, RA-05, SR-04, CM-12, PM-05 (50%)
- CRA.II.2 Timely remediation — address and remediate vulnerabilities without delay, provide security updates: SI-02, RA-05, CM-03, CM-04, SA-11, SA-22 (68%)
- CRA.II.3 Security testing — effective and regular tests and reviews: SA-11, CA-02, CA-08, RA-05, RA-06, SI-06 (82%)
- CRA.II.4 Public disclosure — share information about fixed vulnerabilities after security update: SI-05, PM-15, IR-06 (35%)
- CRA.II.5 Coordinated vulnerability disclosure policy: PM-15, PM-16, SI-05, IR-06 (30%)
- CRA.II.6 Vulnerability reporting channel — contact address for vulnerability reports: PM-15, IR-01, IR-07 (28%)
- CRA.II.7 Secure update distribution — mechanisms for timely and automatic security updates: SI-02, SI-07, CM-03, MA-01, SC-08 (55%)
- CRA.II.8 Free security updates — disseminated without delay, free of charge, with advisory information: SI-02, SI-05 (25%)
- CRA.Info.1 Manufacturer identification details — name, registered trade name, trademark, postal and electronic addresses: no control mapped (0%)
- CRA.Info.2 Vulnerability reporting single point of contact: IR-01, PM-15 (20%)
- CRA.Info.3 Product identification — type, batch, serial number, version: CM-08, CM-02 (15%)
- CRA.Info.4 Intended purpose and security environment description: SA-05, PL-02, PL-07 (42%)
- CRA.Info.5 Known or foreseeable cybersecurity risk circumstances: RA-03, RA-05, PM-09, SA-05 (45%)
- CRA.Info.6 EU declaration of conformity access — simplified or full, with internet address: no control mapped (0%)
- CRA.Info.7 Support period and end-date information: SA-22, PM-05 (25%)
- CRA.Info.8a Instructions for secure commissioning and lifetime use: SA-05, CM-06, PL-02, AT-01 (48%)
- CRA.Info.8b How changes to the product affect data security: CM-03, CM-04, SA-05 (40%)
- CRA.Info.8c How to install security updates: SI-02, SA-05 (38%)
- CRA.Info.8d Secure decommissioning instructions — including data deletion: MP-06, SA-05 (35%)
- CRA.Info.8e How to disable automatic security updates: CM-07, SA-05 (22%)
- CRA.Info.8f Integration documentation — secure integration with other products and systems: SA-05, SA-09, CA-03, SA-04 (55%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=cra
- Control-to-clause mappings as JSON: /api/v1/frameworks/cra?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/cra.json
- Page for people: /frameworks/cra/
