Skip to content
DS Content

Magazine for digital signage and DOOH

Glossary A–ZLetter C

Cyber Resilience Act (CRA)

The Cyber Resilience Act is EU Regulation 2024/2847, which lays down minimum cybersecurity requirements for products with digital elements.

This means hardware and software that can connect to a device or a network. The regulation has been in force since 10 December 2024; the reporting obligations have applied since 11 September 2026, and the remaining obligations apply from 11 December 2027.

In screen networks, the regulation mainly concerns media players, displays with a built-in operating system and player software. Manufacturers must place products on the market without known exploitable vulnerabilities, provide security updates over a defined support period, handle vulnerabilities and keep technical documentation. From December 2027 the CE marking is the visible proof. Actively exploited vulnerabilities and severe security incidents already have to be reported.

The obligations fall primarily on manufacturers, importers and distributors, not on the operator who merely uses screens. However, anyone who sells devices under their own name or trademark can become a manufacturer themselves. Operators still benefit: when buying, they can ask until when security updates are promised and where to report a security flaw. This explanation is not legal advice.

See also