Skip to main content
Glossary termPublished inCRA

Cyber threat (CRA)

What does "Cyber threat" mean under the Cyber Resilience Act?

A cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881:

"cyber threat" means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons

Defined in / by

Also defined different in / by

Last updated: 22 August 2026.

Regulations

  • Cyber Resilience Act (CRA)

    The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations under Article 14 apply from 11 September 2026, to every product with digital elements on the Union market, including products placed there before the Regulation's main obligations start on 11 December 2027. Actively exploited vulnerabilities must be reported within 24 hours.

    Next
    Article 14 reporting obligations apply: actively exploited vulnerabilities and severe incidents

    Checked