Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
products with digital elements made available on the market, the
intended purpose or reasonably foreseeable use of which includes a
direct or indirect logical or physical data connection to a device or
network
(CRA Art. 2)
important, e.g.:
critical, e.g.:
⇒ does not affect PostgreSQL
a natural or legal person who develops or manufactures products
with digital elements or has products with digital elements designed,
developed or manufactured, and markets them under its name or
trademark, whether for payment, monetisation or free of charge
(CRA Art. 3)
a legal person, other than a manufacturer, that has the purpose or
objective of systematically providing support on a sustained basis for
the development of specific products with digital elements, qualifying
as free and open-source software and intended for commercial
activities, and that ensures the viability of those products
(CRA Art. 3)
| company that sells PostgreSQL or variants with support | manufacturer |
| company that sells (only) training or consulting for PostgreSQL | neither |
| company that sells PostgreSQL DBaaS | neither |
| company that does not sell any services around PostgreSQL but develops an open source software for internal use and also offers it for download | steward |
| Cloud Native Computing Foundation → Linux Foundation | steward |
| PostgreSQL Europe association | steward (?!?) |
| Software in the Public Interest (SPI) | steward |
| PostgreSQL Core Team | neither |
| PostgreSQL Security Team | neither |
| individual PostgreSQL hacker | neither |
(excerpt; CRA Art. 13)
(excerpt; CRA Annex I Part I)
(excerpt; CRA Annex I Part II)
either self-assessment or assessment by certified body
include conformity declaration (or on website)
affix CE marking
(excerpt; CRA Art. 14)
(24h)
from 11 September 2026!
(CRA Art. 15)
(CRA Art. 24)
In order to facilitate the due diligence obligation set out in
Article 13(5), in particular as regards manufacturers that integrate
free and open-source software components in their products with
digital elements, the Commission is empowered to adopt delegated acts
in accordance with Article 61 to supplement this Regulation by
establishing voluntary security attestation programmes allowing the
developers or users of products with digital elements qualifying as
free and open-source software as well as other third parties to assess
the conformity of such products with all or certain essential
cybersecurity requirements or other obligations laid down in this
Regulation.
(CRA Art. 25)
(for next 6 months)
(support for manufacturers)