Oracle is committed to supporting customers and partners as the European Union’s Cyber Resilience Act (CRA) enters into application.

The Cyber Resilience Act introduces a common cybersecurity framework for products with digital elements made available on the European Union market.

The CRA introduces requirements in two phases.

Beginning on 11 September 2026, the CRA’s vulnerability and incident reporting obligations become applicable. These obligations require manufacturers to report actively exploited vulnerabilities and severe security incidents affecting covered products through the European Union’s reporting framework. The reporting requirements are intended to support coordinated awareness, information sharing, and response activities across the EU cybersecurity ecosystem. Oracle’s established vulnerability management and security incident response capabilities support preparations for these obligations.

Beginning on 11 December 2027, the CRA’s broader product cybersecurity requirements become applicable. These requirements establish cybersecurity and vulnerability management obligations across the product lifecycle for products with digital elements. Oracle is continuing to assess and prepare for these requirements in line with evolving implementation guidance and supporting standards, building on established secure development and product security practices.

Oracle is committed to meeting applicable regulatory obligations and is preparing for these important milestones. As implementation guidance and supporting standards continue to evolve, Oracle will provide information to help customers understand its approach to the CRA and related product security requirements.

Learn More