EU Cyber Resilience Act sets cybersecurity rules for containers and Kubernetes
The EU Cyber Resilience Act (2024/2847) applies to container images, Kubernetes operators and commercially supported Helm charts sold in the EU. Reporting obligations start Sept. 11, 2026, with full enforcement on Dec. 11, 2027.
- CRA covers container images, Kubernetes operators and commercially supported Helm charts
- Exploited vulnerabilities: ENISA early warning within 24 hours, full notification within 72 hours
- Security updates required for at least 5 years after a product hits the market
- SBOMs, continuous vulnerability monitoring and hardened base images are mandatory
Read next
Policy