By regulation

The EU Cyber Resilience Act

If you make, import or distribute a product with digital elements in the EU, your first obligation lands on 11 September 2026.

CRA · Deadline imminent

Reporting obligations begin — actively exploited vulnerabilities must be notified to the CSIRT of your main establishment and to ENISA.

Early warning within 24 hours; full notification within 72 hours; final report within 14 days of a corrective measure becoming available.

CRA readiness service

What the Cyber Resilience Act is

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is a horizontal product-safety regulation for hardware and software with digital elements placed on the EU market. It entered into force on 10 December 2024. It sits alongside the AI Act and existing sectoral rules: a product with digital elements that is also an AI system may have to comply with both.

The Act's aim is to ensure that products with digital elements are placed on the market with fewer vulnerabilities, that vulnerabilities are handled throughout the product lifecycle, and that users receive clear information about security updates and support periods.

Who it catches

The scope is wider than many organisations assume. It catches:

  • Connected industrial equipment, consumer IoT devices and their embedded software.
  • Operating systems, web browsers, mobile applications and development tools.
  • Commercial software that the maker may not think of as a "product" but is placed on the EU market for a price or as part of a service contract.
  • Remote data processing solutions and software provided as a product even if delivered via the cloud.

Manufacturers hold the obligations directly. Importers and distributors carry verification duties before placing products on the market. Component and software suppliers may receive their customers' obligations as contractual requirements downstream.

What the September 2026 obligation requires

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements must notify the CSIRT of its main establishment. The same information must be made available simultaneously to ENISA. The reporting runs through the CRA Single Reporting Platform — once, not to each Member State separately.

The timeline is tight:

  • Early warning: within 24 hours of becoming aware of the actively exploited vulnerability.
  • Full notification: within 72 hours of becoming aware.
  • Final report: no later than 14 days after the corrective measure has become available.

Severe incidents carry a parallel notification obligation with a one-month deadline for the final report. The distinction between a "regular" vulnerability notification and a "severe incident" notification depends on the criteria set out in the regulation, including scope and impact.

Full application: 11 December 2027

By 11 December 2027 the regulation applies in full. This includes the essential cybersecurity requirements for products with digital elements, the conformity-assessment procedures, internal risk-management processes, the need for technical documentation, and CE marking where required. Products that were already on the market before that date may still need to comply with the vulnerability-handling and reporting obligations after it.

What most organisations are missing

The reporting obligation requires infrastructure that many companies do not yet have: a way to learn that a vulnerability is being exploited; a documented decision process for whether it qualifies; a named person authorised to notify a regulator inside 24 hours, including over a weekend; and a reliable channel to reach customers who need to patch.

How CYBERVETTER helps

We treat CRA readiness as a product-lifecycle and governance exercise, not a one-off gap assessment. Our work typically covers:

  • Mapping the product and software portfolio against CRA scope, including products that are currently miscategorised.
  • Designing the vulnerability-intake, triage and reporting workflow so it can meet the 24/72/14-day clock.
  • Building the technical documentation and internal risk-management evidence required for conformity assessment.
  • Reviewing supplier and customer contracts to place obligations correctly on importers, distributors and upstream component suppliers.
  • Preparing the board and engineering leadership for what personal accountability and market-surveillance scrutiny look like under the Act.

Prepare for the September 2026 deadline

We help manufacturers, importers and software suppliers build the processes, evidence and reporting capability the CRA requires.

CRA readiness service