Articles

Cyber Resilience Act: what manufacturers should clarify now

CRA reporting duties already apply. Which digital products may be affected, what deadlines follow and how manufacturers can prepare.

The Cyber Resilience Act (CRA) concerns the cybersecurity of products with digital elements, including connected devices and software made available on the EU market. Its focus is the product itself, from development and distribution to vulnerability handling throughout the support period.

CRA reporting obligations have applied since 11 September 2026. Most other provisions apply from 11 December 2027. Organisations manufacturing digital products or marketing them under their own name should clarify three questions now: Are our products covered? What is our role? Which processes and evidence are missing? European Commission: CRA overview

1. Which products and businesses are affected?

The CRA generally covers products with digital elements whose intended or reasonably foreseeable use involves a direct or indirect data connection to a device or network and which are made available on the EU market in the course of commercial activity. The main obligations fall on manufacturers placing products on the market under their name or trade mark. Importers and distributors also have duties. Exemptions and special rules apply to some product groups and circumstances, so classification should not rely solely on labels such as “software” or “IoT”. European Commission: legislative summary

A product inventory is a useful starting point: what is offered, under whose brand, in which role, and with which associated software or remote processing functions? Complex software offerings warrant a closer look at their specific structure. The Commission’s July 2026 guidance addresses remote processing, open source and substantial modifications, among other topics.

2. What applies now, and what comes later?

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security. An early warning is required within 24 hours of becoming aware, followed by a further notification within 72 hours. Reports use the central CRA reporting platform. These duties may also affect products made available before December 2027. European Commission: reporting obligations

From 11 December 2027, the essential cybersecurity and vulnerability handling requirements apply, together with documentation and conformity obligations. Transitional rules apply to products already placed on the market; a subsequent substantial modification may be relevant. Timing therefore needs to be assessed for each product. European Commission: transitional rules

3. How should preparation begin?

A CRA project can start with a structured comparison between the product portfolio and existing practices:

  1. Record products and market roles: Which products are supplied in the EU, and who acts as manufacturer, importer or distributor?
  2. Assess product risks: Which attack surfaces, dependencies and security requirements matter for each product?
  3. Review development and components: How are security requirements, third-party components, updates and support managed throughout the product lifecycle?
  4. Define vulnerability and reporting processes: Who receives information, assesses it and can act within the deadlines?
  5. Plan evidence and conformity procedures: What technical documentation is needed, and which assessment procedure applies to the product category?

Manufacturer duties include cybersecurity risk assessment, vulnerability handling during the support period and technical documentation. Whether internal assessment is sufficient or a notified body is needed depends on the product category and applicable procedure. Preparation consultancy is not a conformity assessment and does not replace necessary specialist technical or legal review. European Commission: manufacturer duties and conformity

Our recommendation: begin with a sound assessment of your product portfolio and a prioritised gap analysis. This creates a work plan suited to your products and development processes.

← Latest articles