YOUR
Search

    17.06.2026

    Cyber Resilience Act: the countdown has started


    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European Union is introducing a set of common rules aimed at strengthening the cybersecurity of digital products placed on the European market.

    Software, hardware, connected devices and, more generally, products containing digital elements must be designed, developed and maintained with cybersecurity in mind throughout their entire lifecycle.

    The Cyber Resilience Act came into force on 10 December 2024, but its effects will begin to be felt in the coming months.

    Indeed, the CRA will be implemented gradually, with some provisions coming into force as early as 2026, while the regulatory framework will be fully applicable from 11 December 2027.

    The first deadlines have already been set: from 11 June 2026, the rules relating to conformity assessment bodies will apply; from 11 September 2026, manufacturers will be required to report any actively exploited vulnerabilities or serious incidents affecting product security.

     

    Who is affected and which products containing digital components are covered?

    The provisions of the Cyber Resilience Act are primarily addressed to manufacturers of products containing digital components, but they also apply to other economic operators in the supply chain, including importers, distributors, authorised representatives and, where applicable, open-source software maintainers. In some cases, the manufacturer’s obligations may also fall on importers or distributors, for example when they market a product under their own name or brand or substantially modify the product.

    With regard to its material scope, the Cyber Resilience Act applies to products with digital elements made available on the European Union market. Broadly speaking, these are software or hardware products, including related remote data processing solutions, where their intended purpose or reasonably foreseeable use involves a direct or indirect, logical or physical data connection to a device or network.

    The Cyber Resilience Act therefore covers, by way of example, IoT devices, routers, operating systems, applications, management software, hardware and software components, smart home products, wearable devices and, more generally, digital or connected products intended for distribution or use in the European market.

    However, certain exclusions apply, for example, to products already regulated by specific sectoral legislation, to products developed exclusively for national security or defence purposes, and to certain cases relating to free and open-source software not supplied as part of a commercial activity.

    The practical application of the Cyber Resilience Act therefore requires a case-by-case assessment, taking into account both the product and its distribution model, as well as the role played by the economic operator.

     

    Key obligations

    The Cyber Resilience Act requires manufacturers to integrate cybersecurity throughout the entire lifecycle of products containing digital elements. Such products must therefore be designed, developed, manufactured and maintained in such a way as to ensure a level of security appropriate to the risks.

    Before placing the product on the market, the manufacturer must carry out an assessment of the cybersecurity risks of the product and take them into account at all relevant stages, from design to development, from production to delivery, right through to maintenance. The product must also comply with specific security requirements, including the reduction of exploitable vulnerabilities, secure-by-default configuration, protection against unauthorised access, safeguarding the confidentiality, integrity and availability of data, as well as the ability to receive security updates.

    The manufacturer will also be required to prepare the technical documentation, carry out the applicable conformity assessment procedure, draw up the EU declaration of conformity and affix the CE marking. For many products, self-assessment may be sufficient, while for those considered important or critical from a cybersecurity perspective, more rigorous procedures may be required, including the involvement of notified bodies.

    The manufacturer’s obligations do not end with the placing of the product on the market. The CRA requires the adoption of appropriate processes to identify, correct and document vulnerabilities even in the post-market phase.

    From 11 September 2026, manufacturers will also be required to notify actively exploited vulnerabilities affecting the product and serious incidents affecting its security. For actively exploited vulnerabilities, an initial report must be made within 24 hours of the manufacturer becoming aware of them, followed by a formal notification within 72 hours and a final report. Similar obligations apply to serious incidents, in accordance with specific timeframes for reporting and the final report.

    Importers and distributors are also subject to specific obligations. Before placing a product on the market or making it available, they must verify that the manufacturer has complied with the required obligations and that the product is accompanied by the required documentation and bears the CE marking. If they have reason to believe that a product does not comply or poses a cybersecurity risk, they must not place it, or make it available, on the market.

     

    What to do now

    In light of the deadlines set out in the Cyber Resilience Act, it is essential to begin an assessment of products, internal processes and relationships with suppliers and business partners in good time.

    Preparing in advance will therefore be essential to identify any compliance gaps and approach the upcoming deadlines with greater awareness.