Home / Cybersecurity / Cyber Resilience Act

EU regulation · manufacturers, importers, distributors

Cyber Resilience Act: reporting duties started on 11 September 2026

The EU Cyber Resilience Act (CRA) covers every product with digital elements sold in the EU — connected devices and software. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. From 11 December 2027, the whole regulation applies.

→ Check what the CRA means for my products

Since 11 September 2026: report within 24 hours

StepDeadlineContent
Early warning24 hours after becoming awareActively exploited vulnerability or severe incident, member states affected
Notification72 hoursNature of the issue, corrective or mitigating measures
Final report14 days after a fix is available (vulnerability) / 1 month (incident)Description, severity, root cause, measures taken

Reports go through the single reporting platform run by ENISA, to the national CSIRT.

From 11 December 2027

Who is affected

Penalties for breaching the essential requirements can reach €15 million or 2.5% of worldwide turnover.

Related

Frequently asked questions

We install solar panels, heat pumps or chargers. Are we a manufacturer?

Not if you only install products made by others. You become a manufacturer if you put your own name or brand on a product, or substantially modify it — and an importer if you bring products from outside the EU.

Does the CRA apply to software?

Yes, to software placed on the EU market as a product (with some exclusions, such as software covered by other specific EU rules and non-commercial open source).

What happens on 11 December 2027?

The whole regulation applies: products must meet the essential cybersecurity requirements, carry the CE marking on that basis and come with a support period for security updates.

Sources

Last checked: 28 September 2026. This page is general information, not legal advice.

Free first call · English

Selling connected products?

Tell us what you make or import. An English-speaking advisor replies within one business day with what the CRA requires from you and in which order.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call