Home / Cybersecurity / Cyber Resilience Act
Cyber Resilience Act: reporting duties started on 11 September 2026
The EU Cyber Resilience Act (CRA) covers every product with digital elements sold in the EU — connected devices and software. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. From 11 December 2027, the whole regulation applies.
→ Check what the CRA means for my products
Since 11 September 2026: report within 24 hours
| Step | Deadline | Content |
|---|---|---|
| Early warning | 24 hours after becoming aware | Actively exploited vulnerability or severe incident, member states affected |
| Notification | 72 hours | Nature of the issue, corrective or mitigating measures |
| Final report | 14 days after a fix is available (vulnerability) / 1 month (incident) | Description, severity, root cause, measures taken |
Reports go through the single reporting platform run by ENISA, to the national CSIRT.
From 11 December 2027
- Essential cybersecurity requirements by design and by default
- Vulnerability handling during a declared support period
- Software bill of materials (SBOM) and technical documentation
- Conformity assessment and CE marking
- Security updates delivered free of charge during the support period
Who is affected
- Manufacturers of connected devices and software — including companies that sell products under their own brand
- Importers bringing products from outside the EU
- Distributors, who must check the CE marking and documentation
- Installers of solar inverters, heat pumps, EV chargers, alarms and smart-home systems: usually not manufacturers, but they must choose compliant products and pass on updates
Penalties for breaching the essential requirements can reach €15 million or 2.5% of worldwide turnover.
Related
Frequently asked questions
We install solar panels, heat pumps or chargers. Are we a manufacturer?
Not if you only install products made by others. You become a manufacturer if you put your own name or brand on a product, or substantially modify it — and an importer if you bring products from outside the EU.
Does the CRA apply to software?
Yes, to software placed on the EU market as a product (with some exclusions, such as software covered by other specific EU rules and non-commercial open source).
What happens on 11 December 2027?
The whole regulation applies: products must meet the essential cybersecurity requirements, carry the CE marking on that basis and come with a support period for security updates.
Sources
Last checked: 28 September 2026. This page is general information, not legal advice.
Selling connected products?
Tell us what you make or import. An English-speaking advisor replies within one business day with what the CRA requires from you and in which order.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg