Shape

Updated 28 September 2026

Cyber Resilience Act: a practical guide for manufacturers

The EU Cyber Resilience Act sets cybersecurity requirements for every product with digital elements. Here is what it changes, for whom and when.

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements placed on the EU market: connected hardware, software and components.

It covers the whole lifecycle: secure design, vulnerability handling, security updates during the support period and user information.

The application timeline

The regulation applies in stages. Two dates matter for manufacturers:

  • 11 September 2026: reporting obligations for actively exploited vulnerabilities and severe incidents affecting product security.
  • 11 December 2027: all essential requirements apply to products placed on the market.

Which products are in scope?

Any product whose intended use includes a direct or indirect data connection to a device or network: sensors and gateways, controllers, connected equipment and machines, software sold with or without hardware.

Some “important” or “critical” products face stricter conformity assessment. Others are already covered by specific sector rules. The first step is therefore to classify each product.

Manufacturer obligations

In practice, the manufacturer must:

  • Design and produce the product according to the essential cybersecurity requirements, based on a risk assessment.
  • Identify and document software components, notably through an SBOM.
  • Handle vulnerabilities without delay and provide security updates during the support period.
  • Set up a point of contact and a coordinated vulnerability disclosure policy.
  • Report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours.
  • Draw up the technical documentation and the declaration of conformity.

Reporting: what already applies

Since 11 September 2026, a manufacturer aware of an actively exploited vulnerability or a severe incident must send an early warning within 24 hours, then a notification within 72 hours, followed by a final report.

These deadlines require an organisation prepared in advance: product and component inventory, vulnerability monitoring, a decision path and a named contact.

Penalties

Non-compliance with the essential requirements can lead to fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Market surveillance authorities can also require products to be withdrawn or recalled.

How it fits with RED and the Machinery Regulation

For radio equipment, the RED directive has required cybersecurity since August 2025, based on the EN 18031 standards. For machinery, the Machinery Regulation, applicable on 20 January 2027, adds requirements on protecting control systems. One product can fall under several texts: the analysis should be done in one go.

Checklist

  • List your products with digital elements and classify them under the CRA
  • Appoint an owner and a point of contact for vulnerabilities
  • Produce an SBOM for each product and version
  • Monitor vulnerabilities in your components
  • Write and test the 24h / 72h reporting procedure
  • Check you can ship security updates over the whole support period
  • Run a gap analysis against the essential requirements
  • Plan design fixes before 11 December 2027

Information current as of 28 September 2026. Laws and timelines change: this guide is not legal advice.

Related servicesCyber Resilience Act compliance for your connected products

FAQ

Frequently asked questions

Does the CRA apply to products already sold?

Reporting obligations have applied since 11 September 2026 to products made available on the market. Essential requirements apply to products placed on the market from 11 December 2027.

Is open-source software in scope?

A manufacturer integrating open-source components into its product remains responsible for their security in that product. The regulation provides a specific regime for some open-source actors who do not commercialise the components.

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape