Skip to content
Braincap
← All articles

The Cyber Resilience Act: security becomes mandatory for digital products in the EU, and it has already started

by Claudiu Hulea · IT Management Consultant

Illustration: the Cyber Resilience Act timeline, with the reporting obligation in force on 11 September 2026 and the main obligations on 11 December 2027

The Cyber Resilience Act makes cybersecurity mandatory by law for any product with digital elements placed on the European Union market. It is not a rule only for large technology companies: it catches you if you sell connected software or hardware in the EU, whatever your size. The first obligation already took effect on 11 September 2026, and the bulk of the requirements arrives on 11 December 2027. In other words, the clock has started.

What the CRA is and who it catches

The Cyber Resilience Act is Regulation (EU) 2024/2847, in force since 10 December 2024. It is the first European law that requires cybersecurity for “products with digital elements”, meaning any connected hardware or software placed on the EU market, including the remote data processing linked to it.

It catches manufacturers, importers and distributors alike. It does not matter whether you are a corporation or a small Romanian company selling an app, a device or a software component in the EU. If your product has digital elements and reaches the European market, the CRA applies to you.

The timeline: two dates that matter

11 September 2026, already in force. The reporting obligation. An actively exploited vulnerability or a severe incident affecting product security is reported to the national CSIRT and ENISA, through the CRA Single Reporting Platform, with an early warning within 24 hours and a full notification within 72 hours. Importantly, this applies even to products already on the market, not only future ones.

11 December 2027, the main obligations. The essential security requirements, the conformity assessment and CE marking. From that date, a product with digital elements cannot be legally placed on the EU market without meeting them.

What it requires, concretely

The main obligations are not a form, but a way of building and maintaining the product:

  • Security by design. Security goes into the design from the start, it is not added at the end.
  • Vulnerability handling. A process for handling and coordinated disclosure of vulnerabilities, throughout the support period.
  • SBOM. A machine-readable software bill of materials that says what the product is made of.
  • Security updates. Delivered over the product’s expected support period, not just in the first year.
  • CE marking. After a conformity assessment, a declaration of conformity and technical documentation.

Product classes: how hard it is depends on risk

The CRA splits products by risk level, and the rigour of the assessment rises with the class.

  • Default, around 90% of products: self-assessment, a declaration of conformity and technical documentation.
  • Important (classes I and II): conformity through harmonised standards or a notified body.
  • Critical: mandatory certification.

The first practical step is to know which class your product falls into, because the whole effort follows from there.

What is at stake

Fines reach up to 15 million euros or 2.5% of global annual turnover, whichever is higher, for breaching the essential requirements or the reporting obligations. Beyond the fine, the commercial consequence is more direct: without CE marking, the product cannot be legally placed on the EU market.

For open source, the regulation is more nuanced. Software developed outside a commercial activity is largely out of scope, and organisations that maintain OSS projects used in commercial products have a lighter set of obligations, centred on security policy and vulnerability handling.

What to do now, even if 2027 feels far off

  • Inventory which products with digital elements you place on the EU market and determine which class they fall into.
  • Start an SBOM and a vulnerability handling and disclosure process now, not in 2027.
  • Define each product’s support period and how you deliver updates across it.
  • If you already have products on the market, the 24-hour and 72-hour reporting obligation applies to you already. Make sure you know how and where to report, through the Single Reporting Platform.

What to take away

The CRA and a standard like ISO/IEC 27001 do not substitute for each other: 27001 is the security of the process and the organisation, the CRA is the security of the product you place on the market. A mature management system, with an asset inventory, vulnerability handling and incident response, gives you part of the foundation the CRA asks for at the product level, but it does not exempt you from the product requirements.

The underlying principle, though, is the same as everywhere: security is not an audit passed once, but an effect maintained across the product’s whole lifetime. The CRA writes that into law. Verify the effect, not the checkbox.

Want to know whether your products fall under the CRA, which class they are in and what to prepare by 2027? Get in touch and we start from a review.

Sources

Frequently asked questions

What is the Cyber Resilience Act?

Regulation (EU) 2024/2847, in force since 10 December 2024. It is the first European law that imposes mandatory cybersecurity requirements on any product with digital elements placed on the EU market, meaning connected hardware and software, including related remote data processing. It requires security by design, vulnerability handling, an SBOM, security updates over the support period and CE marking after a conformity assessment.

Who does it catch and from when?

Manufacturers, importers and distributors of products with digital elements sold in the EU, not just large technology companies. The timeline has two dates: the obligation to report actively exploited vulnerabilities and severe incidents applies from 11 September 2026 (already), and the main obligations, including CE marking, from 11 December 2027.

What must be reported and how fast?

From 11 September 2026, an actively exploited vulnerability or a severe incident affecting product security is reported to the national CSIRT and ENISA through the CRA Single Reporting Platform: an early warning within 24 hours and a full notification within 72 hours. The obligation applies even to products placed on the market before 2027.

What is the risk of non-compliance?

Fines of up to 15 million euros or 2.5% of global annual turnover, whichever is higher, for breaching the essential requirements or the reporting obligations. On top of that, without CE marking you cannot legally place the product on the EU market. Non-commercial open-source software is largely out of scope, and organisations that maintain OSS have a lighter regime.

Related articles