Cyber Resilience Act: Europe Puts Product Security on the Clock

August 12, 2026

From 11 September 2026, manufacturers of connected hardware and software will face binding EU reporting duties for actively exploited vulnerabilities and severe security incidents. The significance of the Cyber Resilience Act goes well beyond a 24-hour deadline: it makes cybersecurity a matter of product governance, lifecycle responsibility and market access.

Europe is about to put product cybersecurity on a regulatory clock. From 11 September 2026, manufacturers of products with digital elements will have to report certain actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA). The timing is significant because most of the regulation’s wider obligations will not become fully applicable until 11 December 2027. Reporting comes first. Companies therefore have to build the organisational machinery of compliance before the CRA’s broader product-security regime is fully in force.

That sequence says much about the logic of the legislation. Europe is no longer treating cybersecurity as a desirable technical feature that manufacturers may choose to improve. It is becoming a regulated characteristic of products sold into the European market. Manufacturers will be expected not only to design secure products, but also to monitor vulnerabilities, assess incidents, document decisions and communicate with authorities at speed. Practical guidance published by the European Commission on 27 July 2026 gives companies additional orientation, but it also highlights how little time remains to test whether existing incident-response structures are ready for the new regime.

Security Becomes a Lifecycle Obligation

The Cyber Resilience Act applies broadly to hardware and software products with digital elements whose intended or reasonably foreseeable use involves a direct or indirect logical or physical connection to a device or network. Its scope can therefore include connected equipment, software products and separately marketed digital components. The underlying principle is straightforward: cybersecurity should not begin when a vulnerability is exploited. It should be built into planning, design, development, production and maintenance, and remain part of the manufacturer’s responsibility throughout the relevant product lifecycle.

This is the more consequential regulatory shift. Cybersecurity has traditionally been handled by many companies primarily as an IT or operational-security issue. Under the CRA, it becomes part of product compliance. Manufacturers must conduct cybersecurity risk assessments, consider the security implications of third-party components and reflect their decisions in technical documentation. They must also establish support periods during which vulnerabilities are effectively handled and make the end of those periods clear to customers at the time of purchase. In regulatory terms, a connected product is no longer secure simply because it was secure when it left the factory.

The reporting regime also reaches beyond new product launches. Products already placed on the EU market can remain relevant if they continue to be made available. For legacy products, the decisive question is therefore not when they first entered the market, but whether they are still being supplied in the EU. Manufacturers will need to look beyond current product generations and include older hardware and software that remains commercially available or supported. In practice, CRA exposure may extend across years of product history, including systems designed long before the regulation was adopted.

Twenty-Four Hours Changes Incident Response

The immediate pressure comes from time. Once a manufacturer becomes aware of an actively exploited vulnerability or a severe security incident within the meaning of the CRA, an early warning may have to be submitted within 24 hours. A more detailed notification follows within 72 hours. For actively exploited vulnerabilities, a final report is due no later than 14 days after a corrective or mitigating measure becomes available; for severe security incidents, the final report must be submitted within one month of the 72-hour notification.

Those deadlines do more than accelerate reporting. They change how organisations have to investigate cyber incidents. A sequential model — security investigates first, legal reviews later, management decides at the end — is unlikely to work when the regulatory clock is already running. Technical investigation and legal assessment must proceed in parallel. Within hours, a company may need to establish whether a vulnerability is merely theoretically exploitable or whether credible evidence shows that attackers are already using it; whether an incident has affected, or could affect, the availability, authenticity, integrity or confidentiality of important data or functions; and whether malicious code has been introduced or executed. The CRA therefore forces cybersecurity, product engineering, incident response, compliance and legal teams into a much tighter operating model.

This makes governance as important as technology. A manufacturer may employ excellent security engineers and still fail operationally if no one knows who is authorised to classify an incident, trigger escalation or submit a regulatory notification outside normal business hours. Companies should establish in advance who receives vulnerability reports, who assesses evidence of exploitation, who determines whether an incident meets the statutory threshold, who communicates with regulators and who records the reasoning behind each decision. Under a 24-hour reporting regime, organisational ambiguity becomes a cybersecurity risk of its own.

Reporting Across Europe Requires Advance Planning

Notifications are to be channelled through the CRA Single Reporting Platform, which is intended to be operational by 11 September 2026. The process involves the relevant national Computer Security Incident Response Team, or CSIRT, together with the European Union Agency for Cybersecurity, ENISA. For manufacturers established in the EU, the competent CSIRT is linked to the company’s main establishment — the place in the Union where decisions concerning the cybersecurity of products with digital elements are predominantly taken. That is not necessarily the registered office, the headquarters or the largest physical site, an important distinction for multinational groups whose engineering, security and management functions may be distributed across several countries.

Manufacturers without a main establishment in the Union face a statutory fallback hierarchy. Responsibility may be determined by the location of the authorised representative, then the importer, then the distributor and, if none of these criteria resolves the issue, by the member state in which the largest number of users of the product is located. International companies should settle this question before an incident occurs. A 24-hour deadline leaves little room to begin debating jurisdiction after exploitation has already been detected. The same is true of the reporting platform itself: credentials, internal authorisations and reporting procedures should be tested before they are needed in a live event.

The regulation also extends beyond manufacturers. Importers must, among other things, check whether required conformity procedures have been carried out, whether technical documentation exists and whether the product bears the necessary CE marking. Distributors have their own verification and cooperation duties, including forwarding relevant vulnerability information to manufacturers. The CRA is therefore not simply a software-development law. It affects the wider chain through which connected products enter and remain on the European market.

Vulnerability Management Becomes Evidence-Based Compliance

Perhaps the most important long-term effect of the CRA is that vulnerability management moves from an internal security discipline into a process that may have to withstand regulatory scrutiny. Companies need to know when they became aware of a problem, how it was assessed, what evidence supported the classification and when corrective measures became available. This is particularly important for actively exploited vulnerabilities, because the legal concept requires credible evidence of actual exploitation rather than a merely theoretical attack path. Documentation is therefore no longer an administrative afterthought. It becomes part of the security process itself.

The organisational implications are broad. Product teams need reliable inventories of affected products and components. Security teams need structured processes for vulnerability intake, triage and escalation. Legal and compliance functions need sufficient technical understanding to assess reporting thresholds. Management needs to know when decisions require executive involvement. Procurement teams require visibility over third-party components capable of weakening the security of the final product. And companies need an audit trail robust enough to explain, potentially months later, why a notification was or was not made.

The European Commission’s July guidance is useful precisely because it helps translate a complex regulation into operational questions. It does not, however, replace the CRA and is not independently legally binding. Companies should use it as an implementation aid, not as a substitute for legal analysis. Its practical value lies elsewhere: organisations now have a current European reference against which they can test their own interpretation and internal processes immediately before the first reporting obligations become applicable.

September Is Only the First Milestone

The September deadline should not obscure the much larger transition that follows. From 11 December 2027, the CRA’s wider requirements will generally become applicable. These include obligations concerning secure development, cybersecurity risk assessment, vulnerability management, technical documentation and conformity assessment. Certain categories of important and critical products may face additional requirements and, depending on the applicable classification and procedure, assessment by an independent notified body. September 2026 should therefore be treated as the first operational milestone in a much broader compliance programme rather than as a standalone reporting project.

Between now and then, manufacturers need to map affected products, include relevant legacy systems, establish clear ownership of CRA compliance, review incident-response and vulnerability-management processes, define the evidence required to distinguish active exploitation from theoretical risk, determine the competent CSIRT and prepare communication with ENISA. The 24-hour and 72-hour deadlines must be built into escalation procedures. Support periods, suppliers, third-party components and technical documentation need to be reviewed as part of preparations for 2027. Above all, companies need to know when the reporting clock starts. If an organisation cannot reliably establish when it first became aware of an event, compliance with a time-based reporting regime becomes difficult from the outset.

The broader significance of the Cyber Resilience Act lies here. Europe is moving product cybersecurity from recommended best practice into enforceable corporate responsibility. Manufacturers will still need strong technical defences, but technical competence alone will no longer be enough. They will have to demonstrate that vulnerabilities are monitored throughout the product lifecycle, that incidents are assessed consistently, that responsibility is clearly allocated and that the organisation can communicate with regulators within hours when necessary.

From 11 September 2026, the question for manufacturers is therefore no longer simply whether their products are secure. It is whether their organisations are capable of recognising insecurity, understanding its significance and acting on it quickly enough to satisfy a regulatory regime built around continuous accountability.

That is the deeper change introduced by the CRA. Cybersecurity becomes not merely a product feature, but a measurable element of governance, compliance and access to the European market.

SBS Legal advises companies on the implementation of new regulatory requirements and supports organisations in the legal assessment of cybersecurity and compliance issues. In the context of the Cyber Resilience Act, an early review of affected products, vulnerability-management procedures and internal reporting structures can help identify regulatory risks and prepare organisations for both the reporting duties beginning on 11 September 2026 and the broader CRA regime taking effect in December 2027.

Related Articles

Germany’s Security Paradox: Excellent at Rules, Slow at Results

Viewed from outside, Germany presents a curious contradiction. Few countries take standards, procedures and institutional safeguards more seriously. Yet in security, infrastructure and public administration, the machinery designed to prevent mistakes can itself become...

Drone defence starts with situational awareness

From power plants and airports to logistics hubs and industrial sites, Europe’s critical infrastructure is facing a new security dimension above the conventional perimeter. A visit by former German Federal Transport Minister Patrick Schnieder to LivEye’s Drone...

Share This