Cyber Resilience Act: the first reporting obligations apply since September 2026
The Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements. That means hardware and software that can connect to other devices or networks, from routers to industrial controllers to apps. Most obligations only apply from December 2027. The reporting obligations, however, have applied since September 11, 2026.
The timeline
- Dec 10, 2024
- The regulation enters into force.
- Jun 11, 2026
- The rules for the bodies that assess products apply.
- Sep 11, 2026
- The reporting obligations for actively exploited vulnerabilities and severe incidents apply.
- Dec 11, 2027
- All remaining obligations apply, such as security by design, security updates and CE marking.
Who the reporting obligations apply to
The obligations apply to manufacturers of such products, for all products they make available on the EU market, including those sold before the deadline. Anyone who sells a product under their own name or brand also counts as a manufacturer. Companies that buy in devices and sell them under their own name should therefore review the obligations carefully.
What has to be reported
Manufacturers must report actively exploited vulnerabilities in their products and severe incidents that affect the security of the product. Reports go through a central platform run by the EU agency ENISA to the competent national computer emergency response team.
- Within 24 hours of becoming aware: an early warning.
- Within 72 hours: a notification with the available information on the vulnerability or incident and on initial countermeasures.
- Final report: for vulnerabilities no later than 14 days after a fix is available, for severe incidents within one month.
Manufacturers must also inform the users of their products about the vulnerability or incident and about possible protective measures.
What manufacturers need now
To report within 24 hours, you first need to learn that a vulnerability is being exploited. That requires a defined process: a point of contact where researchers and customers can report vulnerabilities, someone who follows new security advisories for the components in use, and clear responsibility for the report itself, including at weekends.
Equally important is an overview of which software components are in which products. Only then can you quickly tell which products are affected when a new vulnerability in a library becomes known. From December 2027, the Cyber Resilience Act requires such an inventory anyway.
What comes in December 2027
- Security by design: products must meet the essential requirements of Annex I, such as secure default settings, protection against unauthorized access and the smallest possible attack surface.
- Vulnerability handling: manufacturers must handle vulnerabilities throughout the support period and provide security updates. The support period is generally at least five years.
- Software bill of materials: manufacturers must document which software components the product contains.
- Conformity and CE marking: compliance with the requirements is assessed and confirmed with the CE mark. For certain particularly important products, an assessment by an independent body is required.
Cyber Resilience Act and NIS2: the difference
Both address cybersecurity, but at different points. NIS2 governs how companies in certain sectors secure their own operations. The Cyber Resilience Act governs how secure the products placed on the market are. A manufacturer can therefore be affected by both: by NIS2 as a company and by the Cyber Resilience Act as a manufacturer.
How we can help
Our penetration tests cover not only infrastructure but also products and devices, before attackers find the weaknesses. Our Insights publish new warnings from sources such as CERT-Bund, BSI and CERT-EU every hour, and our newsletter delivers them daily or weekly if you prefer. And when it gets serious, our Instant Response team helps analyze and contain an incident.
This article is a general overview and not legal advice. The text of the regulation and the guidance of the competent authorities are authoritative.
FAQ
Frequently asked questions
Does the Cyber Resilience Act apply to pure software?
Yes, software also counts as a product with digital elements, such as a desktop application or an app. Pure cloud services are generally not covered as long as they are not part of a product as remote data processing. NIS2 is more relevant for them.
What about open-source software?
Free software developed and supplied outside a commercial activity is largely exempt. Anyone who builds open-source components into a product they sell is, as the manufacturer, responsible for the whole product.
What fines does the Cyber Resilience Act provide for?
For breaches of the essential requirements and the manufacturer obligations, which include the reporting obligations, up to EUR 15 million or 2.5 percent of worldwide annual turnover, whichever is higher.
Does it also affect distributors and importers?
Yes, to a lesser extent. Importers and distributors must, among other things, check that products carry the CE marking and that the required documentation is available. Anyone selling a product under their own name counts as the manufacturer.
What about products that have already been sold?
The reporting obligations apply to all products on the EU market, including older ones. The remaining requirements generally apply to products placed on the market from December 11, 2027.
Blog
More articles
neonotu at CES 2027 in Las Vegas
From January 6 to 9, 2027, we show Sightadel, veyrisk and Valar at booth 50123 in the Venetian Expo, with live demos and short …
Why continuous vulnerability management now belongs in every business
New vulnerabilities are published every week, and attackers look for systems that have not been updated yet. Why one scan a yea…
NIS2: who is affected, what it requires and what happens if you fail to comply
NIS2 extends IT security obligations to many mid-sized companies. An overview of who is affected, the obligations, fines and li…
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.