The European Cyber Resilience Act (CRA) introduces a significant regulatory change in cybersecurity for a wide range of products with digital elements—ranging from smart devices and security cameras to mobile applications and certain software. For manufacturers, importers, and distributors of these products, this means new obligations. Although most requirements under the CRA will only become applicable in late 2027, some of the initial obligations—specifically reporting actively exploited vulnerabilities and severe security incidents—will apply as early as September 11, 2026.
What Does the Cyber Resilience Act Apply To (and What Does It Exclude)?
The regulation applies to products with digital elements, meaning software or hardware products and their remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to another device or network. Obligations under the CRA primarily concern manufacturers, but to a certain extent also importers and distributors, regardless of where they are established. The decisive factor is whether the product is placed on the EU market. The aim of the regulation is to enhance the cybersecurity of products with digital elements and establish rules ensuring that manufacturers account for security throughout the entire product lifecycle, including the design and development phase.
However, not every software or digital service automatically falls within the scope of the CRA.
Products typically excluded from the CRA regime include:
- Web applications, progressive web applications, or websites accessible solely via a web browser that do not constitute a product with digital elements in themselves;
- Software as a Service (SaaS), Platform as a Service (PaaS), and other cloud solutions, unless they are remote data processing solutions integral to a product with digital elements;
- Open-source and free software developed outside commercial activity, provided it is not commercially monetized.
Similarly, not all electronic products fall under the CRA. The decisive factor is whether the product processes, stores, or transmits digital data and has a relevant data connection. Consequently, simple devices without such connectivity—such as standard electronic toys or home appliances with firmware intended solely for basic functions—will generally fall outside the scope of the CRA.
Incident and Vulnerability Reporting
Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities contained in products with digital elements and severe security incidents impacting their security. Reporting obligations also apply to products already placed on the market. Under the CRA, manufacturers must report in particular:
a) Actively exploited vulnerabilities: vulnerabilities (defects or reduced resilience) for which there is reliable information indicating that they have actually been exploited in a cyberattack; and
b) Severe security incidents: incidents that have an impact on the security of the product with digital elements.
In practice, this will cover situations such as a manufacturer learning about active exploitation of firmware in a network router or unauthorized access to user accounts in a mobile app. Conversely, a product flaw that could theoretically enable a cyberattack but was identified during pre-market testing and has not yet been actively exploited generally does not need to be reported through this procedure.
Manufacturers must report every actively exploited vulnerability and every severe security incident of which they become aware via the single European platform. The notification is submitted to the competent Computer Security Incident Response Team (CSIRT) designated as a coordinator in the Member State where the manufacturer has its main establishment, and is simultaneously made accessible to the European Union Agency for Cybersecurity (ENISA). Very tight deadlines apply to reporting, calculated from the moment the manufacturer obtains a sufficient degree of certainty that it is a reportable vulnerability or incident:
- Early warning of an actively exploited vulnerability or severe security incident—within 24 hours;
- Detailed notification of the vulnerability or incident—within 72 hours;
- Final report—within 14 days of the availability of a corrective or mitigating measure for vulnerabilities, or within 1 month of submitting the notification for severe security incidents.
The CRA does not prescribe a specific method for how manufacturers must learn about a vulnerability or incident. Information may be obtained, for example, from a customer, a national cybersecurity authority, an ethical hacker, a component supplier, or from internal monitoring. In practice, products with digital elements often consist of multiple components from various suppliers. Ultimate responsibility for submitting the notification rests with the final product manufacturer, even if the root cause of the vulnerability lies in a third-party component. At the same time, the manufacturer should inform the supplier of the affected component so that corrective measures can be taken.
In addition to manufacturers, importers and distributors can also contribute to enhancing the cybersecurity of products with digital elements. Their obligations are narrower, consisting primarily of verifying that the manufacturer has met the basic CRA requirements, that the appropriate marking and documentation are attached to the product, and that in the event of non-compliance, they will not place or supply the product on the market until remedied.
Besides communicating with public authorities, the CRA also obliges manufacturers to inform affected product users—or all users, if applicable—about identified actively exploited vulnerabilities or severe security incidents and provide them with information on measures they can take to mitigate risks.
Practical Recommendations
The greatest practical challenge will not be the submission of the report itself, but the ability to timely identify, assess, and escalate an event to meet statutory deadlines. Achieving this requires properly established internal processes and clearly defined responsibilities regarding:
- Who is responsible for evaluating security events;
- Who decides whether an event constitutes a reportable vulnerability or incident;
- Who communicates with the competent authorities;
- Who prepares the notifications; and
- Who informs customers and business partners.
Given the entry into force of these reporting obligations, we particularly recommend:
- Reviewing which products in your portfolio fall within the scope of the CRA;
- Establishing an internal process for the identification and escalation of security incidents;
- Designating individuals responsible for individual reporting steps;
- Verifying whether contracts with suppliers allow for the timely sharing of vulnerability information;
- Preparing communication procedures for customers and product users.
The ability to rapidly identify and correctly qualify an incident or vulnerability is a key condition for compliance with the CRA as of September 2026. This is not merely a regulatory formality; failure to comply with reporting obligations can lead to significant sanctions—fines of up to EUR 15 million or 2.5% of the undertaking's total worldwide annual turnover, whichever is higher.
This text was translated by AI.