The Cyber Resilience Act reporting clock is about to start

Find out if it applies to you

| minute read
Could you report an exploited vulnerability in your connected product within 24 hours? From 11 September 2026, manufacturers in scope of the Cyber Resilience Act (CRA) will beare required to submit an early warning within that timeframe. Find out if you’re in scope of the regulation and what you need to do to get ready. 

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA) is an EU regulation introducing mandatory cybersecurity requirements for products with digital elements (PDEs) made available on the European Union market. 

It covers a broad range of hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, subject to certain exclusions. 

For manufacturers, the CRA makes cybersecurity a legal product requirement. From December 2027, products in scope will generally need to meet the CRA’s essential cybersecurity requirements before being placed on the EU market, with compliance forming part of the CE-marking process. 

Depending on the product and its cybersecurity risks, these requirements include secure-by-default configurations, appropriate protection of data through mechanisms such as encryption, and effective vulnerability handling. Where applicable, security updates should be provided automatically by default, while giving users the ability to opt out. 

What is the Cyber Resilience Act timeline?

The main CRA implementation dates are: 
  • 10 December 2024:The CRA entered into force. 
  • 11 June 2026:The provisions concerning notification of conformity assessment bodies became applicable. 
  • 11 September 2026: Mandatory reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of their products, beginning with an early warning within 24 hours. 
  • 11 December 2027:The CRA becomes fully applicable, including its essential cybersecurity requirements, conformity assessment, technical documentation and CE-marking requirements. 

What happens if you don’t comply with the CRA?

The CRA provides for significant administrative fines. Non-compliance with the essential cybersecurity requirements in Annex I or manufacturers’ obligations under Articles 13 and 14 can result in fines of up to €15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. 

Other categories of infringement are subject to different maximum penalties, and the Regulation includes specific provisions affecting the imposition of fines, including for micro and small enterprises and open-source software stewards. 

For manufacturers selling products with digital elements in the EU, understanding whether the CRA applies — and preparing for the first reporting obligations from September 2026 — should therefore be a priority. 

Am I in scope of the CRA?

As a practical starting point, consider three questions: 
  • Is it a “product with digital elements”? 
  • This can include software or hardware products and their remote data processing solutions, as well as certain software or hardware components placed on the market separately. 
  • Is it made available on the EU market in the course of a commercial activity? 
  • Does its intended or reasonably foreseeable use include a direct or indirect logical or physical data connection to a device or network? 
The CRA applies regardless of where an in-scope product is manufactured. Obligations vary across manufacturers, importers and distributors, with manufacturers carrying the primary responsibility for ensuring that products they place on the market under their name or trademark comply with the Regulation. 

What does this look like in manufacturing and heavy industry?

Some products are obviously connected — for instance, smart watches and smart-home devices. In manufacturing and industrial environments, the answer can be less obvious. 
Depending on their functionality and how they are placed on the market, examples of products that may fall within scope include: 
  • Connected sensors and monitoring equipment 
  • Programmable logic controllers and other industrial control components 
  • Software and firmware incorporated into connected machinery or supplied separately 
A network connection — including an indirect connection — is therefore an important indicator that the CRA may apply. But connectivity alone is not enough to determine scope: the CRA's definitions, commercial-activity requirement and exclusions also need to be considered. 

Are any products excluded from the CRA?

Yes. The CRA contains several specific exclusions and special regimes. 
For example, it does not apply to products with digital elements to which certain existing EU legislation applies, including: 
  • Medical devices covered by Regulation (EU) 2017/745 and in vitro diagnostic medical devices covered by Regulation (EU) 2017/746 
  • Certain motor vehicle products covered by Regulation (EU) 2019/2144 
  • Certain products certified in accordance with EU civil aviation legislation 
  • Marine equipment falling within the scope of Directive 2014/90/EU 

The CRA also does not apply to products developed or modified exclusively for national security or defence purposes, or to products specifically designed to process classified information. 

Free and open-source software developed or supplied outside the course of a commercial activity is also treated differently under the CRA. 

Scope should therefore be assessed product by product rather than on connectivity alone. 

What do I have to do if I’m in scope – and by what deadline?

The CRA creates a number of obligations for manufacturers. Most become applicable in December 2027, while the Article 14 reporting obligations start earlier, on 11 September 2026. 

Getting ahead of the later requirements now can reduce the amount of work needed as the full application date approaches. 

1. Carry out a cybersecurity risk assessment

Applicable from 11 December 2027 

Manufacturers must undertake a cybersecurity risk assessment for products with digital elements and take the outcome into account during the planning, design, development, production, delivery and maintenance phases of the product. 

The product must meet the applicable essential cybersecurity requirements set out in Annex I of the CRA. Harmonised standards and other recognised conformity mechanisms may help manufacturers demonstrate compliance. 

Manufacturers must also prepare the required technical documentation and carry out the applicable conformity assessment procedure. 

The appropriate procedure depends partly on the product's classification and on how the manufacturer demonstrates conformity. Certain important and critical products are subject to more stringent conformity assessment requirements. 

2. Complete the required conformity documentation and CE marking

Applicable from 11 December 2027 

Before placing a product on the market, manufacturers will generally need to complete the applicable conformity assessment process and provide the required documentation and information. 

This includes, where applicable: 

  • The CE marking 
  • An EU declaration of conformity 
  • Information about the product's support period 
  • Information and instructions enabling secure installation, operation and use of the product 
Manufacturers must also maintain the technical documentation required by the CRA. 

3. Be ready to report actively exploited vulnerabilities and severe security incidents 

Mandatory from 11 September 2026 
This is the first major CRA obligation that manufacturers need to prepare for. 
From 11 September 2026, manufacturers must report through the CRA's Single Reporting Platform when they become aware of: 
  • An actively exploited vulnerability contained in a product with digital elements 
  • A severe incident having an impact on the security of a product with digital elements 
The reporting process begins with an early warning within 24 hoursof the manufacturer becoming aware of the vulnerability or incident. 
For an actively exploited vulnerability, the manufacturer must then provide: 
  • Within 24 hours: An early warning containing the information required by the CRA 
  • Within 72 hours: A vulnerability notification providing available general information about the product concerned, the general nature of the exploit and vulnerability, and any corrective or mitigating measures taken 
  • Within 14 days after a corrective or mitigating measure is available: A final report containing, where applicable, information about the vulnerability, its severity and impact, information about any malicious actor that exploited or is exploiting it, and details of the corrective or mitigating measures made available 
For a severe incident having an impact on the security of the product, the process is slightly different: 
  • Within 24 hours: An early warning 
  • Within 72 hours: An incident notification containing available general information about the nature of the incident, an initial assessment and any corrective or mitigating measures taken 
  • Within one month of the 72-hour incident notification: A final report containing a detailed description of the incident, including its severity and impact, the type of threat or root cause likely to have triggered it, and the mitigation measures applied and ongoing 

Reporting will take place through the Single Reporting Platform established by ENISA. Reports are directed to the CSIRT designated as coordinator for the purposes of the CRA, with ENISA also playing a central role in the reporting infrastructure. 

This means manufacturers need the processes and data visibility required to determine quickly what happened, which products and versions are affected, what the security impact is and what mitigating action has been taken. 

The challenge is not simply meeting a 24-hour deadline. It is being able to assemble reliable information quickly enough to make that deadline meaningful. 

4 questions for in-scope manufacturers to answer this week

If your products are likely to be in scope of the CRA but you're not sure whether your operational readiness can keep up with the regulation, here are four questions to ask: 
  • Do you have a specific contact or team responsible for CRA vulnerability and incident reporting through the Single Reporting Platform? 
  • Do you have sufficient visibility of your product's components — for example through an SBOM and related product records — to determine quickly which products and versions are affected when a vulnerability emerges? 
  • Is your existing incident and vulnerability response process capable of supporting a 24-hour early-warning deadline? 
  • Do your supply-chain arrangements give you timely access to information about vulnerabilities affecting third-party components used in your products? 
If you answered “no” or “not sure” to any of the above, you have identified a useful starting point for CRA readiness. 
With the first reporting obligations applying from 11 September 2026, the time to establish these processes is now. 

Make sure you’re ready to report when a vulnerability or severe security incident occurs – talk to one of our experts

Sopra Steria is a top-five tech player in Europe, advising manufacturers of all sizes on how to digitally transform their operations and create compliant, future-fit systems. We bring together regulatory rigour, digital expertise and an unwavering commitment to digital excellence.  
Search

cybersecurity

Related content

AI and cybersecurity

In today’s digital age, traditional cybersecurity measures are no longer sufficient. Cyber threats are evolving rapidly, and adopting innovative solutions is essential to protect your business. Discover how AI is revolutionizing cybersecurity and giving you a strategic edge. 

The Reliable Government

Transforming public services for a citizen-centric future: robust, agile, effective, and connected. Discover how modernizing IT systems and fostering digital skills can transform government services.