EU Cyber Resilience Act: reporting since September 2026, CE rules from 2027
The Cyber Resilience Act covers hardware and software products with digital elements sold in the EU. Manufacturers have had to report actively exploited vulnerabilities and severe incidents since 11 September 2026, and from 11 December 2027 products must meet the cybersecurity essential requirements, carry the CE marking and come with a declared support period. Importers and distributors must check this before selling.
Checked against official sources: 2026-10
At a glance
Scope and conformity assessment
The CRA applies to hardware and software products with digital elements made available on the EU market, including remote data processing solutions and components placed on the market separately, when their intended or reasonably foreseeable use includes a direct or indirect data connection. Products not supplied in a commercial activity are not covered, and some products covered by other EU legislation are excluded.
Most products can use self-assessment (internal control, module A). Important Class I products can self-assess only if harmonised standards, common specifications or a European cybersecurity certification scheme were applied; otherwise a notified body is needed. Important Class II and critical products need a third-party assessment or a certification scheme. Using harmonised standards gives a presumption of conformity.
Manufacturer obligations
- Carry out a cybersecurity risk assessment and meet the essential requirements in Annex I, including vulnerability handling during the support period.
- Exercise due diligence on integrated third-party components.
- Keep the technical documentation available to market surveillance authorities.
- Give identification and contact details and user information under Annex II, including the end date of the support period (month and year) at the time of purchase.
- Draw up the EU declaration of conformity and affix the CE marking before placing the product on the market.
- Report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, and a final report within 14 days after a fix is available (vulnerabilities) or within one month (severe incidents).
Importers, distributors and the timeline
Importers must check that the manufacturer has carried out the conformity assessment, that the technical documentation exists and that the product carries the CE marking, and must not place non-compliant products on the market. Distributors must check the CE marking and the manufacturer's and importer's information, including the support period. Both must tell the manufacturer about vulnerabilities and cooperate with the authorities. A manufacturer can appoint an authorised representative by written mandate.
The reporting obligations apply from 11 September 2026, also to products already on the market. The main provisions apply from 11 December 2027; products already on the market are covered only if they are substantially modified after that date. Existing EU type-examination certificates on cybersecurity expire on 11 June 2028 unless they lapse earlier. Penalties are set by each Member State, and micro and small enterprises may not be fined for missing the 24-hour deadline.
Step by step
- Check whether your hardware or software is a product with digital elements with a data connection, and whether it falls under Annex III (important) or Annex IV (critical).
- Set up vulnerability handling and reporting through the CRA Single Reporting Platform, since reporting has applied since 11 September 2026.
- Carry out the cybersecurity risk assessment and design the product to meet the Annex I essential requirements before 11 December 2027.
- Choose the conformity assessment route: self-assessment, harmonised standards or a notified body, depending on the category.
- Prepare the technical documentation, user information with the support period, the EU declaration of conformity and the CE marking.
- Give your EU importer and distributors the information they must check.
Documents you usually need
- Cybersecurity risk assessment
- Technical documentation
- User information and instructions (Annex II), including the support period end date
- EU declaration of conformity
- Notified body certificate for important Class II and critical products, or Class I without standards
- Vulnerability and incident reports through the CRA Single Reporting Platform
Common problems and how to avoid them
What to do: Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026, including for products already on the market.
What to do: Without harmonised standards, common specifications or a certification scheme, a notified body assessment is needed.
What to do: The support period end date (month and year) must be specified at the time of purchase.
What to do: Importers must check the conformity assessment, technical documentation and CE marking before placing the product on the market.
Sources
- The Cyber Resilience Act - Summary of the legislative text European Commission
- Regulation (EU) 2024/2847 of the European Parliament and of the Council EUR-Lex
Rules change often. This note is practical guidance based on the sources above, not legal advice. Confirm current requirements with the authority, your importer or a licensed customs broker before you ship.
Trade notes
Common questions
What is the Cyber Resilience Act?
Regulation (EU) 2024/2847, which sets cybersecurity requirements for hardware and software products with digital elements sold in the EU.
When does the CRA apply?
It entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026 and the main provisions from 11 December 2027.
What must be reported and how fast?
Actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours and a final report later, through ENISA's CRA Single Reporting Platform.
Do all products need a notified body?
No. Most products can self-assess. Important Class I products need harmonised standards or a notified body, and Class II and critical products need third-party assessment or certification.
Does the CRA apply to products already on the market?
The reporting obligations do. The other requirements apply to them only if they are substantially modified after 11 December 2027.
More free tools
Triplicate is free and keeps getting better. Found it useful? Support Triplicate ♥
Prefer no ads? Pro removes all ads · $1/month