The Cyber Resilience Act: Obligations, deadlines and responsibilities for businesses
On Monday morning, the security team sent a message: one of your software products has a vulnerability, and it is already being actively exploited. It is not just about how quickly a fix is available. From 11 September 2026, there will be another thing to think about: is there a need to report the vulnerability under the Cyber Resilience Act (CRA)?
However, the CRA has wider implications for your day-to-day business operations. The key factor is the role your organisation plays and the obligations that arise from it.
Article overview:
The Cyber Resilience Act: What will change from September 2026?
Which products and companies will be affected by the CRA?
Manufacturers' obligations: Cybersecurity does not end with the launch
Import and trade: When do your responsibilities increase?
Private label: When your own logo changes the game
Reporting obligations: Why 24 hours can be quite a short time
CRA breaches: What fines might you face?
CRA and liability: When an obligation becomes a financial risk
The Cyber Resilience Act: What will change from September 2026?
The requirements under the CRA will come into force in stages. The reporting obligations for manufacturers will take effect on 11 September 2026, while the CRA will be fully applicable from 11 December 2027.
If you leave it until then to start preparing, it will be too late. This is because companies must clarify in advance which of their products are affected, what role these products play in this context, and which members of staff are responsible for security, support and reporting.
Which products and companies will be affected by the CRA?
The CRA applies to products containing digital elements that are made available on the EU market. This includes products that are directly or indirectly connected to, or intended for use with, a device or network. This includes, for example:
- software
- hardware
- connected devices and
- separately marketed components.
However, please note that 'digital' does not automatically mean that the CRA applies. There are exceptions and special rules for certain product groups. If your product falls within the CRA's scope, the next question is what role your company plays. The CRA distinguishes between three main roles:
- Manufacturers either develop products themselves or commission their development, bringing them to market under their own name or brand.
- Importers are companies based in the EU that bring a manufacturer’s products onto the EU market. The manufacturer itself is not based in the EU.
- Distributors supply products within the supply chain without being manufacturers or importers themselves.
At first glance, these seem like clearly distinct categories. In practice, however, your role can change quickly. For example, if you make a 'substantial modification' to the firmware of a connected product before reselling it, you may be regarded as a manufacturer, even though you originally acted solely as a retailer. Therefore, you should be aware of the obligations associated with this role.
Manufacturers' obligations: Cybersecurity does not end with the launch
The software has been developed, tested and released. Is the project complete? Not from the CRA’s point of view. Manufacturers must consider cyber security throughout the product lifecycle. This includes, among other things,
- risk assessment,
- safe product design,
- technical documentation,
- information and instructions for safe use,
- conformity assessment procedures and
- CE marking.
The practical implications of „secure product design“ depend on the specific risk involved. Among other things, the CRA requires the prevention of unauthorised access and the protection of stored or transmitted data. Essential functions must also remain available following a security incident.
However, the conformity assessment process is not the same for every product. While self-assessment is possible for many products, stricter procedures apply to important and critical products, some of which require the involvement of an independent third party.
The process continues after launch. Manufacturers must address vulnerabilities throughout the specified support period. This period is based on the expected lifespan of the product and is generally at least five years. Security updates must promptly resolve vulnerabilities and, as a rule, be available free of charge.
Cybersecurity is therefore evolving from a one-off project into an ongoing task.
As a manufacturer, it is not enough to simply monitor your own development. Security vulnerabilities can also be found in components supplied by third parties or integrated applications. Companies therefore need clear answers to questions such as:
- Who monitors new security issues?
- Who assesses them?
- Who deals with patches?
- And in an emergency, who decides whether a report is necessary?
If you only start to sort things out once a security incident has occurred, you’ll lose valuable time.
Import and trade: When do your responsibilities increase?
The purchasing department has found an attractive, connected product. The price is right and the delivery time is suitable. However, the manufacturer is based outside the EU. Should you simply order the product and resell it? Before doing so, ask yourself what responsibilities you would take on by importing it.
This is because, if you place a product on the EU market that falls under the CRA and originates from outside the EU, you may be regarded as an importer. This gives rise to separate verification obligations. These include checking that the manufacturer has complied with the relevant requirements, that the necessary documentation is available and that the prescribed labelling is correct.
Even if you purchase products within the EU as a retailer, you are not automatically exempt. You must check the details, labelling and information on the products concerned. If you have reasonable concerns that a product does not meet CRA requirements, you can only resell it once these requirements have been met. Therefore, the CRA directly impacts specific aspects of day-to-day business.
- in purchasing,
- during product range reviews,
- in product data and
- in supplier selection.
In future, it will be important not only to ask, „Can the supplier deliver?“, but also: „Can they provide the information, documentation and security updates that you will need later on?“
Private label: When your own logo changes the game
The question of roles is particularly relevant in the private label sector. Here is a classic scenario: you source a connected product from another supplier. You do not make any technical changes. However, your brand name then appears on the product and its packaging.
From a marketing perspective, this constitutes a private label. However, from a CRA perspective, this can quickly lead to manufacturer liability. This is because, by placing an affected product on the market under your own name or brand, you may be regarded as the manufacturer. This entails correspondingly broader obligations.
This raises an important question for companies: Are we currently changing our branding, or perhaps our CRA role as well?
Reporting obligations: Why 24 hours can be quite a short time
Now, let's revisit the scenario we outlined at the beginning. The security team has confirmed that the vulnerability is indeed being exploited. You now have two tasks to tackle simultaneously. First, you must take technical action. Second, you must check whether there is a legal obligation to report this to the CRA. From 11 September 2026 onwards, manufacturers must report any
- vulnerabilities being exploited, and
- serious security incidents affecting product safety.
The following deadlines apply to events that are subject to mandatory reporting:
- Within 24 hours: initial report.
- Within 72 hours: a more detailed report.
- In the case of actively exploited vulnerabilities, the final report must be provided no later than 14 days after a corrective measure becomes available.
- In the case of serious security incidents, the final report must be provided no later than one month after the 72-hour report.
From 11 September 2026, the Single Reporting Platform (SRP), operated by the EU Cybersecurity Agency (ENISA), will be the central point of contact for reporting. However, simply reporting to the authorities is not always enough. Manufacturers must also inform users about actively exploited vulnerabilities or serious security incidents.
Please note that the reporting obligations come into force earlier than most other CRA requirements. These obligations also apply to products placed on the market before 11 December 2027. The other CRA requirements generally only apply to such products if they undergo significant changes on or after that date.
CRA breaches: What fines might you face?
From 11 December 2027, if you breach key obligations under the Cyber Resilience Act, you can expect severe penalties. Breaches of fundamental cybersecurity requirements, as well as certain manufacturer and reporting obligations, may result in fines of up to 15 million euros or 2.5 per cent of global annual turnover, whichever is higher. Breaching the requirements for importers and distributors may result in fines of up to ten million euros or two per cent of global annual turnover.
A special provision applies to micro-enterprises and small businesses: if they fail to meet the 24-hour deadline for initial notification, the CRA will not impose an administrative fine. However, the obligation to notify remains in force.
The specific rules on sanctions and their enforcement are laid down by the Member States.
However, potential sanctions are only one aspect of the issue. Errors relating to the CRA may also result in financial losses and liability issues.
CRA and liability: When an obligation becomes a financial risk
The CRA introduces new obligations. However, the situations that could give rise to disputes seem rather familiar. After all, if your business operations are disrupted, or if there are disputes over responsibilities or poor service, the costs can quickly mount up.
When it comes to insurance cover, it matters who suffers the loss. If a third party suffers a loss as a result of a professional error on your part, your Professional Indemnity Insurance may provide cover within the scope of the agreed policy. If, on the other hand, your own business is affected by a failure, the focus is on potential losses to your business. The benefits you receive depend on the cover you have chosen and the terms and conditions of the relevant policy module.