The EU Cyber Resilience Act: New Responsibilities for Digital Products

Cybersecurity regulation in the EU is increasingly extending beyond financial institutions and traditional data-protection obligations to the digital products themselves.

The EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements, covering areas such as product design, security updates and vulnerability management. Its implementation is being phased in, with certain reporting obligations already applying from 11 September 2026.

Under the reporting requirements, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. Certain early warnings must be submitted within 24 hours of becoming aware of an incident.

Why we’re watching:
Businesses developing, manufacturing or placing connected hardware and software products on the EU market will need to consider cybersecurity requirements as part of their product and compliance strategies.

Source: European Commission

Scroll to Top