EU Cyber Resilience Act (CRA) Is Live: What Software and Connected Product Makers Need to Know

EU Cyber Resilience Act (CRA) Is Live: What Software and Connected Product Makers Need to Know

The European Union’s Cyber Resilience Act (CRA) is no longer just something to prepare for. Its first obligation, reporting actively exploited vulnerabilities and severe incidents, started applying on 11 September 2026. For companies that build connected devices, embedded software, mobile apps, or the cloud services behind them and place them on the EU market, this marks the point where processes have to move from paper to real-world operation.

What Is the CRA and How Does the Timeline Work?

The CRA is the first EU-wide regulation to set mandatory cybersecurity requirements for products with digital elements. It applies in phases:

  • December 2024: The regulation entered into force.
  • 11 September 2026: Vulnerability and incident reporting obligations (Article 14) began to apply.
  • 11 December 2027: All remaining obligations start, including secure-by-design requirements, technical documentation, conformity assessment, and CE marking.

In short: the reporting rules apply today, and there’s roughly a year left to prepare for the broader obligations.

Who Does It Cover?

The reporting obligations apply to manufacturers of products with digital elements made available on the EU market. That includes connected software and hardware (such as mobile apps and IoT devices) as well as the back-end and cloud services those products need to function. Two points matter in particular:

  • The manufacturer’s location isn’t the deciding factor: If a product is placed on the EU market, the manufacturer can be in scope even if it’s based in Turkey. This matters especially for exporters.
  • Products already on the market are included: The reporting duty isn’t limited to newly released products; it covers products that are already out there.

What Does Reporting Mean in Practice?

When a manufacturer becomes aware of an actively exploited vulnerability or a severe security incident affecting its product, the clock starts: an early warning within 24 hours, a detailed notification within 72 hours, and a final report afterward. Notifications go through the Single Reporting Platform operated by ENISA.

Not every vulnerability triggers a report; the trigger is knowing that a flaw is actively being exploited. But to notice that within 24 hours, you need to know which components each product uses and be able to keep watching what happens to them.

5 Steps You Can Take Today

1. Build your product inventory. Which products you place on the EU market contain digital elements? Embedded software, mobile apps, and back-end services all count. Pinning down the scope is where everything starts.

2. Create a software bill of materials (SBOM). The SBOM requirement formally starts in 2027, but the only practical way to tell quickly whether a newly disclosed flaw affects your product is to know your components in a machine-readable form.

3. Automate vulnerability monitoring. Set up a process that continuously watches your components for new vulnerabilities and active-exploitation reports. End-of-life open-source dependencies are a particular risk.

4. Define your incident response and reporting process. Who decides, who prepares the notification, and who is on call on weekends and holidays? In a 24-hour window, these questions need answers on day one. Coordinate with any existing NIS2 or sector-specific incident processes.

5. Bring suppliers and software partners into the process. If part of your product’s software comes from third parties, make sure your contracts spell out how fast vulnerabilities will be communicated to you and how long update support will last.

Conclusion: The Clock Started Today, Not in 2027

The CRA’s major obligations arrive in 2027, but the reporting rules are already running, and meeting them covers much of the 2027 groundwork too: inventory, SBOM, vulnerability tracking, and an incident process. Companies that lay these foundations now will both meet today’s reporting duty and enter conformity assessment far better prepared.

This article is for general information only and is not legal advice. We recommend seeking qualified legal counsel on the scope of your products and your specific obligations.