Suggested region and language based on your location

    Your current region and language

    Man on laptop working modern server room.
    • Blog
      Digital Trust

    The September 2026 Europe Cyber Resilience Act (CRA) Deadline

    What Manufacturers Need to Know Now

    The regulatory landscape for cybersecurity is constantly evolving as more and more devices become connected. For manufacturers placing products with digital elements on the EU market, cybersecurity compliance is no longer just a good practice. It is becoming a legal obligation under EU law and a prerequisite for market access. 

    The Cyber Resilience Act reaches its first major compliance milestone on 11 September 2026. Under the reporting obligations set out in Article 14, and as provided for in the CRA's implementation timeline under Article 71, manufacturers must report actively exploited vulnerabilities and severe cybersecurity incidents affecting products with digital elements. We know big regulatory changes can bring a multitude of questions and may pose significant challenges for all manufacturers of digital products. So, to help bring clarity, we have answered some of the questions organizations like yours may have about this important milestone.  

    1. What is the EU Cyber Resilience Act? 

    The Cyber Resilience Act is the horizontal EU regulation that sets mandatory cybersecurity requirements across EU for the majority of connected hardware and software products (Products with Digital Elements). It aims to make products more secure across their lifecycle, including the mandatory obligation to address vulnerabilities, provide security updates, and meet compliance obligations.

    2. When will the Cyber Resilience Act come into force?  

    The Cyber Resilience Act entered into force on 10 December 2024; however, it is being implemented in stages. Full compliance for all obligations will be required by 11 December 2027, but vulnerability reporting becomes mandatory on 11 September 2026. 

    What happens on 11 September 2026? 

    The Cyber Resilience Act introduces mandatory reporting requirements for: 

    • Actively exploited vulnerabilities 
    • Severe cybersecurity incidents affecting products with digital elements 

    From 11 September 2026, you must have processes in place to identify, assess, and report relevant incidents within the required timelines. This is the first major compliance milestone ahead of full CRA implementation in December 2027.  

    3. Does the September 2026 deadline affect products already on the market? 

    Yes. 

    Reporting obligations apply to products already on the EU market if they are still within their declared support period. The support period is the period during which a manufacturer commits to addressing vulnerabilities and providing security updates for a product. Therefore, if a support period remains valid today, manufacturers must monitor vulnerabilities and incidents and fulfil applicable reporting obligations. 

    Assess your existing product portfolio now and put monitoring and vulnerability management processes in place to fulfil the new obligation that is coming into force. 

    4. Which products fall within scope? 

    The CRA applies to most products with digital elements made available on the EU market, including:  

    • Connected enterprise and IoT products
    • IT and networking products
    • Embedded software 
    • Standalone software applications
    • Components such as operating systems and digital control systems 

    A few exclusions apply for industries which are already in the scope of separate regulations. You may wish to undertake a scope assessment to understand how the CRA applies to your products. 

    5. What is meant by an "actively exploited vulnerability"? 

    An actively exploited vulnerability is a security weakness for which there is evidence of real-world malicious exploitation by threat actors. 

    You must be able to: 

    • Detect vulnerabilities 
    • Assess their severity 
    • Determine whether exploitation is occurring 
    • Report where required 

    This requires the implementation of vulnerability management processes, including ongoing product security monitoring.  

    6. What qualifies as a severe incident? 

    A severe incident is a cybersecurity event that significantly affects a product's security, or the users who rely on it. 

    Examples may include: 

    • Unauthorized access to critical systems 
    • Large-scale compromise of connected devices 
    • Exploitation causing substantial operational disruption 
    • Incidents impacting confidentiality, integrity or availability 

    You should define clear escalation criteria before the reporting deadline arrives.  

    7. What happens if you identify an actively exploited vulnerability or severe cybersecurity incident? 

    If you identify an actively exploited vulnerability or a severe cybersecurity incident affecting a product with digital elements, you must have processes in place to assess, escalate, and report it in line with CRA requirements. 

    Manufacturers should establish clear internal procedures to: 

    • Identify and assess reportable events 
    • Determine whether reporting thresholds have been met 
    • Gather the required evidence and technical information 
    • Escalate incidents to the appropriate stakeholders 
    • Submit reports within the required timelines 

    The CRA foresees reporting through ENISA's Single Reporting Platform (SRP), which is intended to simplify submissions and information sharing across the EU. As further guidance and implementation details become available, manufacturers should monitor ENISA communications and ensure their reporting processes can be adapted accordingly. 

    How BSI can help 

    BSI supports organizations throughout their cybersecurity and regulatory compliance journey. We help you:  

    • Understand what the CRA means for your products 
    • Run readiness assessments and gap analyses to support: 
      • Strengthening secure development and vulnerability management processes 
      • Building incident management and reporting capabilities 
      • Support cybersecurity governance and compliance activities 

    The September 2026 reporting deadline is now closer than ever. Preparing now can help build confidence in your products, processes, and long-term compliance strategy.