EU Cyber Resilience Act: What Applies From 11 Sept 2026
Article 14 reporting went live on 11 September 2026 and covers products you have already sold. The deadlines, the scope, and what lands in December 2027.

Table of Contents
TL;DR — The EU Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024. Its reporting obligations under Article 14 have applied since 11 September 2026, and they cover products already on the EU market — not only ones you place there from now on. If you become aware that a vulnerability in your product is being actively exploited, or that a severe incident has affected its security, you have 24 hours to file an early warning through ENISA's Single Reporting Platform and 72 hours for a full notification, followed by a final report — 14 days after a fix is available for a vulnerability, or one month after the 72-hour notification for a severe incident. Everything else — the essential requirements, conformity assessment, CE marking and the five-year support period — applies from 11 December 2027.
What actually changed on 11 September 2026
Most manufacturers have filed the Cyber Resilience Act under "December 2027". That is where the CE marking obligation sits, and it is where almost all the engineering work sits. But the reporting duty arrived first, and it arrived quietly.
Since 11 September 2026, Article 14 of Regulation (EU) 2024/2847 has required manufacturers to report actively exploited vulnerabilities and severe security incidents to the authorities. ENISA launched the CRA Single Reporting Platform on the same day.
The detail most teams miss: this applies to the products you have already sold. There is no grandfathering. A router you shipped in 2023 is covered. If a vulnerability in it is being exploited today, the clock is running today — even though that product will never carry a CRA CE mark, and even though your conformity assessment obligations are still fifteen months away.
Does the CRA apply to your product?
The scope is deliberately wide. A "product with digital elements" is any hardware or software whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
"Indirect" is the word that catches people. A sensor that has no internet connection of its own, but pairs with a phone app or a hub, is in scope. So is a standalone software library. So is a remote data processing service that is integral to the product's function. If you are working through the full picture for a connected device, our guide to selling electronics in the EU sets out how the CRA sits alongside the other directives.
There is no de minimis threshold and no exemption for small volumes. What is excluded is narrow and sector-specific:
- Medical devices under Regulations (EU) 2017/745 and 2017/746
- Motor vehicles under EU type-approval law
- Civil aviation and marine equipment
- Products developed exclusively for national security, defence, or classified information
- Spare parts that restore identical function
- Free and open-source software not supplied in the course of a commercial activity
If your product connects and is not on that list, assume you are in scope.
What you must report, and how fast
Two things trigger the duty. An actively exploited vulnerability — meaning you have reliable evidence that a malicious actor has exploited it, not merely that it exists. And a severe incident having an impact on the security of the product.
| Deadline | What you file |
|---|---|
| 24 hours from awareness | Early warning |
| 72 hours from awareness | Full notification: affected products, severity, corrective and mitigating measures |
| 14 days after a fix is available | Final report — for vulnerabilities |
| 1 month after the 72-hour notification | Final report — for severe incidents |
Reports go through the ENISA Single Reporting Platform to the CSIRT designated as coordinator in the Member State of your main establishment, with simultaneous provision to ENISA. That CSIRT then disseminates to CSIRTs in every Member State where the product is available. You report once; it reaches everyone.
You must also inform the users affected, and where appropriate tell them what corrective action to take.
Micro and small enterprises are exempt from fines for missing the 24-hour deadline. They are not exempt from the obligation.
{{cta}}
What is not required yet
It is worth being precise about this, because the gap between the two dates is where budget decisions get made.
Until 11 December 2027, none of the following apply: the Annex I essential requirements, the cybersecurity risk assessment, conformity assessment, the EU Declaration of Conformity, CE marking under the CRA, Annex VII technical documentation, or the support period obligation. Open-source software steward duties also start then.
Conformity assessment bodies have been able to apply for notification since 11 June 2026, which matters if your product needs a notified body — capacity will be the constraint, not the calendar.
How your product gets classified
Classification turns on the product's core functionality, not on what is embedded inside it. A smartphone that contains an operating system and a password manager is still a smartphone. The technical descriptions behind that test are set by Commission Implementing Regulation (EU) 2025/2392, in force since 21 December 2025 — any guide written before that date gets classification wrong.
| Category | Examples | Conformity route |
|---|---|---|
| Default | Smart speakers, memory chips, apps, most connected consumer electronics | Self-assessment (Module A) |
| Important, Class I (Annex III) | Browsers, password managers, VPNs, routers, network and identity management | Self-assessment only if harmonised standards are fully applied; otherwise notified body |
| Important, Class II (Annex III) | Operating systems, firewalls, IDS/IPS, microprocessors with security features | Notified body mandatory |
| Critical (Annex IV) | Hardware security modules, smart meter gateways, secure elements, smartcards | Notified body; the Commission may require EUCC certification at assurance level "substantial" |
Around 90% of products fall in the default category. Where more than one category could apply, the stricter one wins.
What you have to build before December 2027
Annex I splits into two parts, and the second is the one that changes how a company operates rather than how a product is designed.
Part I — product properties. Ship with no known exploitable vulnerabilities. Secure-by-default configuration with the ability to reset to original state. Protection against unauthorised access. Confidentiality and integrity of data, commands and configuration. Data minimisation. Resilience including denial-of-service mitigation. Minimised attack surface. Security logging. Secure and, where feasible, automatic security updates, separable from functional updates.
Part II — vulnerability handling. Maintain a software bill of materials in a commonly used, machine-readable format covering at least top-level dependencies. Remediate without delay through free security updates. Test regularly. Publish a coordinated vulnerability disclosure policy and a contact address. Provide a secure update distribution mechanism. Publicly disclose fixed vulnerabilities with severity and remediation information.
The support period is at least five years, unless the product's expected lifetime is genuinely shorter. Five years is a floor, not a target — routers, industrial control systems and operating systems are expected to exceed it. You must tell the buyer the end date at the point of purchase, and record your reasoning in the technical documentation.
Annex VII technical documentation and the Declaration of Conformity must be kept available to market surveillance authorities for 10 years after placing on the market, or for the support period, whichever is longer — and the documentation has to be kept current throughout. If you are building that file for the first time, our guide to the CE technical file covers the structure the CRA evidence will sit inside.
CRA and RED: which one applies right now
These run in sequence, not in parallel, and standing down from the wrong one is an expensive mistake.
From 1 August 2025 until 10 December 2027, the cybersecurity requirements of the Radio Equipment Directive under Delegated Regulation (EU) 2022/30 apply to in-scope radio equipment, demonstrated through the harmonised standards EN 18031-1, -2 and -3. That is your live CE marking obligation for radio products today, and it sits alongside the EMC Directive requirements that already apply to the same equipment.
From 11 December 2027, the Commission intends to repeal 2022/30 and the CRA becomes the applicable framework for the same equipment. The repeal instrument is still in draft (Ares(2025)10949208), so treat the handover as expected rather than settled, and keep meeting EN 18031 in the meantime.
Penalties
| Breach | Maximum fine |
|---|---|
| Annex I essential requirements, or Article 13 / 14 obligations | €15 million or 2.5% of total worldwide annual turnover, whichever is higher |
| Other specified obligations (importer and distributor duties, notified body obligations) | €10 million or 2%, whichever is higher |
| Incorrect, incomplete or misleading information to authorities or notified bodies | €5 million or 1%, whichever is higher |
Market surveillance authorities can also order withdrawal or recall. Open-source stewards are not subject to these fines.
Does the Cyber Resilience Act apply to products already on the market?
For reporting, yes. Article 14 has applied since 11 September 2026 to products already placed on the EU market, so an actively exploited vulnerability in something you shipped years ago is reportable now. The full requirements — essential requirements, conformity assessment, CE marking — apply only to products placed on the market from 11 December 2027, though a substantial modification after that date makes a product "new" again.
Our product has Bluetooth but no internet connection. Is it in scope?
Yes. The definition covers a direct or indirect logical or physical data connection. Pairing with a phone, a hub or a gateway is enough to bring the product into scope.
Can we self-assess, or do we need a notified body?
Most products in the default category can self-assess under Module A, which covers roughly 90% of products with digital elements. Class I products can self-assess only where harmonised standards are fully applied. Class II and critical products require a notified body. Check your product's core functionality against Implementing Regulation (EU) 2025/2392 before assuming.
How long must we provide free security updates?
At least five years from placing the product on the market, or longer where the expected product lifetime is longer. The end date must be communicated to the buyer at purchase, and the reasoning behind it recorded in your technical documentation.
Do we still have to meet RED cybersecurity requirements?
Yes, until 10 December 2027. Delegated Regulation (EU) 2022/30 and the EN 18031 series remain the live obligation for radio equipment. The CRA takes over on 11 December 2027, but the repeal of 2022/30 is still a draft instrument.
What happens if we miss the 24-hour reporting deadline?
Breaches of Article 14 sit in the highest penalty tier — up to €15 million or 2.5% of worldwide annual turnover. Micro and small enterprises are exempt from fines specifically for missing the 24-hour early warning, but the obligation itself still stands, as do the 72-hour and final report deadlines.
What this guide does not cover
This is written for manufacturers placing products with digital elements on the EU market. It does not cover the separate and lighter duties of importers and distributors under Articles 19 and 20, the obligations of open-source software stewards which begin on 11 December 2027, or the detail of the notified body designation process. It also does not address national implementing measures, which vary by Member State.
Dates and figures in this guide reflect the position on 23 September 2026. The CRA's secondary legislation is still being adopted — in particular the repeal of Delegated Regulation (EU) 2022/30 remains in draft — so verify against the Official Journal before making a design or budget decision on the basis of a date here.
Frequently Asked Questions
Everything you need to know about EU compliance
For reporting, yes. Article 14 has applied since 11 September 2026 to products already placed on the EU market, so an actively exploited vulnerability in something you shipped years ago is reportable now. The full requirements — essential requirements, conformity assessment, CE marking — apply only to products placed on the market from 11 December 2027, though a substantial modification after that date makes a product "new" again.
Yes. The definition covers a direct or indirect logical or physical data connection. Pairing with a phone, a hub or a gateway is enough to bring the product into scope.
Most products in the default category can self-assess under Module A, which covers roughly 90% of products with digital elements. Class I products can self-assess only where harmonised standards are fully applied. Class II and critical products require a notified body. Check your product's core functionality against Implementing Regulation (EU) 2025/2392 before assuming.
At least five years from placing the product on the market, or longer where the expected product lifetime is longer. The end date must be communicated to the buyer at purchase, and the reasoning behind it recorded in your technical documentation.
Yes, until 10 December 2027. Delegated Regulation (EU) 2022/30 and the EN 18031 series remain the live obligation for radio equipment. The CRA takes over on 11 December 2027, but the repeal of 2022/30 is still a draft instrument.
Breaches of Article 14 sit in the highest penalty tier — up to €15 million or 2.5% of worldwide annual turnover. Micro and small enterprises are exempt from fines specifically for missing the 24-hour early warning, but the obligation itself still stands, as do the 72-hour and final report deadlines.

Not sure whether the CRA catches your product?
Most connected electronics are in scope, and the reporting duty is live now. We map which regulations apply to your product and your markets, and what evidence each one needs.
See our CE marking service for electronics.
Launch in the EU without compliance guesswork
Get a clear view of what documents you need, what’s missing, and how to avoid market access blockers, built for electronics & IoT manufacturers.
- Identify missing CE deliverables (DoC, test reports, technical file)
- Plausibility checks aligned with market surveillance expectations
- Expert validation for edge cases
