OTSecurity

EU Cyber Resilience Act reporting rules take effect, putting vulnerability disclosure and product security in focus


The European Union’s Cyber Resilience Act (CRA) is set to come into force with mandatory cybersecurity requirements for manufacturers of hardware and software products with digital elements, covering planning, design, development and maintenance across the value chain. The regulation requires manufacturers to address vulnerabilities throughout a product’s lifecycle, while some products deemed particularly relevant to cybersecurity may require third-party assessment by a notified body before being placed on the EU market. 

The CRA entered into force on Dec. 10, 2024, with its main obligations set to apply from Dec. 11, 2027, while reporting requirements take effect on Sept. 11, 2026. Products will bear the CE marking to indicate that they comply with the CRA requirements and national market surveillance authorities will ensure enforcement of the rules. These obligations must be met at every stage of the value chain. 

Under the reporting requirements, manufacturers must report actively exploited vulnerabilities and other specified cybersecurity incidents, while the European Commission published practical guidance on July 27, 2026, to help manufacturers, developers and businesses meet their obligations.

The CRA addresses inadequate level of cybersecurity in many products and the lack of timely security updates. It also tackles the challenges consumers and businesses currently face when trying to determine which products are cybersecure and in setting them up securely, making it easier to identify hardware and software with the proper cybersecurity features. 

The CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products. Some products of particular relevance for cybersecurity may need to undergo a third-party assessment by a notified body before they are sold on the EU market.

“It is useful to place this deadline within the CRA’s full timetable,” Guillaume Lambert, CEO at Aevum Advisory, wrote in a LinkedIn post. “The reporting obligation starting on 11 September 2026 precedes by fifteen months the application of the core of the Regulation on 11 December 2027: essential cybersecurity-by-design requirements, technical documentation, the EU declaration of conformity and CE marking incorporating those requirements. Third-party involvement depends on the product category and the applicable conformity-assessment procedure. Certification is therefore not systematically required.” 

Likewise, Lambert observed that equipment used in critical infrastructure is not automatically a ‘critical product’ within the meaning of Annex IV. 

He added that “The support period must be determined according to the criteria in Article 13(8), with a minimum of five years unless the expected period of use is shorter. Five years is a floor, not a default support period for all industrial products.”

To prepare effectively, Lambert recommends launching three immediate workstreams without delay. Organizations must conduct a thorough audit to identify all connected products, evaluate which fall under CRA requirements, and provide documented legal justifications for any claimed exclusions. Ideally, they must move beyond generic sectoral assumptions to establish a precise inventory with product-specific compliance positions.

Secondly, they must build an escalation chain by assigning internal responsibilities, preparing EU Login accounts and the information required for the first SRP submission, and organizing a full-scale simulation exercise to verify that the 24-hour deadline can be met under real-world conditions, including outside normal working hours, with appropriate communication to affected users. Finally, critical suppliers must be audited and commercial agreements updated to align with CRA transparency obligations, preventing contractual gaps from becoming liabilities when incidents actually occur.

He pointed out that executing this preparation roadmap demands a blend of legal and technical capability that mid-sized organizations rarely maintain internally, highlighting a significant resource constraint for operators navigating these regulatory demands.

“Technology was never the hard part of digital industrial transformation, and cyber compliance is no different,” Cécile Vercellino, senior vice president, services and advisory, Industrial Automation at Schneider Electric, wrote in an emailed statement. “The programs that succeed pair platforms and tools with equal investment in change management and workforce capability. Building that capability alongside the technology is what turns a compliance obligation into a lasting operational advantage.”

“Cybersecurity is what makes digital transformation possible. Once your data becomes monetizable, it becomes valuable, and it needs to be managed accordingly. Cybersecurity is the trust layer for digital transformation. It gives organizations the confidence to adopt AI, cloud and automation, and to connect their systems at scale,” according to Zakarya Drias, head of cybersecurity portfolio at Schneider Electric. “The scale and speed of threats is outgrowing human capacity. AI can analyze large volumes of data, identify patterns and surface risk far faster than a human team can. But cybersecurity is about managing risk, and that requires judgment. The most effective model is AI-accelerated and human-led, where AI augments human expertise rather than replacing it.”

“Look at detection and response. We moved from organizations not noticing incidents at all, to knowing about them but taking a long time to respond. What AI brings is speed of response, because it processes a much wider set of context, not just security data but operational data as well,” Drias added. “AI becomes part of the autonomous operations stack, which means it is now an asset you have to manage. The risk around the AI itself, the data and the models belongs in the risk register alongside everything else.”

Neil Smith, president for CPG at Schneider Electric, wrote in a statement that “Cyber regulation is the single highest-cited top-three business pressure in the 2026 AI in CPG global study (39.4%). Today, regulatory and compliance costs reach 11.6% of product price for CPG manufacturers globally, on par with manufacturer margin (11.0%).” 

He added that the Cyber Resilience Act’s September deadline lands exactly as CPG manufacturers are moving from AI pilots to embedding AI end-to-end in their operations. Meeting the regulation and scaling industrial AI run on the same foundation of real-time, trustworthy operational data. Manufacturers who build that foundation now unlock the AI-driven productivity gains the industry needs to overcome increasing operational complexity.”

Jan Martijn Broekhof, Lector at Wittenborg University of Applied Sciences, wrote in a LinkedIn post that under the CRA, the reporting obligation sits with the manufacturer, the entity that places a product with digital elements on the EU market under its own name or brand, and organisation size does not exempt. 

“An importer or distributor generally does not carry an independent reporting duty, unless it sells under its own brand or substantially modifies the product, in which case it effectively becomes the manufacturer for that product,” Broekhof added. “Open source software stewards face a lighter version of the same duty, reflecting the different relationship they have with the products they maintain. Small and micro enterprises are fully in scope too; the only concession the Dutch NCSC has confirmed is that there is no penalty for missing the strict 24-hour window in that category, which is a mitigation, not an exemption.”

Broekhof flagged one detail because it causes real confusion: “The CRA itself does not require any advance registration before you can report. You do not need an account or a login to submit a notification. That is a deliberate design choice, separate from the registration duty that exists under the Cyberbeveiligingswet (the Dutch NIS2 transposition) for organisations that also fall under that law. The two obligations run in parallel, not as one combined process, and conflating them is an easy mistake to make.”



Source link