A common framework for digital products

The Cyber Resilience Act (CRA) establishes horizontal cybersecurity requirements for products with digital elements made available on the European Union market. Its aim is to ensure that security does not depend solely on voluntary measures or on responding to incidents after a product reaches the market: the framework also sets obligations for design, support and vulnerability management. The law is Regulation (EU) 2024/2847, published in the Official Journal of the EU.

Its scope is broad: it may include both connected hardware and software, provided the product fits the legal definition. That does not mean every technology-related product or service is automatically covered. The law provides for exclusions and specific rules, and whether it applies in a particular case depends on features such as the product’s function, its relationship with other products and the exceptions set out in the text. The category “digital product” is a starting point, not a compliance conclusion.

For manufacturers and companies placing products on the European market, the practical question is not simply whether a device connects to the internet. They need to identify which product is being marketed, what role each company occupies in its supply chain, and which obligations correspond to that role. Legal assessment should be based on the regulation and, where appropriate, specialist advice; general guidance is not a substitute for analysing the specific product.

The timetable has separate milestones

As of 10 October 2026, not all provisions of the CRA have the same application date. The European Commission states that obligations to report actively exploited vulnerabilities and serious incidents affecting products with digital elements began to apply on 11 September 2026. Those obligations were therefore already in force on the reference date for this guide.

By contrast, the regulation’s general product requirements will not begin to apply until 11 December 2027. The distinction matters: the fact that one part of the law is already operational does not mean all its design, documentation or conformity requirements apply in October 2026. Conversely, the fact that general application is still pending does not remove obligations whose milestone has already passed.

Milestone Date Scope indicated by the EU
Application of reporting obligations 11 September 2026 Actively exploited vulnerabilities and serious incidents
General application of CRA requirements 11 December 2027 The regulation’s product requirements, subject to applicable provisions and exceptions

The table summarises application dates; it is not a comprehensive timetable for every article or a conformity assessment. For planning purposes, it is advisable to check the specific provision of the regulation relevant to the activity and distinguish between entry into force, application date and transitional periods. In particular, it is not accurate to describe the entire set of obligations as having entered into force simultaneously.

What the reporting obligation already in force requires

The active obligation concerns manufacturers and two types of events: actively exploited vulnerabilities and serious incidents affecting product security. According to the Commission’s official reporting page, a manufacturer must issue an initial alert within 24 hours of becoming aware, followed by a notification within 72 hours. This sequence requires companies to be able to detect, assess and escalate relevant information, not merely to have a contact channel.

The Commission also describes a final report: for actively exploited vulnerabilities, it must be submitted no later than 14 days after a corrective measure becomes available; for serious incidents, it is due within one month of the 72-hour notification. These deadlines relate to different circumstances. They should not be confused with the initial deadline or interpreted as permission to delay the first communications until the technical investigation is complete.

The procedure is conducted through the CRA’s single reporting platform, according to information from the Commission. Operationally, a company subject to the obligation needs processes that allow it to record when it became aware, preserve incident evidence, coordinate technical and regulatory teams, and prepare successive communications. The date of awareness may determine how deadlines are calculated, so recording and internal escalation matter just as much as the technical response.

Responsibilities in the supply chain

The regulation distributes responsibilities among actors such as manufacturers, importers and distributors. The manufacturer has a central role in obligations concerning the product and its security; those who import or distribute it also have duties within their supply-chain role. The precise content of each duty depends on the company’s legal role and the circumstances specified in the law: using the customary commercial name for an activity is not enough to determine who is responsible.

Preparation should begin with an inventory of products with digital elements intended for the EU market and a map of the entities that manufacture, import or distribute them. It is then useful to link each product to its documentation, internal owners, update processes and channels for receiving vulnerability reports. These measures are preparation recommendations based on the obligations and dates described; they are not, by themselves, a complete legal checklist or proof of conformity.

An initial check can be framed as follows:

  • Define the product and check whether it falls within the scope or an exclusion.
  • Identify the role of each company involved and who performs the manufacturer function.
  • Verify that a mechanism exists to identify and escalate vulnerabilities and incidents.
  • Review the applicable reporting deadlines and retain evidence of decisions.
  • Prepare to assess the general requirements before their application date.

The list helps organise the work, but it does not resolve interpretive questions about a particular product. Nor does it make it possible to conclude, without documentation and analysis, whether a particular company is already compliant or non-compliant.

What can be stated and what remains to be assessed

The verifiable conclusion as of 10 October 2026 is limited: the reporting obligations identified by the Commission have applied since 11 September 2026, while general application of the CRA requirements is scheduled for 11 December 2027. This distinction between milestones helps avoid two opposite mistakes: treating all obligations as still in the future, or presenting the entire regime as fully applicable from September 2026.

The legal text and institutional documentation allow the framework and its dates to be described, but they are not enough to assess a particular manufacturer’s compliance, classify a product whose status is uncertain, or determine the regulation’s economic impact. Nor can one infer that every security incident automatically triggers CRA reporting: the cited obligation is limited to the vulnerability and incident categories defined by the framework. Borderline cases require review of the provisions and the technical facts.

For manufacturers and distributors, the practical decision is to move forward on two parallel tracks: treat reporting preparation as a current matter where relevant, and separately plan for general conformity before December 2027. For users, the CRA establishes a regulatory framework, but it does not guarantee that an individual product has no vulnerabilities or replace updates and secure practices. This distinction between a rule, preparation and real-world outcomes is essential to avoid attributing more to the law than it can demonstrate.