The Cyber Resilience Act, Regulation (EU) 2024/2847, is the first horizontal cybersecurity law for products placed on the EU market. It entered into force on 10 December 2024, and because it is a regulation rather than a directive, it applies directly across all Member States with no national transposition.
The structural change is straightforward to state and significant in effect: cybersecurity is now a condition of CE marking, with the same legal standing as safety and electromagnetic compatibility. A connected product that satisfies every existing directive but fails the CRA's essential cybersecurity requirements cannot lawfully carry the CE mark once the regulation applies in full.
Two Deadlines, Not One
Most planning conversations anchor to 11 December 2027, when the main obligations — secure-by-design requirements, technical documentation, conformity assessment and CE marking — apply in full. That is the wrong anchor point for the obligation that arrives first.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products to ENISA and their national CSIRT through the single reporting platform. This obligation applies to products already on the EU market, not only to products placed after the deadline. If a product is on the market on that date, the reporting duty attaches to it — fifteen months before the wider design and documentation requirements apply.
The September obligation is therefore a current-portfolio problem, and it is the one most organisations have not planned for.
Products and Operators in Scope
Scope follows the market, not the manufacturing location. Any "product with digital elements" — hardware or software that can connect, directly or indirectly, to a device or network — made available on the EU market falls within the regulation, wherever it is designed or produced.
- Manufacturers carry the primary obligations: secure development, vulnerability handling, documentation, conformity assessment and reporting
- Importers and distributors must verify that products they place or make available on the market comply before doing so
- Product types span consumer IoT, industrial controllers, connected instrumentation, wearables, embedded firmware and standalone software products
Certain categories already governed by sector-specific cybersecurity rules — including medical devices under the MDR and IVDR — are exempt. For everything else, the working assumption should be that a product shipping with firmware or connectivity is in scope until an assessment demonstrates otherwise.
The Reporting Clock Runs on Hours
The Article 14 timelines are measured from the moment the manufacturer becomes aware of an actively exploited vulnerability or severe incident:
- 24 hours — early warning to ENISA and the national CSIRT
- 72 hours — full notification, including corrective or mitigating measures taken
- 14 days — final report once a corrective or mitigating measure is available (one month for severe incidents)
The trigger is deliberately narrow. An actively exploited vulnerability requires reliable evidence of actual malicious exploitation — a published proof-of-concept or a disclosed-but-unexploited CVE does not, by itself, start the clock. The obligation is not to report every weakness; it is to report the ones being used.
The operational challenge sits upstream of the report. A manufacturer cannot report what it cannot detect. Meeting the timelines requires a defined internal process: monitoring for vulnerabilities in the product and its components, classifying severity, escalating internally, and knowing in advance which CSIRT receives the notification. Organisations that treat this as a form-filling exercise discover the gap on the day the clock starts.
Essential Requirements and the SBOM
From December 2027, products must be designed, developed and produced to meet the essential cybersecurity requirements of Annex I. In practical terms:
- Secure-by-design and secure-by-default development, proportionate to the product's risk
- A documented vulnerability handling process, including a Software Bill of Materials in a machine-readable format
- Security updates provided across a defined support period — generally the expected product lifetime, and at least five years in most cases
- Technical documentation demonstrating conformity, maintained for ten years
For most SME manufacturers the SBOM is the item that exposes the largest gap. Few organisations can currently produce a complete, current inventory of the software components inside their products — including third-party and open-source components integrated years ago and not examined since. Building that inventory is slow, and it is the foundation everything else in the regulation rests on.
Classification Determines the Conformity Route
The route to CE marking depends on how the product is classified, across three tiers of increasing demand:
- Default products — the majority of products with digital elements. Manufacturers may self-assess against the essential requirements using internal control (Module A), documented in the technical file
- Important products (Annex III) — split into Class I (including password managers, VPNs, browsers and smart home gateways) and Class II (including firewalls, hypervisors and tamper-resistant microcontrollers). Class I products may self-assess only where harmonised standards are applied in full; otherwise, and for all Class II products, a notified body must be involved
- Critical products (Annex IV) — including smart meter gateways, smartcards and secure elements, which require certification under a European cybersecurity certification scheme once the relevant scheme is mandated
Where a product could fall into more than one class, the stricter classification applies. Classification should therefore be determined early: it dictates whether a notified body must be engaged, and notified body capacity ahead of the 2027 deadline is expected to be constrained.
Penalties for non-compliance with the essential requirements reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Market surveillance authorities can also require withdrawal or recall of non-conforming products.
A Proportionate Starting Point
Preparation does not require waiting for further guidance — the European Commission published practical application guidance in July 2026, and ENISA has issued guidance on the reporting platform. The sequence is structured:
- Map every product commercialised, imported or distributed in the EU and assess it against the scope criteria
- Determine the organisation's role for each product — manufacturer, importer or distributor — because the obligations differ
- Establish the vulnerability monitoring, classification and reporting process required from September 2026, including confirming the reporting channel with the national CSIRT before an incident occurs
- Begin SBOM development and gap-assess current design and documentation practice against Annex I
- Classify products and identify the applicable conformity assessment route for 2027
Handled this way, the CRA becomes an extension of conformity work most regulated organisations already perform competently. Handled as an IT problem, it produces a policy document that will not withstand the first 24-hour clock.
Positioning for What Follows
The organisations that will manage December 2027 without disruption are the ones treating September 2026 as the point at which cybersecurity entered their conformity system. The reporting obligation is modest by comparison with what follows. It is also the process everything else attaches to.
Ninety8 Compliance supports manufacturers in scoping their product portfolio against the CRA, building the vulnerability reporting process, and developing the SBOM, technical documentation and conformity evidence the regulation requires — across the CRA, CE marking and the wider EU product compliance framework.