EU regulation is gaining momentum

Cyber Resilience Act: What manufacturers need to bear in mind from September 2026

The Cyber Resilience Act is entering its critical implementation phase: The mandatory requirements for vulnerability management and reporting of security incidents in digital products will come into force in roughly one year. This article outlines what needs to be done now.
Cyber Resilience Act: Was Hersteller ab September 2026 beachten müssen

The European Union is introducing mandatory requirements for vulnerability management and reporting of security incidents for products with digital components from 11 September 2026 when it introduces the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). The CRA’s comprehensive cybersecurity and transparency requirements will be fully implemented starting December 2027. However, from autumn 2026 onwards, important requirements will set new standards for manufacturers, importers and distributors of digital products.

Who is affected by the CRA?

The CRA applies to all operators who place products with digital elements on the EU market – from IoT devices to software and embedded systems. Exemptions exist for products intended exclusively for national security, medical devices, vehicles or aviation.

Cyber Resilience Act Whitepaper Thumbnail

Whitepaper

What manufacturers of connected devices need to know now

Learn how the new EU Cyber Resilience Act is changing the requirements for manufacturers of connected devices.

What will be mandatory from September 2026?

Vulnerability management and reporting obligations

Documentation requirements

Additional CRA requirements apply from December 2027

The remaining extensive cybersecurity obligations will come into force on 11 December 2027:

Workshop scene

bbv Academy on EU regulations

Get your team ready for the CRA

The EU is enacting various laws on cybersecurity. This particularly affects product developers. This course will give you a clear understanding.

Advantages for companies: Compliance as a competitive edge

Companies that view the CRA not only as an obligation but as a strategy benefit twice over.

What companies should do now

Companies should start now to introduce organisational and technical measures to comply with CRA requirements.

Checklist for implementing the Cyber Resilience Act - symbolic image

Checklist

For successful implementation of the Cyber Resilience Act

Our Cyber Resilience Act checklist offers you clear guidance to efficiently plan and implement all necessary steps.

Conclusion: Ensure compliance early on

The mandatory reporting and vulnerability management obligations that will become mandatory on 11 September 2026 require companies to act immediately. At the same time, companies should carefully prepare for further comprehensive implementation of the CRA requirements from December 2027 to ensure lasting security, market opportunities and regulatory compliance. The implementation of a comprehensive security and transparency concept is the key to sustainable success in the EU’s digital single market.

THIS MIGHT ALSO INTEREST YOU

Header-Bild zu Blog GPSR
Header-Bild zu Blog RED
Portrait of Martin Egloff
The expert

Roland Achermann

Attention!

Sorry, so far we got only content in German for this section.