What applies from September 2026 and from December 2027
The CRA is an EU regulation and applies directly in every Member State. Its reporting obligations apply from 11 September 2026, when manufacturers must begin to notify actively exploited vulnerabilities and severe incidents affecting the security of their products. The main requirements apply from December 2027.
Individual units placed on the EU market before 11 December 2027 can continue through distribution, and fall under the main requirements only if they are substantially modified from that date, although the reporting obligations cover them from September 2026. Product lines from which new units will be placed on the EU market on or after 11 December 2027 need a readiness plan for those units. The readiness plan must work back from that date to establish design, development and assessment milestones.
Which products and which organisations are in scope
The CRA covers hardware and software whose intended or reasonably foreseeable use includes a data connection to a device or network. Some products sit outside it, including medical devices, motor vehicles and certified aviation products governed by their own EU rules, marine equipment, and products developed exclusively for national security or defence. Free and open-source software supplied outside a commercial activity is also outside scope. Each product needs its own scope assessment.
The assessment route depends on the product's classification and the standards or certification routes available. Some products can be assessed internally; others require external assessment. Management should establish the route for each product early enough to include its cost and lead time in launch plans.
Importers may place on the market only products that comply, and must check that the manufacturer has carried out conformity assessment, drawn up technical documentation and affixed the CE marking. Distributors must verify the CE marking and documentation before making products available. An importer or distributor that places a product on the market under its own name or trademark, or carries out a substantial modification, takes on the manufacturer's obligations.
What each requirement means commercially
- Development capacity
- Products must meet the CRA's essential cybersecurity requirements, including secure default configuration, protection against unauthorised access and a limited attack surface. For product lines with new units reaching the EU market from December 2027, this work draws on the same development capacity as existing roadmap commitments.
- Ongoing support costs
- Manufacturers must handle vulnerabilities and provide security updates for a support period of at least five years, or the expected use time if that is shorter. Where a product is expected to be in use for longer, the support period should reflect that. The cost continues after the sale and belongs in pricing and lifecycle plans.
- Assessment lead times
- Where a product needs a notified body or certification, the timetable depends on their availability and on whether a suitable certification scheme applies. The technical documentation behind the CE marking must be complete before a product is placed on the market.
- Supplier dependencies
- Manufacturers must exercise due diligence on third-party components, including open-source software, so that they do not compromise the product's security. Supplier contracts may need to cover vulnerability information and updates for the full support period.
What the portfolio readiness assessment should show
The executive team should commission the assessment and own the resulting plan. The board should scrutinise material revenue exposure, funding and delivery confidence.
- Exposure
- Which products are in scope, in which category, and how much EU revenue depends on them?
- Delivery
- What must change in each product, who owns delivery, and what funding is required?
- Portfolio choices
- Which products will be remediated or replaced, and which product lines will stop placing new units on the EU market from December 2027?
- Evidence
- What supports the conformity timetable, and how will reporting readiness be tested before September 2026?