EU cybersecurity regulation is moving at pace. NIS2, CER, DORA and the Cyber Resilience Act (CRA) are creating a regulatory landscape that covers organisations, critical infrastructure, financial services and digital products.
For businesses developing or manufacturing products with digital elements, one of the most important milestones is approaching. From 11 September 2026, the CRA’s reporting obligations will apply, requiring manufacturers to report certain actively exploited vulnerabilities and severe incidents. The Regulation will become fully applicable on 11 December 2027. The European Commission has already published guidance to help businesses prepare, covering areas including product scope, vulnerability reporting, risk assessments and support periods. At the same time, proposed changes under Cybersecurity Act 2.0 indicate that the EU cybersecurity framework will continue to evolve.
For businesses, the challenge is therefore not simply understanding another regulation. It is turning regulatory requirements into processes that can work in practice, particularly when a vulnerability or incident needs to be identified, assessed, and reported under strict deadlines.
What Is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) introduces cybersecurity requirements for products with digital elements placed on the EU market. While regulations such as NIS2 focus primarily on the cybersecurity of organisations, the CRA shifts attention to the security of the products themselves.
The CRA covers a broad range of hardware and software, including connected products and certain standalone software. Its requirements extend across the product lifecycle, addressing areas such as cybersecurity risk assessment, vulnerability management, security updates and ongoing support.
The CRA entered into force on 10 December 2024, but its requirements are being introduced in stages. Chapter IV has applied since 11 June 2026, reporting obligations under Article 14 begin on 11 September 2026, and the Regulation will apply in full from 11 December 2027.
This phased approach means that manufacturers cannot wait until 2027 to begin preparing. The first operational CRA obligations are already approaching, making vulnerability management and incident reporting immediate priorities for affected businesses.
The Deadline Businesses Should Be Watching
The most immediate CRA milestone is 11 September 2026, when its reporting obligations begin to apply. From this date, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
The reporting process is built around tight deadlines. Manufacturers must submit an early warning within 24 hours of becoming aware of a relevant vulnerability or incident, followed by a full notification within 72 hours. Final reporting then follows, with different deadlines depending on whether the case concerns an actively exploited vulnerability or a severe incident.
These requirements make vulnerability management an operational responsibility, not simply a compliance exercise. Organisations need to be able to identify relevant vulnerabilities, assess their significance, determine whether reporting is required and coordinate the response quickly enough to meet the regulatory deadlines.
For affected manufacturers, 11 September 2026 is therefore more than another date on the compliance calendar. It is the point at which vulnerability and incident response processes must be ready to operate under real regulatory time pressure.
What Happens by December 2027?
From 11 December 2027, the Cyber Resilience Act will apply in full, introducing broader cybersecurity requirements for products with digital elements.
Manufacturers will need to ensure that cybersecurity is addressed throughout the product lifecycle, from planning and design to development, delivery and maintenance. This includes carrying out cybersecurity risk assessments, meeting the CRA's essential cybersecurity requirements and ensuring that vulnerabilities are handled effectively throughout the product's support period.
The CRA also introduces requirements relating to product information, documentation and conformity assessment. Depending on the product category, some products may require a third-party assessment before they can be placed on the EU market. Compliant products will carry the CE marking, while national market surveillance authorities will be responsible for enforcing the rules.
The Standards Are Starting to Take Shape
Regulatory requirements are only one part of CRA preparation. Businesses also need to understand how those requirements will translate into concrete technical expectations. This is where harmonised standards become important.
The European Commission has requested a set of standards to support CRA implementation, covering both general cybersecurity processes and specific product categories. Products that conform to relevant harmonised standards can benefit from a presumption of conformity with the CRA’s essential requirements.
This work is now moving forward. In August 2026, ETSI announced 17 product-specific draft standards covering areas including operating systems, routers and switches, firewalls, VPNs, network management systems, SIEM systems, browsers, password managers and connected consumer products. The drafts are currently undergoing public enquiry and are intended to support manufacturers in demonstrating compliance.
The standards are not yet final, so manufacturers should avoid treating the current drafts as a definitive compliance checklist. However, their development provides an increasingly clear indication of the technical direction of the CRA.
Beyond the CRA: The Cybersecurity Act 2.0
The CRA is not being introduced in isolation. In January 2026, the European Commission proposed a new cybersecurity package aimed at strengthening the EU’s cybersecurity capabilities while simplifying parts of the existing regulatory framework. The package includes a proposal to revise the EU Cybersecurity Act alongside targeted amendments to NIS2.
The proposed changes focus on several areas. They would strengthen ENISA’s role, simplify aspects of the European cybersecurity certification framework, address security risks in critical ICT supply chains and introduce measures intended to make compliance with existing cybersecurity rules more straightforward. The NIS2 amendments would also clarify certain scope and jurisdictional issues and strengthen ENISA’s coordinating role for cross-border entities.
For organisations, the significance goes beyond any individual amendment. It demonstrates that the EU cybersecurity framework is still evolving even as businesses are implementing recently adopted legislation. Companies therefore need to monitor not only the requirements already in force, but also proposed changes that could affect how those requirements are implemented in the future.
One Regulatory Landscape, Multiple Layers of Responsibility
The growing number of EU cybersecurity rules does not mean that every organisation faces the same obligations. The key challenge is understanding which regulatory framework applies, and at which level.
NIS2, for example, focuses on cybersecurity risk management and incident response for essential and important entities, while CER addresses the broader resilience of critical entities. DORA establishes ICT risk and operational resilience requirements for financial entities. The CRA takes a different approach, placing cybersecurity requirements directly on products with digital elements made available on the EU market.
This creates a regulatory landscape with several overlapping layers:
- NIS2 - cybersecurity and risk management of organisations
- CER - resilience of critical entities against a broader range of threats
- DORA - digital operational resilience in the financial sector
- CRA - cybersecurity of hardware and software products
- RED and other product legislation - cybersecurity requirements for specific categories of products
The distinction is important, but the frameworks do not always operate independently. The European Commission explicitly notes the close relationship between NIS2 and CER, while the CRA itself contains provisions addressing its interaction with other EU legislation.
For businesses, this means compliance cannot be approached as a series of isolated projects. A single organisation may need to consider requirements at both the organisational and product level, making regulatory mapping an important part of cybersecurity planning.
The practical question is therefore not simply “Which regulation applies to us?” but “Which requirements apply to our organisation, our products and our processes - and how do they work together?”
From Regulatory Compliance to Operational Readiness
Meeting EU Cyber Resilience Act (CRA) requirements, including strict 24-hour early warnings and 72-hour incident notifications starting September 11, 2026, requires more than theoretical policies. Organisations need clear roles, cross-functional communication, and tested response processes.
Practising realistic incidents via cyber range exercises helps identify gaps between written procedures and actual execution under pressure. As frameworks like the proposed Cybersecurity Act 2.0 continue to evolve, true compliance hinges on operational capability. September 11, 2026, should be treated not just as a deadline, but as a milestone for practical readiness built through active training.
Table of contents
