Starting September 11, 2026, the European Union's Cyber Resilience Act (CRA) reporting requirements for digital device manufacturers have come into force. Companies are now required to notify regulators about actively exploited vulnerabilities and serious security incidents affecting their products.
The rules apply to all hardware and software products with digital elements sold on the EU market, including models that are already on sale.
Notifications go through a single CRA reporting platform, built and maintained by the EU Agency for Cybersecurity (ENISA). The European Commission has published practical guidance explaining to manufacturers, developers, and companies how to meet the new requirements. National market surveillance authorities will oversee compliance on the ground.
What This Means for Consumers
For owners of connected devices, from smart locks to fitness trackers, the new rules mean manufacturers will respond to cyber threats faster. The Cyber Resilience Act requires digital products to be designed, updated, and maintained with user protection against security risks in mind throughout their entire lifecycle.
Manufacturers will confirm CRA compliance through CE marking, which will let consumers tell verified devices apart from the rest.
The incident reporting obligations took effect on September 11, 2026. The main package of CRA requirements covering product design and maintenance will kick in later, on December 11, 2027. The Act builds on the earlier EU Cybersecurity Strategy and the Security Union Strategy.
Read also:
