
Last updated: 2026-10-09
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, sets out the cybersecurity requirements that products with digital elements must meet before they are placed on the EU market, and how manufacturers must handle vulnerabilities while their products are in use. One obligation already applies: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of their products. The remaining obligations follow from 11 December 2027.
For the management of a manufacturer, the CRA is more than a topic for the engineering department. It affects product strategy, budget, organisation and contracts with suppliers. Below you will find what the CRA requires, which deadlines apply, which decisions rest with management and how to check where you stand.
What the Cyber Resilience Act covers and who it applies to
Under Article 2(1), the CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Under Article 3(1), a product with digital elements is a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. This can cover controllers, gateways, connected devices and machine components as well as software sold on its own.
Article 2(2) to (4) excludes, among others, products covered by the EU regulations on medical devices, in vitro diagnostics or vehicle type-approval, aviation products certified under Regulation (EU) 2018/1139, and marine equipment. Whether a particular product is in scope is a legal question that your legal department or counsel should answer for the individual case. The applicability check gives a first orientation.
Manufacturers, importers and distributors
The CRA allocates obligations by role, the economic operators (Article 3(12)):
- Manufacturers (Article 3(13)) develop or manufacture products with digital elements, or have them designed, developed or manufactured, and market them under their own name or trademark, including free of charge. They carry the most extensive obligations (Articles 13 and 14).
- Importers (Article 3(16)) are established in the EU and place on the market products bearing the name or trademark of a company established outside the EU. Before doing so they must check, among other things, that the manufacturer has carried out the conformity assessment and drawn up the technical documentation (Article 19(2)).
- Distributors (Article 3(17)) make products available on the market without affecting their properties. They check, among other things, the CE marking and the manufacturer's information (Article 20(2)).
Roles can change: under Article 21, an importer or distributor is considered a manufacturer if it places a product on the market under its own name or trademark or carries out a substantial modification of a product already on the market. With traded goods, own brands and bought-in parts in the portfolio, it is worth checking which role your company has for each product. More in the overview of CRA roles and on manufacturer obligations.
The deadlines at a glance
Published in the Official Journal on 20 November 2024, the Regulation entered into force on the twentieth day after publication, 10 December 2024 (Article 71(1)). Its obligations apply in stages (Article 71(2)):
| Date | What applies | Provision |
|---|---|---|
| 10 Dec 2024 | Entry into force of the Regulation | Article 71(1) |
| 11 Jun 2026 | Chapter IV (Articles 35 to 51): notification of conformity assessment bodies | Article 71(2) |
| 11 Sep 2026 | Manufacturers' reporting obligations under Article 14 | Article 71(2) |
| 11 Dec 2027 | All other obligations, including the Annex I requirements, technical documentation, conformity assessment and CE marking | Article 71(2) |
Two transitional rules matter for products already on the market. Products placed on the market before 11 December 2027 are subject to the requirements of the Regulation only if they undergo a substantial modification after that date (Article 69(2)). The Article 14 reporting obligations, however, expressly apply to these products as well (Article 69(3)). A device in the field for years is thus already subject to reporting, provided it is in scope. Details on the timeline are in CRA timeline and deadlines.
What rests with management
The CRA obligations apply to the company as manufacturer, importer or distributor. Part of the implementation can be handled within the project. Some points, however, affect budget, product strategy or organisation and therefore need a decision by company management. Six areas belong here.
1. Ownership
Who is responsible for the CRA in the company, and who for each product? Who decides when something has to be reported, and who deputises for that person? Without named owners, topics such as risk assessment, documentation and supplier requirements fall between engineering, quality and purchasing. Clear allocation with a reporting line to management creates accountability.
2. Budget
The effort depends on the number of products and variants, their product class, the maturity of development and vulnerability handling, and the support period you commit to. Part of the cost is one-off, such as the technical documentation per product; part is ongoing, such as vulnerability handling and security updates. The cost drivers are explained in What does CRA compliance cost?
3. Product portfolio
Which products and variants will you still place on the market from 11 December 2027, which will be developed further and which will be phased out? Every single unit counts: a device from a series built for years must meet the requirements if it is placed on the market from that date (recital 38). For units placed on the market before, the question of substantial modifications after that date matters (Article 69(2)). The product class helps determine whether an internal conformity assessment is possible or a notified body must be involved; for important products of class I this also depends on whether harmonised standards are applied (Article 32); important and critical products are listed in Annexes III and IV (see CRA product classes).
4. Support period
Under Article 3(20), the support period is the period during which the manufacturer must ensure that vulnerabilities of the product are handled effectively. Under Article 13(8), the manufacturer determines it so that it reflects the length of time the product is expected to be in use; it is at least five years, unless the product is expected to be in use for less. The end date must be indicated at the time of purchase, at least by month and year (Article 13(19)), and security updates made available must remain available for a minimum of 10 years after being issued or for the remainder of the support period, whichever is longer (Article 13(9)). The support period thus becomes a commitment to the market that ties up staff and money for years. More in Support period and update duty.
5. Round-the-clock reporting capability
Since 11 September 2026, a manufacturer must notify any actively exploited vulnerability in its product and any severe incident having an impact on the security of the product, simultaneously to the CSIRT designated as coordinator (the competent national computer security incident response team) and to ENISA, via the single reporting platform (Article 14(1), (3) and (7)). The early warning notification is due without undue delay and in any event within 24 hours of becoming aware, the more detailed notification within 72 hours, followed by a final report (Article 14(2) and (4)). The Regulation provides no different deadline for weekends or public holidays. Meeting these deadlines depends on reports being received, assessed and passed to someone with authority to decide outside business hours as well. Organising and funding that availability is a management decision. On the process, see CRA reporting obligation since 11 September 2026 and our service reporting process and PSIRT.
6. Supply chain
Manufacturers must exercise due diligence when integrating components sourced from third parties, including open-source software, so that these do not compromise the cybersecurity of the product (Article 13(5)). If they identify a vulnerability in a component, they report it to the person or entity manufacturing or maintaining it (Article 13(6)). Supplier selection, purchasing terms and the information suppliers deliver, such as a software bill of materials (SBOM), therefore belong on management's agenda. How to draft contracts in the individual case is a matter for your legal department or counsel.

Questions to ask your team
These questions can give you a first picture of the status in one meeting. Note whether the answers point to evidence or to intentions.
- Do we have a complete list of all products and variants with digital elements, and is it recorded for each product which role and product class we assume and why?
- Who would decide tonight on an early warning notification under Article 14, who deputises for that person, and do both have access to the reporting platform?
- Is there a documented cybersecurity risk assessment for every product under Article 13(2) and (3)?
- Do we produce a software bill of materials for each release, and how do we find out whether a newly disclosed vulnerability affects one of our products?
- Which support period do we plan for each product, on what basis, and is it reflected in the budget?
- Which products will we still place on the market after 11 December 2027, including from current series, and which of them need a notified body?
- Could we provide the market surveillance authority, on request, with the documents demonstrating conformity (Article 13(22))?
What the consequences of infringements can be
Enforcement lies with the market surveillance authorities of the Member States (Article 52). Upon a reasoned request they can require the manufacturer to provide all information and documentation needed to demonstrate conformity (Article 13(22)). Where a product presents a significant cybersecurity risk and does not meet the requirements, the authority requires corrective action within a set period; if none is taken, it takes provisional measures to prohibit or restrict the product being made available, or to withdraw or recall it (Article 54(1) and (5)).
In addition, Article 64 provides for administrative fines. For non-compliance with the Annex I requirements and the obligations in Articles 13 and 14, the range goes up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher (paragraph 2). Other obligations, including those of importers and distributors, carry up to EUR 10 million or 2% (paragraph 3), and supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request up to EUR 5 million or 1% (paragraph 4). For manufacturers that are microenterprises or small enterprises, Article 64(10)(a) contains a special rule on fines for a missed 24-hour deadline for the early warning; how far it reaches is a question of interpretation, and the reporting obligation itself remains. Setting the fine takes into account, among other things, the nature, gravity and duration of the infringement and the size of the company (paragraph 5). For more, see CRA fines and penalties.
On implementation in Germany, the Federal Government submitted a draft act implementing Regulation (EU) 2024/2847 to the Bundestag on 26 May 2026 (Bundestag printed paper 21/6134; previously Bundesrat printed paper 260/26). The draft designates the Federal Office for Information Security (BSI) as market surveillance authority and governs the procedure for fines under Article 64; the fine ranges themselves are set by the Regulation. The Bundestag held the first reading on 11 June 2026 and referred the draft to its Committee on Internal Affairs as lead committee, and the Bundesrat raised no objections on 12 June 2026 (Bundestag printed paper 21/6512). As of the date of this article, the act has been neither adopted nor promulgated in the Federal Law Gazette.
Note that fines under Article 64 are directed at the economic operator; where that is a GmbH or AG, at the company. Whether and when members of management are personally liable is governed by other provisions, such as the duties of care under section 43 of the German Limited Liability Companies Act (GmbHG) and section 93 of the German Stock Corporation Act (AktG) or the rules of German administrative offences law, and depends on the individual case. These questions are covered in CRA and management liability.
How to check where you stand: gap analysis or CRA readiness audit
The right route depends on whether a CRA programme is already running.
| CRA gap analysis | CRA readiness audit | |
|---|---|---|
| Starting point | no CRA programme yet | CRA programme already running, in-house or with a service provider |
| Aim | identify gaps and plan measures | assess the status independently |
| Approach | together with your teams | samples from the evidence, independent of the project lead |
| Result | gap report and prioritised action plan per product | report for management with a rating per product and recommendations by urgency |
The CRA gap analysis records your products, gives a technical assessment of which of them fall under the CRA and in which role you act, for review by your legal department or counsel, and measures how far each product is from the requirements. It ends with a prioritised action plan you can use to plan budget and dates.
If implementation is already under way, the CRA readiness audit answers a different question: how much of it is evidenced? Blackfort Technology reviews the programme independently of the project lead in five review areas, with samples taken from code, processes and documents. If we have contributed to the programme ourselves, we disclose this before the engagement and you decide whether we carry out the review; parts we implemented ourselves are marked in the report as not independently assessed. The audit is neither a certificate nor an attestation and does not replace the conformity assessment under Article 32; questions that have to be decided legally are flagged for your legal department or counsel. How the review runs is described in CRA audit: process and scope; which evidence to expect is covered in Checking CRA readiness.
What you can tackle now
The reporting obligation already applies, the remaining obligations from 11 December 2027. By then, products, documentation and processes must meet the requirements, including a notified body assessment where one is required. Management can now name the people responsible, have reporting availability secured, decide on the portfolio and support periods, and ask for status reports backed by evidence. For an overview of our services, see CRA consulting and implementation.
Note: This article is general information as of 9 October 2026 and does not constitute legal advice. For an assessment of your individual case, please contact your legal department or a law firm.
Frequently asked questions
What does management need to know about the Cyber Resilience Act?+
Does the CRA also apply to products already on the market?+
How quickly must a manufacturer report an actively exploited vulnerability?+
How long must the support period be?+
What fines does the CRA provide for?+
Is management personally liable for CRA infringements?+
Is the CRA readiness audit a certification?+
Sources
- Verordnung (EU) 2024/2847 (Cyber Resilience Act), Art. 2, 3, 13, 14, 19 bis 21, 52, 54, 64, 69, 71, EUR-Lex
- Regulation (EU) 2024/2847, Official Journal, CELEX 32024R2847 (Cellar)
- Deutscher Bundestag, Drucksache 21/6134: Entwurf eines Gesetzes zur Durchführung der Verordnung (EU) 2024/2847, 26.05.2026
- Deutscher Bundestag, hib 431/2026: Gesetzentwurf zur Umsetzung der Cyberresilienz-Verordnung
- § 43 GmbHG, Haftung der Geschäftsführer
- § 93 AktG, Sorgfaltspflicht und Verantwortlichkeit der Vorstandsmitglieder
- Deutscher Bundestag, Drucksache 21/6512: Stellungnahme des Bundesrates (15.06.2026)
- Bundesrat, Beratungsvorgang 260/26
- Deutscher Bundestag, Textarchiv: Erste Lesung Cyberresilienz-Durchführungsgesetz (11.06.2026)
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).