Most European companies have one date in mind for the Cyber Resilience Act: December 2027. It is the one on the slides, the one consultants use to say there is time.
It is real, but it is the second one. The first is 11 September 2026, a few weeks away, and it covers an obligation that requires no certification and no marking: it requires noticing something and reporting it quickly.
If you make, import or resell anything with software inside it, this concerns you even if you have not looked at it yet.
The three dates, in order
The Cyber Resilience Act is Regulation (EU) 2024/2847. It entered into force on 10 December 2024 and applies in stages.
| Date | What starts |
|---|---|
| 11 June 2026 | Provisions on notification of conformity assessment bodies |
| 11 September 2026 | Reporting obligations: actively exploited vulnerabilities and severe incidents |
| 11 December 2027 | Full application: essential security requirements, conformity assessment, marking, software bill of materials, minimum support period |
The logic of the staging is that reporting requires no redesign: it requires knowing what you have sold, noticing if someone is attacking it, and saying so. That is the part you can switch on immediately, which is why it comes first.
Who is actually covered
This is where most companies get caught, because the scope is wider than the name suggests.
The regulation applies to products with digital elements. Not "IT products": products containing software or that connect. And obligations do not depend on company size, but on your role in the supply chain.
It covers you if you:
- Build machinery or plant with PLCs, HMIs, remote control or telemetry. This is the most common case in European manufacturing and the one that surprises people most, because the company thinks of itself as mechanical, not digital.
- Develop and sell software, including niche products with few customers.
- Import connected products from outside the European Union.
- Distribute other companies' connected products.
- Put your brand on a product manufactured by someone else. In that case, for the purposes of the regulation, you are the manufacturer. This is the point that costs the most to those who do not know it.
It does not cover you directly if you merely use connected products bought from others. But it will reach you anyway, because your suppliers will start asking you things and your customers will start asking you.
What must be reported, and what must not
The regulation does not ask you to report every vulnerability. It asks for two specific things, and it matters not to confuse them with the rest of the noise.
Actively exploited vulnerabilities. Not a theoretical weakness found in a component, not a supplier's security advisory: a vulnerability in your product that somebody is using to attack.
Severe incidents affecting the security of the product. The typical case is a compromise of one of your systems that reaches products already delivered — the firmware update channel, for instance.
Not in scope: vulnerabilities you find internally and fix before anyone exploits them, quality problems with no security impact, incidents confined to your corporate network without touching products in the field. Those may fall under other rules — NIS2 if you are an entity in scope, GDPR where personal data is involved — but not under the CRA.
The timings, which are the hard part
The deadlines are tight and worth looking at closely, because they are what your internal procedure has to be built around.
Early warning within 24 hours of becoming aware. You do not need to have understood everything: you need to say that something happened.
Full notification within 72 hours, with what you have reconstructed and the corrective or mitigating measures taken or planned.
Final report: within 14 days of a corrective measure becoming available, for an actively exploited vulnerability; within one month, for a severe incident.
The real constraint is not writing the notification: it is the 24 hours. Twenty-four hours includes the night, Saturday, and the August shutdown week. Which means you need to settle who receives the report when it lands, on which channel, and who has the authority to start the clock without having to track down the managing director. In the companies where we have seen this work, the decision was taken in advance and written on one page.
What to have ready by September
The obligation that starts is about process, not product. It can be done in a month, and this is what to put in place.
Know what is out there. A list of the products with digital elements you have placed on the market, with firmware or software version, and an indication of which third-party components they contain. A formal software bill of materials is a 2027 obligation, but a reasonable list is needed now: without knowing what is inside a product you cannot notice that a known vulnerability affects it.
A channel to receive reports. A published address, actually monitored, with a person who looks at it. Most vulnerabilities come from outside: a researcher, a customer, a supplier. If the only channel is the switchboard, the news reaches you late.
A written handling procedure. Who assesses, on what criteria you decide something is "actively exploited", who authorises notification, who drafts it, who informs customers. Two pages are enough; zero pages are not.
Vulnerability monitoring on the components you use. If your HMI ships an open source library, somebody has to notice when an advisory lands on that library.
A channel to customers. Because reporting to the authority is not enough: whoever has your product on their line needs to know what to do.
The wider picture, so you do not do the same work three times
If you build connected machinery and also supply companies in scope for NIS2, four fronts land on you over the next eighteen months. They look different and largely are not.
NIS2 contract clauses from customers in scope, asking for evidence on access, backups, incidents and subcontractors. CRA reporting from 11 September 2026 and full requirements from 11 December 2027. The Data Act, which from September 2026 requires data-accessible design for new connected products. And the new Machinery Regulation, applicable from 20 January 2027, introducing cybersecurity requirements for connected machinery — with the known and unresolved complication that the harmonised standards have not yet been published.
The technical evidence these four fronts demand is largely the same: knowing what is inside your products, managing vulnerabilities, updating securely, tracking who accesses what, and being able to respond to an incident within defined timeframes.
Build it once, on a foundation that answers all four, rather than opening four disconnected projects with four different consultants. It is the most concrete advice we can give on this subject, and it is also the one that saves the most money.
Penalties
CRA breaches carry fines up to 15 million euro or 2.5% of annual worldwide turnover, whichever is higher, for breaches of essential requirements. As always the ceilings are calibrated for large companies and enforcement is proportionate — but the practical point for an SME is not the fine: it is that a non-compliant product cannot be placed on the Union market, and that consequence bites immediately.
Questions we get asked
We build machines, not software. Does the CRA really apply to us?
If the machines have a PLC, an operator panel, remote control or telemetry, yes. The regulation covers products with digital elements, not IT companies, and it is the point that surprises manufacturers most.
What exactly do I have to report?
Only two things: vulnerabilities in your product that somebody is actively exploiting, and severe incidents that affect the security of products already delivered. Not every vulnerability found, not every quality issue, not incidents that stay inside your own network.
Do the 24 hours include Saturday and the August shutdown?
Yes. Which is why the hard part is not writing the notification but deciding in advance who receives it, on which channel, and who has the authority to start the clock without tracking down the managing director.
We put our brand on a product made by someone else. Who is the manufacturer?
You are. For the purposes of the regulation, putting your brand on another company's product makes you the manufacturer, with all the attendant obligations. It is the costliest mistake we see.
We already have CE marking. Is that not enough?
No. Existing marking covers other requirements; the CRA cybersecurity requirements arrive with full application in December 2027, and the reporting obligation applies in the meantime regardless. Note too that from 20 January 2027 the new Machinery Regulation introduces cybersecurity requirements of its own.
Do I need a software bill of materials now?
Formally no — that is a December 2027 obligation. But you need a reasonable list of what is inside your products by September: without knowing which libraries are in there, you cannot notice that a security advisory concerns you.
A note on sources
The dates and deadlines in this article are verified against the European Commission's official Cyber Resilience Act pages, which state 11 September 2026 for the entry into application of the Article 14 reporting obligations and 11 December 2027 for full application, with the 24-hour, 72-hour, 14-day and one-month deadlines. We were unable to extract the full article text from EUR-Lex at the time of writing, so if you are building a formal procedure, have the text of Regulation (EU) 2024/2847 checked by your legal advisers.
The penalty figure comes from secondary professional sources rather than our own reading of the article.
If you build connected machinery
We work with manufacturers in north-east Italy who realised over the past two years that they had also become software companies without deciding to. The useful work is nearly always the same: understand what is inside the products already sold, put in place a process that meets the deadlines, and do it once for all four regulations instead of four times.
If 11 September is going to find you without a procedure, get in touch: a month is enough to put together what is needed.
Related articles: