Could the EU Cyber Resilience Act Affect Your Ability to Sell Products in Europe? 

Organisations who manufacture and sell products with digital elements into the European market are entering a period of regulatory change that will directly influence how products are designed, developed and maintained.

The Cyber Resilience Act (CRA) is regulatory change that is currently in motion, with phased obligations relevant from 11th September 2026 onwards. Broader compliance obligations are enforced as the regulation becomes fully enforceable later in the following year. 

For the more immediate focus; September’s deadline requirement is specifically relating to reporting requirements for vulnerabilities and security incidents.  

For manufacturers with product roadmaps extending into 2026/2027 and beyond, this timing is going to directly affect commercial futures. Products already in development today may fall within scope by the time they reach or remain in the market. 

The practical question for many organisations is therefore immediate: could the CRA requirements affect our ability to continue selling existing, or launching new products, into the EU market? 

In many cases, the answer will be, yes.

What’s Changing Under the Cyber Resilience Act? 

The Cyber Resilience Act introduces mandatory cyber security requirements for products with digital elements placed on the EU market. This includes connected hardware, software enabled products, and systems that rely on embedded or external software components. 

The regulation requires manufacturers of products with digital elements to be able to demonstrate that cyber security has been considered throughout the product lifecycle, including design, development, production, and post market activity. In practice, this means being able to evidence areas such as secure by design decisions, software dependencies (including a Software Bill of Materials), vulnerability management processes, and how security issues are monitored and resolved once products are in the field. 

While cyber security has long been a technical discipline within manufacturing organisations, the CRA formalises it as a regulatory, evidence-based requirement tied to market access. 

Who Does It Impact? 

The CRA applies broadly to products with digital elements, which extends well beyond traditional software organisations. 

Manufacturers commonly in scope include those producing: 

  • Industrial automation and control systems  

  • IoT and connected devices  

  • Electronics with embedded software components  

  • Smart infrastructure and building systems  

  • OT and industrial equipment with digital functionality  

  • Hardware products reliant on software or firmware  

EXEMPTIONS

While the CRA applies broadly to products with digital elements, certain sectors are excluded where cyber security requirements are already governed by dedicated European legislation. 

The following product categories are currently exempt from CRA requirements: 

  • Medical Devices – Products regulated under existing medical device cyber security frameworks 

  • Motor Vehicles – Vehicles and automotive systems covered by established vehicle cyber security regulations 

  • Civil Aviation – Aircraft and aviation systems subject to sector specific safety and security requirements 

  • Marine Equipment – Maritime products regulated through existing marine safety frameworks 

These exemptions are designed to avoid overlapping regulatory obligations. However, organisations supplying digital components, software, or connected technologies into these sectors should still assess their role carefully, as individual components may fall under separate cyber security requirements or other EU regulations. 

Why Timing Matters 

The CRA entered into force on 10th December 2024, but compliance requirements are being introduced in phases. For manufacturers, the most important point is that obligations begin well before full enforcement in 2027. 

From 11th September 2026, manufacturers will be legally required to report actively exploited vulnerabilities and serious security incidents. 

Reporting must follow strict timelines: 

  • 24 hours: early warning after becoming aware of an incident  

  • 72 hours: detailed incident assessment  

  • 14 days: final report once mitigation or applicable patches are published/available  

These requirements apply to products already on the market, not just new releases. In practice, this means manufacturers will need reporting processes in place well before September 2026 in order to comply. 

 

Full Compliance Deadline: December 2027 

By 11th December 2027, all products in-scope must meet full CRA requirements. 

This includes: 

  • Security-by-design and security-by-default principles  

  • Defined vulnerability support periods (disclosed at point of sale)  

  • Technical documentation and evidence of compliance  

  • Software Bill of Materials requirements  

  • CE (Conformité Européenne) marking for applicable products  

... and many more. 

 

Starting Today Helps You Tomorrow 

Although the official compliance deadline is 2027, organisations bringing products with digital elements to the EU market must begin preparation much earlier to avoid disruption. This includes adapting development processes, implementing vulnerability reporting, building compliance evidence systems, and aligning engineering and regulatory functions. 

Product development cycles mean that decisions made now will determine whether products launched in 2026 and 2027 are compliant at the point they reach the market. 

Delays in preparation are therefore not absorbed later, they can typically surface as disruption during product release, certification, or customer assurance processes. 

What This Means for You 

For organisations selling into the EU, CRA compliance is not a technical exercise in isolation. It’s increasingly linked to: 

  • product approval and market entry requirements  

  • customer and distributor assurance expectations  

  • contractual obligations in supply chains  

  • ability to maintain uninterrupted EU sales channels  

Where manufacturers cannot demonstrate required security practices and evidence, they will be unable to sell their product in the European market after December 2027. 

challenges 

Most manufacturers reach a similar point once the CRA is assessed in detail. The questions become: 

  • Does this apply to our specific products and markets? 

  • What level of compliance is required (as there is more than one)? 

  • Have we ever designed the products formally in a manner that considered risks? 

  • Where and what are the gaps between current processes and the requirements? 

  • What is the risk to product delivery schedules and revenue plans? 

These are operational questions with commercial and executive level implications, particularly for organisations with defined product release cycles. 

HOW CYRO CYBER SUPPORTS YOU

Cyro Cyber works with manufacturers to assess and respond to the Cyber Resilience Act requirements in a structured and operationally realistic way. 

With more than 30 years of experience with industrial cyber security environments and relevant security frameworks (ISA/IEC62443-4-1, ISO 27001, ISO 27002 etc.) our focus is on aligning regulatory requirements with the realities of product engineering and manufacturing operations. 

Our engagements typically include: 

  • An initial assessment of the CRA in the context of your organisation and its applicability across products or product families. 

  • Identification of compliance gaps and evidence requirements  

  • Prioritised remediation roadmaps aligned to product lifecycles  

  • Support in developing required security documentation and processes  

  • Advisory and technical hands-on support across engineering and operational teams to support internal teams and functions. 

If you’re manufacturing connected products for the EU market and are unsure how the Cyber Resilience Act applies to your organisation, now is the right time to assess your position. Speak to our team today to discuss your CRA readiness and next steps. 

 

Need supporT? Enquire Now

One of our experts will be in touch shortly to better understand your requirements and challenges.

Next
Next

Mythos and the New Cyber Security Reality: When Vulnerability Discovery Moves at Machine Speed