Skip to content
EU Rules Finder

Cyber Resilience Act: does it apply to your product?

Checked against the sources on 6 October 2026

The Cyber Resilience Act sets cybersecurity requirements for hardware and software products sold in the EU. Its reporting duties apply from 11 September 2026; the rest from 11 December 2027.

Which products

Products with digital elements: hardware and software products, including their remote data processing, whose intended or reasonably foreseeable use includes a data connection to a device or network. Smart home devices, routers, apps, connected toys and many industrial components are typical examples.

What is excluded

Products already covered by sector cybersecurity rules: medical devices and in vitro diagnostics, motor vehicles, civil aviation and marine equipment. Products developed only for national security or defence are also outside, as is free and open-source software not supplied in the course of a commercial activity.

Dates

DateWhat applies
11 September 2026Manufacturers report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report.
11 June 2026Rules for conformity assessment bodies.
11 December 2027All other requirements: secure design, vulnerability handling, conformity assessment, CE marking, technical documentation.

What it asks of manufacturers

  • meet essential cybersecurity requirements in design and production;
  • handle vulnerabilities for a support period, generally at least five years;
  • a conformity assessment: self-assessment for most products; for important and critical products, harmonised standards or a third-party body;
  • technical documentation, an EU declaration of conformity and the CE marking.

Connected consumer products are often under the GPSR as well. Check that with the GPSR check.

Sources