Cyber Resilience Act: does it apply to your product?
Checked against the sources on 6 October 2026
The Cyber Resilience Act sets cybersecurity requirements for hardware and software products sold in the EU. Its reporting duties apply from 11 September 2026; the rest from 11 December 2027.
Which products
Products with digital elements: hardware and software products, including their remote data processing, whose intended or reasonably foreseeable use includes a data connection to a device or network. Smart home devices, routers, apps, connected toys and many industrial components are typical examples.
What is excluded
Products already covered by sector cybersecurity rules: medical devices and in vitro diagnostics, motor vehicles, civil aviation and marine equipment. Products developed only for national security or defence are also outside, as is free and open-source software not supplied in the course of a commercial activity.
Dates
| Date | What applies |
|---|---|
| 11 September 2026 | Manufacturers report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report. |
| 11 June 2026 | Rules for conformity assessment bodies. |
| 11 December 2027 | All other requirements: secure design, vulnerability handling, conformity assessment, CE marking, technical documentation. |
What it asks of manufacturers
- meet essential cybersecurity requirements in design and production;
- handle vulnerabilities for a support period, generally at least five years;
- a conformity assessment: self-assessment for most products; for important and critical products, harmonised standards or a third-party body;
- technical documentation, an EU declaration of conformity and the CE marking.
Connected consumer products are often under the GPSR as well. Check that with the GPSR check.