Europe's Connected Devices Face a Hard Deadline: Security Reporting Starts in 2026, Full Rules in 2027
Published on 10/01/2026 at 15:21 | Editorial boerse-global.de
Manufacturers of networked machinery, appliances and software across Europe are working against a regulatory clock that has already started ticking. Under the Cyber Resilience Act — formally Regulation (EU) 2024/2847 — products with digital elements may only be placed on the EU market if they meet the regulation's core requirements, and that obligation takes full effect on 11 December 2027.
But the compliance burden does not begin there.
Since 11 September 2026, makers of connected devices, machines and systems have been required to actively report vulnerabilities and serious security incidents. An initial early warning must be filed within 24 hours, with a detailed notification following within 72 hours.
Obligations That Outlast the Sale
The CRA's reach extends across the entire product lifecycle rather than ending at the point of sale. Article 13 requires security updates for at least five years from the moment a product becomes available on the market — or for its full service life, whichever applies.
Those duties also catch products developed before 11 December 2027, provided they continue to be made available on the market after that date. Compliance is not settled by affixing a CE mark; it involves ongoing vulnerability handling and the reporting of actively exploited flaws to ENISA, the EU's cybersecurity agency.
Container and Kubernetes providers fall inside the scope too, whenever they offer commercial support to customers in the EU — no matter where the company itself is headquartered. Their obligations include hardened base images, the production of a Software Bill of Materials (SBOM) and systematic monitoring.
A Vendor's Five-Step Path to a Signed Declaration
How this looks in practice is illustrated by the Qt Group. With Qt 6.12 LTS, released at the end of September 2026, the company says it shipped the first version carrying a signed EU declaration of conformity under the CRA for its commercial licences. Getting there involved a five-stage process running from product definition through evidence gathering to lifecycle maintenance.
The framework was placed in the CRA's standard category through self-assessment. A CE mark is to follow once regulatory standards are defined more precisely. The declaration does not cover the open-source Community Edition, and commercial licences come with a five-year commitment to security updates.
Legacy Hardware Meets New Rules
The process industry faces a sharper set of problems. Field devices and bus infrastructures there often stay in service for ten to twenty years, and many rest on older standards such as PROFIBUS PA/DP that were never built with modern cybersecurity concepts in mind.
Specialists recommend migrating the control layer to Profinet in stages, gaining higher bandwidth and network-based security while keeping existing field devices connected through gateways. Softing, for instance, offers pnGate PA as an integration route for exactly this scenario.
Machine builders, meanwhile, should expect security updates and vulnerability management to become part of product liability. Suppliers of HMI and edge platforms are increasingly being judged on whether they can update installed machines remotely and maintain documentation that satisfies the CRA over the long term. Companies such as Novotek provide tools including EXOR and Corvina to ease version management and secure remote connections.
Training, Standards and a Nürnberg Showcase
A support industry is forming around the transition. ONEKEY will present a fast-track CRA compliance programme at the it-sa trade fair in Nürnberg from 27 to 29 October 2026, covering maturity assessments and automated SBOM generation. Estimates put the number of digital products in the EU affected by the regulation somewhere between hundreds of millions and billions.
Alongside direct CRA preparation, the IEC 62443 standards series serves as a key foundation. Technical workshops — such as those run by secuvera GmbH in September — teach manufacturers the technical security requirements and processes needed for a secure development lifecycle, helping them work through the security levels and component requirements the Cyber Resilience Act demands.
