Europe's Connected Products Face a 24-Hour Clock: Inside the Cyber Resilience Act Rollout
Published on 10/06/2026 at 08:50 | Editorial boerse-global.de
Manufacturers selling anything with a digital component in the EU now have a hard deadline hanging over their heads — and for actively exploited security flaws, the window to speak up is a single day.
The European Commission has issued detailed guidance to help companies prepare for the Cyber Resilience Act, Regulation (EU) 2024/2847, which sets sweeping cybersecurity requirements for makers and suppliers of products with digital elements. The guidance arrives after the first binding vulnerability reporting duties took effect in September, with broader obligations for the entire product lifecycle due by the end of 2027.
A phased countdown, not a single switch
The regulation entered into force on 10 December 2024 and unfolds in stages. Chapter IV provisions apply from 11 June 2026, while the reporting duties under Article 14 have already been binding since 11 September 2026 — and they extend to products already sitting on the European market.
Under those rules, manufacturers must flag actively exploited vulnerabilities to their national cybersecurity centre (NCSC) within 24 hours as an early warning. A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a security update being made available.
To centralise this flow, the European Union Agency for Cybersecurity (ENISA) began operating a single reporting platform on 11 September 2026. Its initial capability is limited to handling these mandatory notifications.
What kicks in from December 2027
The regulation's full weight, including Annex I, lands on 11 December 2027. From then, every product with digital elements placed on the EU market must be designed according to recognised IT security principles and carry a CE mark. The requirements stretch across the whole lifecycle, from development through to documentation:
- Support and updates: Article 13(8) calls for a support period of at least five years, while Article 13(9) requires free security updates for at least ten years.
- Transparency via software bills of materials (SBOM): Under Annex I Part II, manufacturers must maintain a machine-readable software bill of materials covering at least top-level dependencies. It does not have to be publicly accessible, but market surveillance authorities can demand it. Germany's Federal Office for Information Security (BSI) describes the format in Technical Guideline TR-03183 Part 2, which serves as a reference point.
- Handling legacy components: Open-source components that have reached end of life are not banned. Still, manufacturers carry responsibility for every vulnerability in the building blocks they integrate, for the full support period.
Who is covered, what non-compliance costs
Company size is irrelevant under the Cyber Resilience Act — manufacturers, importers and distributors are all bound equally. Article 64(2) sets fines of up to €15 million or 2.5% of global annual turnover for breaches.
Pilot projects run under CRA initiatives show that alongside technical testing, risk assessments and airtight documentation are what make the difference.
Help is available for smaller firms. The second call of the European SECURE project opened on 1 October 2026, with €11.5 million in funding available across Europe until 11 December 2026. The money is meant to guide businesses through maturity analyses, governance questions and regulatory requirements.
