The Cyber Resilience Act, Regulation (EU) 2024/2847, is the first horizontal cybersecurity law for products placed on the EU market. It entered into force on 10 December 2024, and because it is a regulation rather than a directive, it applies directly across all Member States with no national transposition.

The structural change is straightforward to state and significant in effect: cybersecurity is now a condition of CE marking, with the same legal standing as safety and electromagnetic compatibility. A connected product that satisfies every existing directive but fails the CRA's essential cybersecurity requirements cannot lawfully carry the CE mark once the regulation applies in full.

Two Deadlines, Not One

Most planning conversations anchor to 11 December 2027, when the main obligations — secure-by-design requirements, technical documentation, conformity assessment and CE marking — apply in full. That is the wrong anchor point for the obligation that arrives first.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products to ENISA and their national CSIRT through the single reporting platform. This obligation applies to products already on the EU market, not only to products placed after the deadline. If a product is on the market on that date, the reporting duty attaches to it — fifteen months before the wider design and documentation requirements apply.

The September obligation is therefore a current-portfolio problem, and it is the one most organisations have not planned for.

Products and Operators in Scope

Scope follows the market, not the manufacturing location. Any "product with digital elements" — hardware or software that can connect, directly or indirectly, to a device or network — made available on the EU market falls within the regulation, wherever it is designed or produced.

Certain categories already governed by sector-specific cybersecurity rules — including medical devices under the MDR and IVDR — are exempt. For everything else, the working assumption should be that a product shipping with firmware or connectivity is in scope until an assessment demonstrates otherwise.

The Reporting Clock Runs on Hours

The Article 14 timelines are measured from the moment the manufacturer becomes aware of an actively exploited vulnerability or severe incident:

The trigger is deliberately narrow. An actively exploited vulnerability requires reliable evidence of actual malicious exploitation — a published proof-of-concept or a disclosed-but-unexploited CVE does not, by itself, start the clock. The obligation is not to report every weakness; it is to report the ones being used.

The operational challenge sits upstream of the report. A manufacturer cannot report what it cannot detect. Meeting the timelines requires a defined internal process: monitoring for vulnerabilities in the product and its components, classifying severity, escalating internally, and knowing in advance which CSIRT receives the notification. Organisations that treat this as a form-filling exercise discover the gap on the day the clock starts.

Essential Requirements and the SBOM

From December 2027, products must be designed, developed and produced to meet the essential cybersecurity requirements of Annex I. In practical terms:

For most SME manufacturers the SBOM is the item that exposes the largest gap. Few organisations can currently produce a complete, current inventory of the software components inside their products — including third-party and open-source components integrated years ago and not examined since. Building that inventory is slow, and it is the foundation everything else in the regulation rests on.

Classification Determines the Conformity Route

The route to CE marking depends on how the product is classified, across three tiers of increasing demand:

Where a product could fall into more than one class, the stricter classification applies. Classification should therefore be determined early: it dictates whether a notified body must be engaged, and notified body capacity ahead of the 2027 deadline is expected to be constrained.

Penalties for non-compliance with the essential requirements reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Market surveillance authorities can also require withdrawal or recall of non-conforming products.

A Proportionate Starting Point

Preparation does not require waiting for further guidance — the European Commission published practical application guidance in July 2026, and ENISA has issued guidance on the reporting platform. The sequence is structured:

Handled this way, the CRA becomes an extension of conformity work most regulated organisations already perform competently. Handled as an IT problem, it produces a policy document that will not withstand the first 24-hour clock.

Positioning for What Follows

The organisations that will manage December 2027 without disruption are the ones treating September 2026 as the point at which cybersecurity entered their conformity system. The reporting obligation is modest by comparison with what follows. It is also the process everything else attaches to.

Ninety8 Compliance supports manufacturers in scoping their product portfolio against the CRA, building the vulnerability reporting process, and developing the SBOM, technical documentation and conformity evidence the regulation requires — across the CRA, CE marking and the wider EU product compliance framework.