Phone us
The main requirements of the EU Cyber Resilience Act come into effect in December 2027. While that may still sound some way off, preparing for compliance could involve significant changes to product development, vulnerability management, documentation and security processes.

With mandatory vulnerability and incident reporting requirements already in force, organisations affected by the Cyber Resilience Act should be assessing their readiness now rather than waiting for the final deadline to approach.

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA), formally Regulation (EU) 2024/2847, introduces mandatory cybersecurity requirements for products with digital elements sold on the EU market.

It requires cybersecurity to be considered throughout a product’s lifecycle, from its initial design and development through to vulnerability management, security updates and ongoing support.

Although the CRA is EU legislation, its reach extends beyond organisations established within the EU. Businesses that develop, manufacture, import, distribute or supply an in-scope product on the EU market may have obligations under the regulation.

For organisations that have not yet established whether the CRA applies to them, that should be the starting point.

Which products are covered?

The CRA applies to “products with digital elements” where their intended or reasonably foreseeable use involves a direct or indirect connection to a device or network.

This covers a wide range of products, including connected and Internet of Things devices, operating systems and applications, routers and other network equipment, security software and separately supplied hardware or software components.

Certain remote data-processing solutions may also fall within scope where they are necessary for a product to perform one of its functions.

There are some exclusions and specific arrangements for products already covered by equivalent sector-specific EU legislation, including certain medical devices, motor vehicles, aviation products and marine equipment.

Pure Software as a Service (SaaS) may fall outside the CRA where it is not integral to an in-scope product, although organisations will need to consider carefully how their particular products and services are structured.

Who is responsible for compliance?

The most extensive responsibilities fall on manufacturers.

Under the CRA, however, the definition of a manufacturer is wider than simply the organisation physically creating the product. A business that has a product designed or developed and then markets it under its own name or trademark can also be treated as the manufacturer.

This means organisations selling commissioned or rebranded software should not assume that responsibility rests with the original developer.

Importers must check that products manufactured outside the EU meet the CRA requirements before placing them on the EU market. Distributors also have responsibilities, including checking that the required marking and documentation are in place and not supplying products they know, or have reason to believe, are non-compliant.

Understanding which role an organisation occupies is therefore an important early step in determining what needs to be done.

Reporting requirements are already in force

The CRA is not simply a December 2027 issue.

Since 11 September 2026, manufacturers have been required to report actively exploited vulnerabilities and severe security incidents affecting in-scope products through the CRA Single Reporting Platform.

The deadlines are demanding. An early warning must be submitted within 24 hours of becoming aware of the vulnerability or incident, followed normally by a more detailed notification within 72 hours.

Further final reporting is then required, with different timescales applying to actively exploited vulnerabilities and severe incidents.

Meeting these deadlines requires more than having an incident-reporting policy. Organisations need effective processes for identifying potentially reportable events, escalating them internally, making decisions quickly, collecting appropriate evidence and submitting accurate regulatory reports.

Businesses that have not yet tested whether their existing incident and vulnerability processes can meet these timescales should make this an immediate priority.

What will full CRA compliance require?

Most of the CRA’s remaining requirements become applicable from 11 December 2027.

For many organisations, however, the work required to meet them cannot realistically be left until the final months before the deadline.

Manufacturers will need to demonstrate that cybersecurity has been integrated across the planning, design, development, production, delivery and maintenance of their products.

A documented cybersecurity risk assessment will be central to this. Organisations will need to consider areas including intended use, foreseeable misuse, the product’s operating environment, the data it processes and the possible impact of a security incident.

Depending on the product and its risk profile, appropriate controls may include secure-by-default configurations, access controls, protection of data confidentiality and integrity, attack-surface reduction, security logging and measures to improve resilience against attacks.

Effective vulnerability management will also be essential. Manufacturers must be able to identify and document components and dependencies, test for vulnerabilities, receive and investigate vulnerability reports, remediate weaknesses and distribute security updates.

This includes appropriate oversight of third-party and open-source components incorporated within products.

Support periods and security updates

Manufacturers will need to establish a support period during which vulnerabilities are handled and security updates are provided.

As a general rule, this should be at least five years unless the product would reasonably be expected to be used for a shorter period.

Users must be told when that support period ends, and security updates addressing vulnerabilities will generally need to be provided free of charge.

Organisations will also need to give users clear information on the secure installation, operation, maintenance and decommissioning of their products.

For businesses that do not currently manage product security in this way, the CRA may therefore require changes not only to technical controls but to wider product-development and support processes.

Conformity assessment and CE marking

Before an in-scope product can be placed on the EU market, the manufacturer must demonstrate that it meets the CRA’s essential cybersecurity requirements.

The assessment process will depend on the type and classification of the product. Many standard products may be assessed through an internal control or self-assessment process, while products with greater cybersecurity significance may require more rigorous assessment, including involvement from a notified body.

Once conformity has been demonstrated, manufacturers must prepare an EU declaration of conformity and apply the CE marking.

Supporting technical documentation will also need to demonstrate how the product complies, including its risk assessment, security controls, testing, vulnerability-management arrangements and relevant conformity-assessment evidence.

Again, producing this evidence retrospectively could prove difficult. Organisations will be in a much stronger position if the required documentation is built into development and security processes well ahead of the deadline.

Download our free guide to the EU Cyber Resilience Act below.

Download our free guide to the EU Cyber Resilience Act

    By submitting this form you are consenting to receiving our monthly newsletter. Your data will be handled in accordance with our Privacy Policy and we will be in touch regarding your enquiry.

     

    December 2027 is closer than it looks

    For businesses with multiple products, complex supply chains or gaps in their existing product-security arrangements, achieving CRA compliance may involve a substantial programme of work.

    The first step should be to establish which products fall within scope, determine whether the organisation is acting as a manufacturer, importer or distributor, and assess existing processes against the CRA requirements.

    From there, businesses can identify gaps, prioritise remediation and build the necessary security and compliance evidence into their existing product lifecycle.

    The key point is not to treat December 2027 as the date to start preparing. It is the date by which the relevant requirements need to be met.

    How AJC can help

    AJC can help organisations understand how the Cyber Resilience Act applies to their products and assess how prepared they are for the requirements already in force and those taking effect in December 2027.

    We can support scope and readiness assessments, review cybersecurity and vulnerability-management arrangements, identify gaps in technical documentation and incident-reporting processes, and help organisations develop a practical roadmap towards compliance.

    Starting now gives businesses time to integrate CRA requirements into existing development and security processes, rather than trying to address them as a standalone compliance exercise as the deadline approaches.

    Please contact us on 020 7101 4861 email us info@ajollyconsulting.co.uk  if you think we can help.

     

    Image accreditation: Getty Images (May 2024) from Unsplash.com. Last accessed on 23rd September 2026.. Available at: https://unsplash.com/photos/futuristic-information-interface-with-data-connections-and-network-patterns-3d-illustration-dqHskSJDfe4

    In case you missed it...

    AJC Achieves ISO 27001 Certification

    AJC is pleased to announce that it has achieved ISO 27001 certification, recognising the robust information security processes and controls...

    Read More
    revolut data breach
    Revolut Data Breach: Why Official Email...

    A recent Revolut data breach has highlighted the risks of relying on apparently legitimate email requests for sensitive information. This...

    Read More
    cookie compliance gambling websites
    Cookie Compliance Lessons from UK Gambling...

    Cookie compliance is about more than having a banner in place. This article looks at new research into UK gambling...

    Read More

    Get in touch

      By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.