Cyber Resilience Act 2026: Major Changes for Digital Professionals Starting September 11

September 17, 2026

Cyber Resilience Act 2026: Major Changes for Digital Professionals Starting September 11

The European regulation on cyber resilience is now entering its operational phase. Here we discuss the relevant parties and what they need to report starting from this date.

Summary

  1. How the deadline of September 11 impacts and who is affected?
  2. How to report an exploited vulnerability or a severe incident?
  3. An intermediate step in the implementation of the CRA

The Cyber Resilience Act (CRA) reaches its first mandatory stage this Friday, September 11, 2026. Article 14 of the European regulation on cyber resilience requires manufacturers of products with digital components to report actively exploited vulnerabilities and serious incidents impacting their security.

What does the September 11 deadline change, and who is affected?

The scope is broad: software, hardware, and their remote data processing solutions, as long as they are made available on the EU market in a commercial capacity. The responsibility rests on the manufacturer, the entity that develops or has the product developed and markets it under its own name.

Assorted devices and software screens representing products on the EU market
Le CRA couvre logiciels, matériels et solutions de traitement à distance disponibles sur le marché européen.

Here are the stakeholders affected by this deadline:

  • Software publishers: desktop or mobile applications, firmware, components sold separately,
  • Manufacturers of connected hardware: from household objects to network equipment,
  • Agencies and studios, who market under their own brand a product they have developed or had developed,
  • Importers and distributors, who brand a product with their label, or modify it before re-marketing it.

The obligation isn’t limited to new products. Article 69 of the regulation subjects to Article 14 products that were already on the market before December 11, 2027, the date when the text is fully applicable. Thus, software that has been on the market for several years and is still maintained enters the scope from day one.

For users, the obligation targets the supplier, not the company that utilizes the product. However, a client can demand from the manufacturer that security updates are available for the entire support period of the product, as ANSSI reminds in its FAQ dedicated to the CRA.

How to report an exploited vulnerability or a severe incident?

In practice, all notifications are to be submitted through a single platform, shared across the entire European Union, which is set to go live on September 11, 2026. This platform is managed by ENISA, the EU’s cybersecurity agency. The manufacturer must post an initial alert within 24 hours of discovering a vulnerability or incident, followed by a complete notification within 72 hours. Additional information is then added to this notification as required by the regulation.

Dashboard-style interface representing a unified incident reporting platform
La plateforme unique gérée par ENISA centralise les notifications d’incidents et de vulnérabilités.

Upon registering on the platform, the publisher specifies the country of their primary establishment. Then, with each notification, they must detail the countries affected by the reported vulnerability or incident. Each EU country has an incident response center tasked with receiving these reports. In France, this role is played by CERT-FR (French Computer Emergency Response Team), attached to ANSSI, which accesses the information provided by the manufacturer and forwards it to other concerned countries.

This center can also pass this information to the national market surveillance authority (ANFR for France). It is this authority that checks the compliance of marketed products and can enforce necessary corrective or restrictive measures.

A practical guide from the European Commission for applying the CRA

On July 27, 2026, the European Commission published “practical guidelines to assist manufacturers, developers, and businesses of all sizes in meeting their obligations under cyber resilience legislation.” This document clarifies the scope of products covered, the concept of substantial modification, and support periods. It includes 67 practical examples and decision trees designed for microenterprises and SMEs.

An intermediate step in the implementation of the CRA

The timeline for the regulation extends until the end of 2027, with September 11, 2026, being just one milestone. The next step involves compliance checks: significant class II products and critical products will need to be assessed by a notified body. In France, ANSSI serves as this notifying authority.

The notification procedure will be published soon by ANSSI. This will be based on the accreditation by Cofrac of the candidate body for notification. Accreditation is expected to open in the second half of 2026, and notifications should thus begin by the end of 2026, according to the FAQ.

The full implementation of the regulation will occur on December 11, 2027, with essential cybersecurity requirements, technical documentation, the EU declaration of conformity, and CE marking as stipulated by the CRA.

Similar Posts

Rate this post

Leave a Comment

Share to...