A quick guide to the EU Cyber Resilience Act changes coming this September…

What is the EU Cyber Resilience Act?

Cyber Security laws for technology businesses that operate in the EU are about to change. ‍ ‍

The EU Cyber Resilience Act, or CRA, is a new law intended to make connected products and software safer. It places responsibility on manufacturers to make sure their products are secure, vulnerabilities are fixed and customers are warned when serious security problems arise.

‍ It covers products with a digital element sold or supplied in the EU, such as:‍ ‍

  • Software and mobile applications

  • Routers, firewalls and network equipment

  • Smart cameras, sensors and tracking devices

  • Connected machinery and laboratory equipment

  • Software built into another product

  • Cloud services that are essential to how a connected product works

‍ Although it is an EU law, it can apply to a UK business if that business supplies an affected product into the EU.

What changes are happening 11 September 2026?

‍ ‍From 11 September 2026, manufacturers must report: ‍ ‍

  • A vulnerability in their product that criminals are known to be actively exploiting.

  • A serious cyber incident affecting the security of their product.

‍ The manufacturer must:

  • Send an initial warning within 24 hours of becoming aware.

  • Provide more information within 72 hours.

  • Submit a final report once the investigation or corrective work is complete.

  • Inform affected customers and tell them what action to take.

Reports will be made through the EU’s CRA Single Reporting Platform.

This reporting duty also covers affected products already on the EU market. It is not limited to new products launched after 11 September. The rest of the CRA, including secure design requirements, technical documentation, conformity assessments and CRA-related CE marking, becomes fully applicable on 11 December 2027.

Who is affected?

The CRA is based on what a business supplies, not the sector it operates in. A business is likely to be affected if it develops, manufactures or sells connected products or commercial software into the EU. Simply using laptops, Microsoft 365, software or an MSP does not make a business subject to the CRA. Some products, including certain regulated medical devices, vehicles and aviation products, may be covered by separate industry legislation and can be excluded from the CRA.

Five simple actions affected businesses should take

Work out whether the CRA applies
List the software, hardware and connected products supplied into the EU. Identify which company is legally treated as the manufacturer.

Decide who will report an incident
Nominate the people responsible for deciding whether something must be reported and who has authority to submit the report.

Create a 24-hour reporting process
Make sure security incidents and actively exploited vulnerabilities can be investigated and escalated quickly, including during weekends and staff holidays.

Prepare to contact affected customers
Maintain accurate customer contact details and prepare a security notice explaining the problem, the risk and what customers need to do.

Start preparing for full compliance
Review how products are designed, tested, patched and supported. Start documenting product risks, software components, vulnerabilities, security updates and support periods before the wider requirements apply in December 2027.

The big takeaway

‍From 11 September 2026, UK businesses that supply software or connected products into the EU must be ready to identify and report serious product security problems within 24 hours.They do not need to complete every part of CRA compliance by September, but they must have the reporting process working by that date.

‍ ‍If you’re preparing for the upcoming changes and would like to discuss Cyber Security, get in touch to speak to a FACT3 expert today.

Next
Next

FACT3 Learning and Development Advisor to compete in Ironman event…