European Commission - Directorate General for Energy

09/11/2026 | Press release | Distributed by Public on 09/11/2026 01:50

Safer and more secure digital products

Hardware and software products are increasingly exposed to cyberattacks. From baby monitors and smartwatches to apps and computer programmes, products with digital elements are part of our daily lives. The Cyber Resilience Act (CRA)strengthens the cybersecurity of these products and better protects consumers and businesses from cyber threats.

As of 11 September 2026, manufacturers must reportanyactively exploited vulnerabilities and severe incidents that have an impact on the security of their products. They must submit an early warning within 24 hours, followed by a full notification within 72 hours. A final report must then be submitted no later than 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability, and within 1 month for a severe incident.

In practice, this means consumers can rely on faster notifications and stronger protection for their connected devices, such as door locking systems, keeping their home safe and secure in the event of a cyberattack.

The reporting obligations apply to all products with digital elements made available in the EU, including those already on the market. Manufacturers will submit their notifications through the CRA Single Reporting Platform, established and maintained by the European Union Agency for Cybersecurity.

The Commission published practical guidance to help manufacturers, developers, and businesses meet their obligations. National market surveillance authorities will ensure enforcement of the rules.

The Cyber Resilience Act builds on the EU cybersecurity strategy and the EU security union strategy. It aims to strengthen the EU approach to cybersecurity. The new rules require products with digital elements to be designed, updated, and maintained to protect users from security risks. TheCE marking will help them identify products that comply with the CRA requirements.

The main obligations introduced by the Act will apply from 11 December 2027, while the reporting obligations apply from 11 September 2026.

For more information

Cyber Resilience Act

Protecting your digital life

ENISA - FAQ

Digital economy and society

European Commission - Directorate General for Energy published this content on September 11, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 11, 2026 at 07:50 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]