Cybersecurity / Source date:

EU Cyber Resilience Act: Product Security Becomes Mandatory

The EU Cyber Resilience Act makes product security mandatory for hardware and software sold in Europe — extending cybersecurity obligations beyond data protection into product design itself.

Illustration of an engineer reviewing a connected controller and component documentation.

The Cyber Resilience Act entered into force last December and most of the organisations it will affect have not started, because the substantive obligations do not bite until December 2027 and the reporting duties until September 2026. That reading of the timetable is defensible for a company that only buys software. It is a serious miscalculation for any company that sells a product with digital elements, which is a much broader category than it sounds. The Act does not regulate software companies. It regulates products placed on the European market that contain software — and that includes industrial equipment, building systems, connected devices, and anything embedded in a machine you manufacture.

If your product has a network interface and you sell it into the European Union, you are now a manufacturer of a product with digital elements, whatever your company calls itself

Here is what the obligations actually require and what the realistic preparation sequence looks like from this point.

Cyber Resilience Act application datesDates verified against the European Commission overview. Scope, exceptions and conformity route require product-specific legal assessment.

Each event links to its supporting source. This is a selective chronology, not a performance comparison.

What the Act requires of manufacturers

Security by design and by default, documented as a process rather than asserted as a property. You will need to show the risk assessment, the design decisions and the testing. Vulnerability handling for the support period, meaning a coordinated disclosure policy, a route for researchers to report, and the capacity to produce and distribute security updates for the whole declared support life — a minimum of five years for most products. A software bill of materials, maintained, covering at least the top-level dependencies. Most manufacturers cannot currently produce one for a product shipped three years ago. Incident and vulnerability reporting. From 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported, with an early warning within twenty-four hours. That is the first hard date and it is fourteen months away. CE marking and conformity assessment, with third-party assessment by a notified body for products in the important and critical categories.

The four things that will actually be hard

The support period commitment, because it is a multi-year financial obligation attached to a product you sell once. Pricing has not caught up with that anywhere. The bill of materials for existing products, which requires reconstructing a dependency tree nobody documented, often including components from suppliers who have since disappeared. The twenty-four hour early warning, which requires a detection and decision process that most industrial manufacturers do not have and cannot improvise. And the supply chain, because your obligations flow to your component suppliers, and the smaller ones will need help meeting them.

Where to be this time next year

By September 2026 you need the reporting capability working. Realistically that means: product inventory and scope determination this year, a bill of materials process for anything in active development, a disclosure policy published, and the incident reporting process built and rehearsed by the middle of next year. The conformity assessment work can follow, but not by much, because notified body capacity will be tight and the 2027 date arrives with everyone queuing at once.

Practical Guidance for Cyber Resilience Act Compliance Assessment

  • Determine scope first: which products, which category, which obligations.
  • Publish a coordinated disclosure policy — cheap and visible.
  • Build the bill of materials process into current development now.
  • Cost the support period and reflect it in product pricing.
  • Stand up the reporting process well before September 2026.
  • Flow requirements to component suppliers in contracts this year.
  • Book notified body engagement early; capacity will be scarce.
  • Rehearse a twenty-four hour early warning with real people.

The Regional Angle

The first point is that this reaches regional manufacturers and integrators who have never considered themselves subject to European regulation. Gulf-based producers of industrial equipment, building management systems, metering, marine and oil field equipment, and increasingly connected consumer products all place goods on the European market, sometimes through a distributor who has not raised the issue. The obligation attaches to the product entering the market, not to where the company sits, and a distributor or importer arrangement does not transfer the manufacturer's duties. Regional exporters should establish this year whether their European route to market makes them a manufacturer, an importer or neither, because the three positions carry very different obligations and most have never been asked. The second concerns component sourcing patterns common in this region, which make the bill of materials harder than the European average. Regional manufacturers frequently integrate modules sourced from Asian suppliers with limited software documentation, and firmware provided as a binary with no dependency manifest. Producing a credible bill of materials for such a product means either obtaining information the supplier has never supplied or performing binary analysis. Start that conversation with suppliers now and make it a condition of new supply agreements, because renegotiating an existing relationship in 2027 under regulatory pressure gives you no leverage at all. The third is about what this does to the regional market as a whole, and it is not only a cost. Gulf national programmes in industrial development and localisation are pushing domestic manufacturing up the value chain, and European product-security requirements provide an externally validated standard to build toward — the same discipline that satisfies the Act tends to satisfy the security expectations of Gulf utilities, national oil companies and defence procurement. Manufacturers treating this as an export compliance cost will spend the money and get compliance. Those treating it as a product engineering standard will spend the same money and get a differentiator in their home market, where sovereign buyers are asking similar questions with less precision.

The objection worth taking seriously

The strongest objection is that acting now is premature and expensive. The technical standards that will define conformity are still being drafted, notified body designation is incomplete, guidance on scope boundaries is thin, and companies that build compliance programmes against an unfinished framework have historically had to rebuild them. The sensible course is to monitor, wait for the harmonised standards, and start in earnest in 2026 with eighteen months still available — which is what most competent regulatory affairs functions are advising. That is sound advice about the conformity assessment work specifically, and building a CE marking programme against draft standards would indeed be wasteful. It does not apply to the other half of the obligations. The bill of materials, the disclosure policy, the support period costing and the incident reporting process are not standards-dependent — they are operational capabilities whose shape is already clear from the Act's text, and each takes longer to build than to decide. The reporting duty in particular arrives in September 2026, which is before the wait-and-see plan even begins. And the support period commitment has to reach product pricing decisions being made now for goods that will still be on sale when the obligation lands. Wait on conformity assessment. Do not wait on the things whose cost is time rather than interpretation.

Common Questions

Does this apply to software we only use internally?

No. The Act covers products placed on the market. Internal tools and bespoke systems built for your own use are out of scope, though your suppliers' products are in it.

What counts as an important or critical product?

The Act lists categories, weighted toward security functions and infrastructure components. Determine your classification early, because it decides whether you need a notified body.

How long must we support a product?

The expected product lifetime, with five years as the general minimum. The obligation is a real cost and should be in the price.

What should we expect over the next twelve months?

Expect harmonised standards work to advance through this year and next, with guidance on scope boundaries following. Expect notified body capacity to become a visible constraint. Expect European customers to start asking suppliers for bills of materials well before the deadline. And expect the September 2026 reporting duty to catch out manufacturers who planned around the 2027 date.


Cyber Resilience Act Compliance Assessment — we establish whether the Act reaches your products, then build the capabilities whose cost is time rather than interpretation.

Continue reading

Talk to OPS

Start with the operating problem.