Skip to main content

On September 11, the first real obligation of the European Cyber Resilience Act comes into force

11 September 2026

A new rule of the game for any product with software

Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), is the first European law to set horizontal cybersecurity requirements for all products with digital elements: any hardware or software product that connects, directly or indirectly, to another device or to a network.

It stems from a simple observation: for years, a home appliance has had to prove it was electrically safe in order to carry the CE marking, but no one required the same of its software. The CRA closes that gap and brings cybersecurity into the same CE marking framework we already know from directives such as the Low Voltage Directive or the Machinery Directive.

The regulation entered into force in December 2024 and its application is staggered: it arrives in phases, each with its own date and its own obligations.

What happens on September 11, 2026

This date marks the first real step of that staggered rollout: the obligation to notify authorities of actively exploited vulnerabilities and severe incidents affecting product security, within demanding deadlines:

  • 24 hours — early warning from the moment the issue becomes known.
  • 72 hours — notification detailing the nature of the vulnerability and the corrective or mitigating measures.
  • 14 days — final report once the fix is available.

The notification is sent simultaneously to the national coordinating CSIRT and to ENISA, through a single platform set up for that purpose.

There is an important nuance: this obligation also covers products already on the market, even if they were placed there before December 2027. There is no grace period for the installed base.

Alongside the notification, the manufacturer must inform affected users about the vulnerability and the measures they can take.

What happens on December 11, 2027

This is the date on which the regulation becomes fully and completely applicable. From that point on, products placed on the market will have to meet the essential cybersecurity requirements set out by the CRA: security by design, minimal attack surface, vulnerability management throughout the support period, an SBOM (software bill of materials), and a vulnerability reporting channel.

They will also need technical documentation, an EU declaration of conformity, and CE marking that also covers the cybersecurity dimension.

Products already placed on the market before that date are not subject to these new requirements, unless they undergo a substantial modification.

Our position at Conatec

Conatec manufactures electronic controllers with embedded software that are integrated into equipment made by OEM manufacturers. We have spent months working on our adaptation to the CRA, with a two-pronged approach.

Regarding the installed base: our legacy products are deployed in non-critical environments — they are not part of essential infrastructure, nor do they fall under the "important" or "critical" product categories defined by the regulation — and they operate mainly over industrial fieldbuses with no direct exposure to the internet. The regulation expressly recognizes this transitional regime: these devices are not subject to the new essential requirements as long as they are not substantially modified.

What we have put in place is an internal vulnerability monitoring and notification procedure, with a designated responsible function, a reporting channel, and a subscription to leading vulnerability intelligence sources.

Regarding new products: our current product platform was designed following the security-by-design principles that the CRA turns into a legal requirement — verified boot, controlled firmware updates, minimized attack surface, software component traceability via SBOM, and a defined vulnerability management cycle. This is the foundation on which we are building our conformity file ahead of December 2027.

What this means for our customers

If you integrate our controllers into your equipment, your company is the manufacturer of the final product and assumes its own obligations under the CRA.

Our role is to make it easy for you: clear technical information about the component, proactive communication in the event of any relevant vulnerability, and a two-way coordination channel so that your notification deadlines can be met.

We are opening this coordination process with our OEM customers. If you would like to get ahead of it, get in touch with us.

* This article is for informational purposes only and does not constitute legal advice.