Cyber Resilience Act: Companies Face First 2026 deadline

2026.07.24 | News

cyber security 3400657 1920

The EU Cyber Resilience Act (CRA) is set to shift cybersecurity from an IT concern to a product-compliance obligation. It applies to hardware and software products with digital elements made available on the EU market, including final products, separately marketed components and certain remote data processing solutions, if their intended purpose or reasonably foreseeable use involves a direct or indirect data connection to a device or network. 

Most obligations will apply from Dec. 11, 2027. But the first operational milestone comes sooner: starting Sep. 11 this year, manufacturers must report actively exploited vulnerabilities and severe product security incidents. The reporting duty also covers products already made available in the EU.

For manufacturers, the starting point is classification. Products may be unlisted or fall into an important product category. Important products include, among others, browsers, password managers, VPNs, operating systems, routers, modems, switches, smart-home security products, connected toys and certain health-tracking wearables. Class II important products include hypervisors, container runtimes, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers. Critical products include hardware devices with security boxes, such as physical payment terminals and hardware security modules, as well as smart meter gateways and smartcards or similar secure elements. The product’s core functionality, not the mere presence of a component, drives the classification.

Manufacturers must conduct cybersecurity risk assessments, design and build products that meet essential cybersecurity requirements, ensure that products are not placed on the market with known exploitable vulnerabilities, and maintain vulnerability-handling processes. They must also set a support period, generally at least five years unless a shorter expected product lifetime applies, and provide security updates, generally free of charge, during that period.

Transparency will also become a compliance issue. Products must be accompanied by clear user information, including the intended purpose, security-relevant features, foreseeable cybersecurity risks, a support period end date and instructions for secure installation, updates and decommissioning, including data removal.

Documentation and Security

Technical documentation will matter as much as security engineering. Before placing a product on the market, manufacturers must carry out the relevant conformity assessment, draw up an EU declaration of conformity and affix the CE marking in line with the CRA. Documentation must be kept available for market surveillance authorities for 10 years after the product is placed on the market or for the support period, whichever is longer.

Importers and distributors are not passive intermediaries. They must check that the manufacturer has complied with the relevant conformity, CE marking and documentation obligations and must not place or make available non-compliant products. They also have notification and cooperation duties if they become aware of vulnerabilities or cybersecurity risks. If they sell a product under their own name or trademark, or substantially modify a product already on the market, they may be treated as manufacturers.

The cost of getting this wrong can be high. The CRA provides for fines of up to EUR 15 million or 2.5% of worldwide annual turnover for the most serious breaches, up to EUR 10 mln or 2% for other economic-operator obligations, and up to EUR 5 mln or 1% for misleading or incomplete information. Under the Hungarian implementing rules, repeated infringements may trigger a fine of at least 1.5 times the previous penalty, subject to the statutory maximum.

Companies should use the period before September to map and classify products, review supply-chain contracts, define support periods, prepare incident-reporting processes and test how vulnerability information will move from engineering to legal teams, management and regulators. The compliance deadline may still appear distant, but the data needed to meet it is already being created today.

Source: bbj.hu

Share This
Hajdú-Bihar Vármegyei Kereskedelmi és Iparkamara
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.