CRA reporting requirements are now in force – are your products ready?
The Cyber Resilience Act changes how connected products and software must be developed, documented and maintained. Download our guide for a practical overview of the requirements already in force – and what your organisation needs to do before December 2027.
Cybersecurity is becoming a product requirement
Since 11 September 2026, manufacturers have been required to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The first notification must be submitted within 24 hours.
But the reporting obligation is only the beginning. From 11 December 2027, the main CRA requirements will apply in full. Products within scope will need to meet requirements covering secure development, continuous vulnerability management, security updates, technical documentation and CE marking.
This is not a matter for legal or security teams alone. The CRA affects the entire product lifecycle – from leadership decisions and product classification to development, supply chains, incident management and support.
What you will learn from the guide
The guide gives leadership teams, boards, product owners and other decision-makers a clear overview of:
- which products and organisations may fall within the scope of the CRA
- which requirements already apply
- what must be reported within 24 and 72 hours
- how product classification affects the route to market
- what needs to be in place before 11 December 2027
- which questions boards and leadership teams should ask
- how to turn regulatory requirements into working product security.
You will also get a practical checklist to help your organisation prioritise the right actions – both now and over the longer term.åde på kort och lång sikt.
Download the guide!