Alexander Matheus, Cyber Security Experte im VDE Institut

Alexander Matheus, Senior Expert Smart Technologies and Information Security at VDE Institute

| VDE
2026-09-11 press release

Cyber Resilience Act: First Reporting Requirements Take Effect

Things are getting serious for manufacturers of digital products: As of September 11, 2026, the first legal requirements of the Cyber Resilience Act (CRA) have taken effect. Companies must have processes in place to detect and report actively exploited vulnerabilities and serious security incidents in a timely manner. The VDE warns that violations could result in fines running into the millions.

(Frankfurt am Main, September 11, 2026) The first legal requirements of the Cyber Resilience Act (CRA) have been in effect since September 11, 2026. The Association for Electrical, Electronic & Information Technologies (VDE) is reminding the public of this. “Effective immediately, manufacturers must have processes in place that enable them to detect, assess, and report actively exploited vulnerabilities and serious security incidents in a timely manner,” says Alexander Matheus, Senior Expert for Smart Technologies and Information Security at the VDE Institute. If the required reports are not submitted on time, sanctions by market supervisory authorities may be imposed. The CRA provides for fines of up to 15 million euros or 2.5 percent of global annual revenue.

“Actively exploited security vulnerabilities and serious security incidents that compromise the security of a product with digital elements must be reported,” explains Matheus. “The deadlines are very tight. Companies must respond within narrow time frames and submit the appropriate reports to the relevant authorities. That is why clear processes and responsibilities are crucial.”

The CRA Entails a Significant Need for Adaptation

Under the CRA, only products with digital elements will be eligible for a CE marking in the future if they meet the prescribed cybersecurity requirements. Only then may they be placed on the European market. This affects manufacturers of products with digital elements, including, for example, connected household appliances, industrial control systems, software products, or components in the Internet of Things. For many companies, the CRA entails a significant need for organizational and technical adjustments. In addition to increased documentation requirements, development processes must be adapted. Furthermore, continuous vulnerability management will be necessary. Monitoring suppliers and subcontractors is also becoming increasingly important.

Even though most requirements do not take effect until December 2027, the VDE believes that affected companies should not delay implementation any further. “Those who view September 11 as the first major milestone and take action now will lay the groundwork for a successful and efficient implementation of the remaining CRA requirements by 2027,” says cybersecurity expert Alexander Matheus, looking ahead to the coming months.
Companies should already have a clear understanding of which of their products fall under the CRA, who is responsible for preparing the required documentation, and which processes apply to reporting vulnerabilities and security incidents. “The sooner these questions are answered, the more efficiently implementation can take place,” says Matheus.

Transparency Regarding Individual Action Requirements

To support companies in implementing these complex requirements, the VDE Institute guides manufacturers through the entire compliance process. The range of services extends from initial CRA readiness assessments and impact analyses to detailed gap analyses, as well as support with risk assessments and the evaluation of technical documentation. In addition, the VDE Institute conducts product and system audits as well as comprehensive cybersecurity tests to identify potential vulnerabilities early on and reliably assess security requirements.

The goal is to provide companies with early transparency regarding their specific needs for action and to offer a clear, practical roadmap to CRA compliance. This enables companies to systematically meet the CRA’s requirements and ensure the long-term marketability of their products.

Further information and quotes from Alexander Matheus can be found in this interview on the VDE website.

About the VDE Institute 

The VDE mark is synonymous with safety and quality in electrical devices, components and systems for more than 100 years. The VDE Institute - a subsidiary of the VDE Group - is a worldwide partner for industry customers, business, government authorities, the electrical trade and consumers. More than 100,000 devices per year are subjected to product, quality and safety tests by the VDE Institutes independent testing engineers before they receive the VDE mark. Around the globe, VDE experts monitor more than 7,000 production facilities. Cooperation agreements with more than 50 countries ensure that the tests performed by the VDE Institute are internationally recognized. 200,000 types of products with millions of model variants bear the VDE mark worldwide. The VDE Testing and Certification Institute GmbH, a non-profit organization, employs more than 500 people in Offenbach am Main.

For more information, visit www.vde.com/institute

About VDE

VDE, one of the largest technology organizations in Europe, has been regarded as a synonym for innovation and technological progress for more than 130 years. VDE is the only organization in the world that combines science, standardization, testing, certification, and application consulting under one umbrella. The VDE mark has been synonymous with the highest safety standards and consumer protection for more than 100 years. 

Our passion is the advancement of technology, the next generation of engineers and technologists, and lifelong learning and career development “on the job”. Within the VDE network more than 2,000 employees at over 60 locations worldwide, more than 100,000 honorary experts, and around 1,500 companies are dedicated to ensuring a future worth living: networked, digital, electrical.  
Shaping the e-dialistic future. 

The VDE (VDE Association for Electrical, Electronic & Information Technologies) is headquartered in Frankfurt am Main. For more information, visit www.vde.com

Kontakt
Press Officer