(Frankfurt am Main, September 11, 2026) The first legal requirements of the Cyber Resilience Act (CRA) have been in effect since September 11, 2026. The Association for Electrical, Electronic & Information Technologies (VDE) is reminding the public of this. “Effective immediately, manufacturers must have processes in place that enable them to detect, assess, and report actively exploited vulnerabilities and serious security incidents in a timely manner,” says Alexander Matheus, Senior Expert for Smart Technologies and Information Security at the VDE Institute. If the required reports are not submitted on time, sanctions by market supervisory authorities may be imposed. The CRA provides for fines of up to 15 million euros or 2.5 percent of global annual revenue.
“Actively exploited security vulnerabilities and serious security incidents that compromise the security of a product with digital elements must be reported,” explains Matheus. “The deadlines are very tight. Companies must respond within narrow time frames and submit the appropriate reports to the relevant authorities. That is why clear processes and responsibilities are crucial.”
The CRA Entails a Significant Need for Adaptation
Under the CRA, only products with digital elements will be eligible for a CE marking in the future if they meet the prescribed cybersecurity requirements. Only then may they be placed on the European market. This affects manufacturers of products with digital elements, including, for example, connected household appliances, industrial control systems, software products, or components in the Internet of Things. For many companies, the CRA entails a significant need for organizational and technical adjustments. In addition to increased documentation requirements, development processes must be adapted. Furthermore, continuous vulnerability management will be necessary. Monitoring suppliers and subcontractors is also becoming increasingly important.
Even though most requirements do not take effect until December 2027, the VDE believes that affected companies should not delay implementation any further. “Those who view September 11 as the first major milestone and take action now will lay the groundwork for a successful and efficient implementation of the remaining CRA requirements by 2027,” says cybersecurity expert Alexander Matheus, looking ahead to the coming months.
Companies should already have a clear understanding of which of their products fall under the CRA, who is responsible for preparing the required documentation, and which processes apply to reporting vulnerabilities and security incidents. “The sooner these questions are answered, the more efficiently implementation can take place,” says Matheus.
Transparency Regarding Individual Action Requirements
To support companies in implementing these complex requirements, the VDE Institute guides manufacturers through the entire compliance process. The range of services extends from initial CRA readiness assessments and impact analyses to detailed gap analyses, as well as support with risk assessments and the evaluation of technical documentation. In addition, the VDE Institute conducts product and system audits as well as comprehensive cybersecurity tests to identify potential vulnerabilities early on and reliably assess security requirements.
The goal is to provide companies with early transparency regarding their specific needs for action and to offer a clear, practical roadmap to CRA compliance. This enables companies to systematically meet the CRA’s requirements and ensure the long-term marketability of their products.
Further information and quotes from Alexander Matheus can be found in this interview on the VDE website.