Ein leuchtendes blaues Schild mit einem Vorhängeschloss-Symbol schwebt über einer detaillierten Leiterplatte.
RAHMAT / stock.adobe.com
2026-09-11 expert contribution

Cyber Resilience Act: Why September 11, 2026 is a Critical Date for Manufacturers

When discussing the Cyber Resilience Act (CRA), many companies initially focus on December 11, 2027. On that date, most requirements of the new EU regulation on the cybersecurity of products with digital elements will become mandatory.

However, September 11, 2026 already marks an important milestone. From this date onward, manufacturers must report actively exploited vulnerabilities and severe security incidents to the relevant authorities. As a result, the practical implementation of the CRA begins much earlier than many market participants expect.

“The CRA Is Not a 2027 Project. It Is a Task That Begins Today.”

Interview with Cybersecurity expert Alexander Matheus from the VDE Institute: What companies need to know about the Cyber Resilience Act now

Alexander Matheus, Cybersecurity expert at VDE Institute
VDE
Contact
Alexander Matheus

Mr. Matheus, many companies are talking about the CRA. Why is this topic so relevant right now?

Many companies are focusing exclusively on December 2027 while overlooking the fact that the first legal obligations become applicable as early as September 11, 2026.

By that date, manufacturers must have processes in place to identify, assess, and report actively exploited vulnerabilities and severe security incidents within the required timeframes. If such reports are not submitted after September 11, 2026, market surveillance authorities may impose penalties. In the most severe cases, these may amount to €15 million or 2.5% of annual global turnover, in accordance with Article 64(2) of the regulation.
 

What exactly must manufacturers report starting September 11, 2026?

Manufacturers must report actively exploited security vulnerabilities as well as severe security incidents that affect the security of a product with digital elements.

The reporting deadlines are very short. Companies must respond within narrow timeframes and submit the required notifications to the responsible authorities. Clear processes and defined responsibilities are therefore essential.
 

Many companies view 2027 as the key date for the Cyber Resilience Act. Why is September 11, 2026 still the first major milestone?

The September 2026 deadline serves as an important wake-up call for the entire industry. CRA requirements cannot be implemented at short notice. Vulnerability management, risk assessments, technical documentation, and security-by-design principles must be integrated into existing development and quality processes at an early stage.

In addition, a Software Bill of Materials (SBOM), which serves as a basis for determining the relevance of reported vulnerabilities, must be established. Companies that recognize September 11 as the first major milestone and take action now will create the foundation for a successful and efficient implementation of all remaining CRA requirements by 2027.
 

Which companies most often underestimate the impact of the CRA?

Primarily companies that have not previously had to deal extensively with cybersecurity regulations.

Many manufacturers of traditional consumer products are now developing connected products. As soon as a household appliance, for example, can be controlled via an app or exchanges data, CRA requirements may become relevant. Therefore, we generally recommend conducting an early applicability assessment.

We also observe that some companies are waiting for harmonized standards to be finalized before addressing the topic in depth. This can have serious negative consequences, as the time required to establish processes and prepare the necessary documentation may no longer be sufficient to meet the relevant deadlines.
 

What common mistakes are you currently seeing among manufacturers?

One of the most common misconceptions is that the CRA only affects software manufacturers or IT departments. In reality, the regulation applies to a wide range of connected products and requires collaboration across multiple functions, from product development and quality management to compliance and procurement.

Even products that are not directly connected to the internet but communicate locally may fall within the scope of the CRA. This is often overlooked, as are software applications and cloud services, which must also be considered as part of CRA compliance.

In addition, many companies underestimate the effort required for documentation, risk assessments, and vulnerability management. In the future, cybersecurity must be considered throughout the entire product lifecycle. Organizations that only begin implementation shortly before product launch will find it difficult to meet the requirements efficiently.

For this reason, we recommend establishing transparency early, assessing whether products are within scope, and systematically comparing existing processes against CRA requirements.
 

What should manufacturers do now?

The most important step is to conduct a comprehensive assessment.

Companies should ask themselves:

  • Which products fall under the CRA?
  • Have all relevant product elements been considered, including software and cloud applications?
  • Who is responsible for preparing the additional documentation?
  • Which cybersecurity measures are already in place?
  • Which security processes already exist, and which need to be established or adapted?
  • What cybersecurity measures are currently implemented for products?
  • How are vulnerabilities handled today?
  • Are reporting procedures formally defined?
  • Are suppliers sufficiently involved, and are contractual requirements in place?

The earlier these questions are answered, the more efficiently implementation can proceed.
 

What are the consequences of failing to comply with the CRA?

The Cyber Resilience Act is not simply another regulatory requirement. It is a mandatory prerequisite for placing many products with digital elements on the European market.

Companies that fail to comply face significant consequences. Market surveillance authorities may take action against products that do not meet CRA requirements. Measures can range from sales restrictions to product withdrawals from the market.

In addition, financial penalties and substantial reputational damage may result if security deficiencies become public or mandatory reporting obligations are not fulfilled.

Equally important is the business perspective. Manufacturers that do not adapt their cybersecurity processes in time risk delays in product launches, additional development effort, and rising compliance costs.

As mentioned earlier, market surveillance authorities may also impose penalties for non-compliance under Article 64 of the regulation. Depending on the severity of the infringement, penalties may reach up to €15 million or 2.5% of annual global turnover.


How the VDE Institute supports companies on their path to CRA compliance

The requirements of the Cyber Resilience Act go far beyond the technical security of a product. They require the integration of cybersecurity, product development, quality management, risk assessment, documentation, and regulatory compliance.

To support companies in implementing these complex requirements, the VDE Institute guides manufacturers throughout the entire compliance journey.

Services range from initial CRA readiness assessments and applicability analyses to detailed gap analyses, support with risk assessments, and reviews of technical documentation. The VDE Institute also performs product and system testing as well as comprehensive cybersecurity testing to identify potential vulnerabilities at an early stage and reliably assess security requirements.

In addition, the VDE Institute serves as an independent partner during the preparation and execution of conformity assessments. Manufacturers receive support in implementing regulatory requirements in a structured manner and establishing the prerequisites for future CE marking in accordance with the Cyber Resilience Act.

The goal is to provide companies with early transparency regarding their specific needs and a clear, practical roadmap toward CRA compliance. This enables organizations to implement requirements efficiently, minimize risks, and ensure the long-term marketability of their digital products.

Act Now Instead of Waiting How well prepared is your company for the new requirements?

The VDE Institute's CRA Checklist provides an initial assessment of the key requirements of the Cyber Resilience Act. It helps identify areas requiring action at an early stage and enables organizations to better evaluate their maturity level in cybersecurity, product development, and compliance.

Use the CRA Checklist as the first step toward CRA compliance and receive a reliable assessment of your current status. Upon request, our experts are available to review the results with you and discuss the next implementation steps.

Check it out now

Current Information about the VDE Institute