Skip to main content van Berings

Insights

eu trade&compliance

EU Cyber Resilience Act: what to expect in the second half of 2026

The EU Cyber Resilience Act (CRA, Regulation 2024/2847) entered into force on 10 December 2024 and represents one of the European Union’s most significant legislative initiatives aimed at ensuring the security of products with digital components. Its primary objective is to mitigate the risks of cyber incidents and vulnerabilities throughout the entire product lifecycle, safeguarding users, businesses, and critical infrastructures, while harmonising the rules for accessing the European market. The regulation establishes essential cybersecurity requirements for all products with digital elements, imposing specific obligations on manufacturers, importers, and distributors.

The CRA covers a wide range of products, from hardware devices to embedded software, including networked devices, critical components, and IoT systems. The regulation follows a risk-based approach: the requirements and conformity assessment procedures vary depending on the criticality and complexity of the products, promoting security by design and by default. The CRA applies to all products placed on the EU market, including those already available prior to full application, scheduled for 11 December 2027.

Key deadlines and milestones in 2026

The second half of 2026 marks a critical period for the activation of the first obligations and the establishment of essential operational frameworks:

  • 11 June 2026: the legal framework for the notification of conformity assessment bodies (notified bodies) comes into effect. This is essential for manufacturers requiring third-party assessments. Notified bodies must be accredited by the competent authorities in the EU Member States before they can operate, ensuring sufficient capacity and avoiding bottlenecks.
  • 11 September 2026: manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents will apply to all products already on the EU market. The regulation requires rapid alerting, notification, and follow-up, using a centralized reporting system managed by ENISA.
  • Q3 2026: the first harmonised standards are expected to be finalised, providing manufacturers with reference standards for CRA conformity assessments and a presumption of conformity once the regulation is fully applicable.
  • 11 December 2026: the first notified bodies are expected to be operational, enabling companies to rely on third-party conformity assessments for critical or important products.

Objectives and impact of the CRA

The CRA pursues several strategic objectives:

  • Embedded product security: ensuring that security is an integral part of the design and lifecycle of digital products, reducing the risk of attacks and vulnerabilities.
  • EU-wide regulatory harmonisation: creating a uniform regulatory framework to simplify market access and reduce the risk of fragmentation among Member States.
  • Transparency and accountability: clear and traceable reporting obligations for vulnerabilities and incidents, including products already on the market, incentivising proactive risk management.
  • Promotion of technical standards: harmonised standards allow manufacturers to demonstrate compliance clearly, reducing litigation and uncertainty.

The regulation therefore impacts not only technical aspects but also organisational and legal processes, influencing product design, business operations, supplier management, and contractual arrangements.

Recent updates

On 3 March 2026, the European Commission published a draft guidance for public stakeholder consultation. The guidance clarifies operational aspects, including distinctions between tangible products and software, management of open-source software, technical support periods, and substantial changes to products already on the market. While not legally binding, this guidance serves as a practical reference for organising compliance and reporting.

Practical implications for businesses

Companies are already expected to:

  • Verify internal processes for reporting vulnerabilities and incidents within the prescribed deadlines;
  • Coordinate with notified bodies where third-party assessments are required;
  • Prepare documentation for CE marking;
  • Integrate harmonised standards into processes and manage legacy products already on the market.

Non-compliance may result in sanctions, suspension of CE marking, or exclusion from the market.

van Berings supports clients by providing strategic advice and legal guidance on CRA compliance. Through a consultative approach, we helps clients understand the requirements, prepare for upcoming deadlines, and manage risks related to the security of digital products, ensuring a proactive and informed approach in anticipation of the regulation’s full application in 2027.


DISCLAIMER: the content of this news is for informational purposes only and neither represents, nor can be construed as a legal opinion