The Cyber Resilience Act's First Deadline Is September 11, 2026 — Is Your Product Ready?

Most manufacturers have marked one date on the Cyber Resilience Act calendar: December 11, 2027, when the regulation applies in full. That focus is understandable, and it’s also a trap. The first legally binding obligation arrives more than a year earlier, on September 11, 2026, and it applies to connected products already on the market, not just future launches.

From that date, manufacturers of products sold in the EU must report actively exploited vulnerabilities and severe security incidents to European authorities on a strict clock. There’s no grace period tied to your next product cycle. If you build or ship connected measurement, control, laboratory or IT/multimedia equipment into the EU, the reporting regime reaches your current portfolio.

This article breaks down:

  • Why September 11, 2026 is the real first deadline, and what the Cyber Resilience Act requires on that date

  • How the CRA reshapes the CE mark for connected products, and which conformity route your product will follow

  • The practical steps to take now so a reporting obligation doesn’t catch your team unprepared

What the Cyber Resilience Act Actually Is

The Cyber Resilience Act, formally Regulation (EU) 2024/2847, is the EU's first horizontal cybersecurity law for "products with digital elements." It entered into force on December 10, 2024 and becomes fully applicable on December 11, 2027.

A product with digital elements is any hardware or software whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. That definition is deliberately broad. It captures networked instruments, industrial PCs, edge gateways, sensors, and the firmware and software that run on them.

The CRA sits alongside the directives that already govern the CE mark, rather than replacing them. A connected product that today needs the CE mark for EMC and safety will, from December 2027, also need to demonstrate cybersecurity conformity to carry that same mark.

Why September 11, 2026 Matters More Than December 2027

The reason the earlier date slips past so many teams is structural. The CRA's headline requirements, secure-by-design engineering, vulnerability handling, conformity assessment, and CE marking, apply from December 2027. But the reporting obligations under Article 14 apply from September 11, 2026, more than a year before full application.

This is set out in the regulation's own transition provisions and confirmed in the European Commission's Cyber Resilience Act guidance. The provisions covering the notification of conformity assessment bodies apply even earlier, from June 11, 2026, so the machinery for third-party assessment is already being stood up.

The takeaway is simple. The first thing the CRA asks of manufacturers is not a redesigned product. It’s the ability to detect and report a serious cybersecurity event quickly, and that capability has to exist by September 2026.

What You Actually Have to Report, and How Fast

Article 14 is event-triggered. The clock starts only when a manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of one of its products. When that happens, the reporting timeline is tight.

An early warning is due within 24 hours of becoming aware, followed by a full notification within 72 hours. A final report follows no later than 14 days after a corrective measure becomes available for an actively exploited vulnerability, or within one month for a severe incident.

Reporting is done once, through the ENISA Single Reporting Platform. The notification is addressed to the national Computer Security Incident Response Team where the manufacturer has its main establishment, and the information is made available to ENISA. Building the intake, triage and escalation path to hit a 24-hour window isn’t something you can improvise the day an incident lands.

The Retroactive Trap: Legacy Products Are Already in Scope

Here’s the detail that surprises most product teams. The September 2026 reporting duty isn’t limited to new or in-development products. It applies to every in-scope product with digital elements that has been placed on the EU market before full application and remains available.

A gateway you shipped in 2019 counts if it’s still in use and an exploitable vulnerability emerges in it. That reframes CRA readiness from a design-cycle problem into a portfolio problem. Teams that plan only around their next launch will have a gap across their installed base.

This is where an accurate product inventory earns its keep. You cannot report a vulnerability in a component you didn’t know your product contained, which is why component visibility across current and legacy products is the practical foundation of Article 14 compliance.

How the CRA Changes the CE Mark

From December 2027, the CE mark on a connected product will signify cybersecurity conformity in addition to the EMC, safety and radio conformity it already represents. To affix it, a manufacturer must complete a conformity assessment, satisfy the essential requirements in Annex I, and draw up an EU Declaration of Conformity.

The route depends on how the product is classified. Default products, the large majority, may self-assess through internal control. Important products, listed in Annex III and split into Class I and Class II, face stricter procedures, and critical products in Annex IV require a notified body in every case.

The Commission has since published the technical descriptions of these categories in Commission Implementing Regulation (EU) 2025/2392, so classification is now a concrete exercise rather than a guessing game. For manufacturers already navigating a coordinated CE campaign across the EMC Directive, Low Voltage Directive, and RED, the CRA becomes one more workstream to fold into the same technical file and Declaration of Conformity.

Does This Apply to Measurement, Control, Lab and IT Equipment?

For most of our core audience, the answer is yes. The scope test is connectivity, not category. If your instrument, controller or computing platform connects to a network or another device, directly or indirectly, it’s a product with digital elements.

Networked lab instruments, programmable controllers and connected measurement devices fall squarely inside the definition. So do the industrial and edge computing platforms that increasingly run IT architectures in the field, and the IT/multimedia hardware that has carried CE and FCC marks for years.

Cybersecurity isn’t entirely new territory for this equipment either. The obligation to demonstrate security safeguards already entered the CE framework through the Radio Equipment Directive's Article 3.3 requirements for connected radio products. The CRA extends that expectation horizontally, to connected products whether or not they contain a radio.

The Cost of Getting It Wrong

The CRA carries penalties on the scale manufacturers associate with data-protection law. Breaches of the essential requirements and of the Article 13 and 14 obligations can draw fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.

Beyond fines, market surveillance authorities can restrict or withdraw non-compliant products from the EU market. For a manufacturer whose revenue depends on European access, an enforcement action against the CE mark is a direct threat to sales, not a paperwork inconvenience.

The regulation does soften one edge for smaller players. Microenterprises and small enterprises may not be fined solely for missing the 24-hour early-warning deadline, though the underlying reporting expectation still stands.

What to Do Before September 11, 2026

The reporting obligation rewards preparation, and most of the groundwork is organizational rather than technical. Start with the work that makes an Article 14 report possible on short notice:

  • Inventory your connected products, current and legacy, and identify the components inside each one so you can tell quickly whether an emerging vulnerability affects you.

  • Confirm your reporting route. Determine your main establishment for CRA purposes, identify the relevant national CSIRT, and monitor ENISA's rollout of the Single Reporting Platform.

  • Stand up an intake and triage process so a report of an actively exploited vulnerability reaches the right people inside 24 hours, and watch public exploitation feeds so you learn about relevant events early.

  • Classify your products against Annex III and Annex IV now, so you know by December 2027 whether you can self-assess or will need a notified body.

Running this alongside your existing CE work is the efficient path. The same product data, technical documentation and Declaration of Conformity that support your EMC and safety compliance for measurement, control and laboratory equipment become the backbone for adding the CRA layer.

Turn the Deadline Into a Head Start

The manufacturers who treat September 11, 2026 as the real first milestone will move into full CRA application with reporting processes already proven and product classifications already settled. The ones anchored to December 2027 risk discovering the gap the hard way, when an exploited vulnerability surfaces in a product they didn’t realize was in scope.

Plan Your CRA Timeline With GME

GME is an ISO 17025-accredited EMC and product safety laboratory, and CE marking is what we help manufacturers achieve every day. The CRA's cybersecurity conformity is a distinct discipline from EMC and safety testing, so we help clients map where it fits into their overall CE roadmap and, for the security-specific analysis, work alongside our cybersecurity partner, XtraByte Consulting.

If you’re scoping a 2026 or 2027 product plan for the EU market, talk to a GME about CE mark testing and how the Cyber Resilience Act intersects with your existing compliance program. Share your target markets and a product overview, and we will help you build a plan that keeps EMC, safety, and cybersecurity moving together rather than colliding at the finish line.