In 2022, we published a briefing considering the European Commission’s proposed Regulation (EU) 2024/2847, or the Cyber Resilience Act (CRA). Since then, the CRA has come into force with reporting obligations applying since 11 September 2026 and the full regime taking effect on 11 December 2027.
The CRA imposes cybersecurity obligations on manufacturers of “products with digital elements”, which is broadly defined to cover any software or hardware product and its remote data processing solutions, including software or hardware components placed separately on the EU market. This briefing outlines the key elements of the new regime.
Economic operators & their obligations
Manufacturers
A manufacturer is anyone who develops or manufactures a product with digital elements or has a product with digital elements designed, developed or manufactured, and markets them under their own name or trademark whether sold, monetised, or provided free of charge.
Manufacturers must conduct cybersecurity risk assessments, due diligence on third-party components integrated into their own products, comply with conformity assessment requirements, apply the CE marking, keep and maintain technical documentation, report incidents/vulnerabilities.
Importers
An importer is anyone established in the EU who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the EU.
Importers must verify manufacturer compliance with essential cybersecurity and vulnerability handling requirements, confirm that conformity assessments, technical documentation and CE marking are in place, withhold non-compliant products from the market, report vulnerabilities to the manufacturer and cooperate with market surveillance authorities.
Distributors
A distributor is anyone in the supply chain, other than the manufacturer or importer, that makes a product with digital elements available on the EU market without affecting its properties.
Distributors must verify CE marking, manufacturer and importer compliance with labelling, documentation and support period obligations, withhold non-compliant products from the market, report vulnerabilities to the manufacturer and cooperate with market surveillance authorities.
MSME support: Micro, small and medium-sized enterprises (MSMEs) can access targeted Member State support (training, sandboxes, testing) and EU funding through the Digital Europe Programme; simplified technical documentation may also be introduced for micro and small enterprises.
Conformity assessment for manufacturers
Options for conformity assessment
Manufacturers of products with digital elements which are neither “important” nor “critical” can assess those products’ compliance with the CRA’s requirements via an internal control procedure without the need for notified body involvement. “Important” products (Annex III) and “critical” products (Annex IV) face more rigorous conformity obligations. A Manufacturer of “important” products in Class I, that has applied relevant harmonised standards, common specifications or European cybersecurity certification schemes at “substantial” assurance level may self-assess conformity with the CRA. Where no such standards exist or the product falls into Class II the product must undergo third-party conformity assessment. Critical products must comply with a European cybersecurity certification scheme for conformity assessment purposes.
Harmonised standards
While European standardisation bodies have been formally requested by the European Commission to draft new or revise existing standards in support of the CRA, the standards referred to above which are needed to enable manufacturers’ conformity self-assessment are not yet available. While these standards are not yet available, manufacturers of products with digital elements should begin preparing compliance documentation in the meanwhile and ensure that they are ready to engage with the relevant requirements when they are published.
Notified bodies
Member States must notify the Commission and other Member States of bodies authorised to carry out conformity assessments under the CRA. No “notified bodies” have yet been appointed, meaning third-party conformity assessment is not yet available in practice. Once appointed, these notified bodies will be listed on the European Commission’s NANDO Information System.
Incident reporting obligations
Manufacturers must report actively exploited vulnerabilities and severe incidents through the European Union Agency for Cybersecurity’s (ENISA) Single Reporting Platform. A single submission notifies both ENISA and the Member State’s designated Computer Security Incident Response Team (CSIRT), with the receiving CSIRT disseminating the information to other affected Member States. Once reported, manufacturers must also inform affected users. These obligations apply to all products with digital elements on the Union market, including those placed on the market before 11 December 2027. Reporting timelines for manufacturers made aware of vulnerabilities and severe incidents are as follows:
| Reporting stage | Timeline / requirement |
| Stage 1 — Early Warning Notification | 24 hours |
| Stage 2 — Detailed Notification | Within a further 48 hours (72 hours from initial awareness) |
| Stage 3 — Final Report | Active exploits: within 14 days of a corrective measure being available Severe incidents: within 1 month of the Stage 2 notification |
Importers and Distributors are not subject to the same reporting obligations or timelines but must notify the manufacturer of vulnerabilities (weaknesses, susceptibility or flaw of a product with digital elements exploitable by a cyber threat) upon becoming aware of them. Products not in compliance with the CRA must also be recalled and withdrawn from the market.
Any natural or legal person may also voluntarily report vulnerabilities, threats, incidents and near misses via the Single Reporting Platform.
Irish implementation & enforcement
As a directly applicable EU Regulation, the CRA does not require transposition into Irish law. However, Ireland may need to rely on implementing measures to designate a national market surveillance authority, establish enforcement powers and set penalty regimes, although the precise form and timing of any such measures have not yet been confirmed.
In Ireland, the NCSC is responsible for providing national CRA guidance and supporting implementation of the Article 14 reporting regime.
Authorities appointed under the CRA have corrective or restrictive measures at their disposal such as the power to recall, prohibit, restrict or withdraw non-compliant products with digital elements from the market. They may also fine for non-compliance with security requirements. Depending on the obligation that has been breached these fines can be up to €15,000,000 or if the offender is an undertaking up to 2.5% of its worldwide annual turnover for the preceding financial year.
Guidance
Article 26 CRA requires the Commission to publish guidance to facilitate and ensure consistent implementation of the CRA.
On 27 July 2026, the Commission published its first practical guidance to assist economic operators in meeting their obligations. It addresses product scope (including remote data processing solutions and free and open-source software); what constitutes a “substantial modification”; how support periods should be applied; and how to meet reporting and risk assessment requirements.
In Ireland, the National Cyber Security Centre (NCSC) published supplementary guidance on 11 September 2026 to support organisations in understanding and fulfilling their reporting obligations under the CRA.
Next steps for economic operators & key dates
As the deadline for compliance with the CRA approaches, it will be important for economic operators to determine their role in the supply chain. The CRA imposes different obligations on manufacturers, importers and distributors. Therefore, organisations should assess and determine which obligations apply to them so that they may put in place the governance, resourcing and processes needed to meet those obligations.
| Date | Milestone |
| 10 December 2024 | CRA entered into force |
| 11 June 2026 | Entry into application of the provisions on the notification of Conformity Assessment Bodies Member States to designate notifying authorities |
| 11 September 2026 | Entry into application of reporting obligations |
| 11 December 2026 | Member States must strive to ensure, by this date, that there are a sufficient number of Conformity Assessment Bodies identified across Member States to avoid bottlenecks and hindrances to market entry |
| 30 October 2027 | Publication of additional standards and supporting materials to facilitate compliance with the CRA |
| 11 December 2027 | Full application of the Cyber Resilience Act |
Please contact a member of our Technology and Innovation Group if you would like assistance in determining your obligations under the CRA.
The authors would like to thank Cian Curley and Vivienne O’Keeffe for their contributions to this briefing.


