NMS - New Media Service GmbH
Fertigungsmaschine mit Steuerterminal in einer hellen Produktionshalle, zwei Personen an der Bedienung
AI-generated

Cyber Resilience Act: first establish whether it applies to you

The CRA reporting obligations take effect on 11 September 2026. They apply to manufacturers of products with digital elements, not to everyone who uses software.

Book a consultation

ISO 27001 · Microsoft Solutions Partner

The reporting obligations of the Cyber Resilience Act take effect on 11 September 2026. They apply to manufacturers of products with digital elements, not to everyone who uses software. We first establish whether you are affected, and only then support the implementation.

Does the Cyber Resilience Act apply to my company?

Only if you place products with digital elements on the EU market commercially. Anyone who merely uses software internally is out of scope, and that applies to most mid-sized companies.

You are affected if you, for example:

  • sell machines or devices containing software, including as a supplier

  • place an application under your own name on the market

  • import hardware with firmware and distribute it under your own name

  • license software as a product rather than providing it as a service

You are not affected if you:

  • use software only within your own operations

  • provide IT services without placing a product on the market

  • resell third-party products without placing them on the market under your own name

What applies from 11 September 2026?

Initially only the reporting obligations under Article 14. The full requirements for product security, conformity assessment and CE marking follow on 11 December 2027.

  • 24 hours: early warning to the relevant CSIRT and to the European agency ENISA

  • 72 hours: notification with the details known at that point

  • 14 days or one month: final report

Does the reporting obligation cover older products?

Yes. The regulation exempts legacy products from the security requirements, but not from the reporting obligations. Anything placed on the market before 11 December 2027 need not meet the Annex I requirements: it must still be reported.

How do we proceed?

  • Scope: what do you place on the market, under whose name, in which market? The result is a written assessment, even if it says „not affected"

  • Inventory: which products, which software components, which suppliers

  • Reporting path: who reports, to whom, within which deadline, using which template

  • Exercise: a dry run with a fictitious vulnerability, so the path holds when it matters

  • Ongoing operation: monitoring your own product components for known vulnerabilities

What we do not do

We do not make you CRA-compliant. Nobody can: the regulation obliges the manufacturer, and that responsibility stays with you. We support the implementation, set up the reporting path and rehearse it with you: you sign the declaration.

How do we start?

With a thirty-minute conversation that establishes whether the Cyber Resilience Act applies to you. If it does not, you have a written justification for your records. Book an appointment.