
Cyber Resilience Act: first establish whether it applies to you
The CRA reporting obligations take effect on 11 September 2026. They apply to manufacturers of products with digital elements, not to everyone who uses software.
ISO 27001 · Microsoft Solutions Partner
The reporting obligations of the Cyber Resilience Act take effect on 11 September 2026. They apply to manufacturers of products with digital elements, not to everyone who uses software. We first establish whether you are affected, and only then support the implementation.
Does the Cyber Resilience Act apply to my company?
Only if you place products with digital elements on the EU market commercially. Anyone who merely uses software internally is out of scope, and that applies to most mid-sized companies.
You are affected if you, for example:
sell machines or devices containing software, including as a supplier
place an application under your own name on the market
import hardware with firmware and distribute it under your own name
license software as a product rather than providing it as a service
You are not affected if you:
use software only within your own operations
provide IT services without placing a product on the market
resell third-party products without placing them on the market under your own name
What applies from 11 September 2026?
Initially only the reporting obligations under Article 14. The full requirements for product security, conformity assessment and CE marking follow on 11 December 2027.
24 hours: early warning to the relevant CSIRT and to the European agency ENISA
72 hours: notification with the details known at that point
14 days or one month: final report
Does the reporting obligation cover older products?
Yes. The regulation exempts legacy products from the security requirements, but not from the reporting obligations. Anything placed on the market before 11 December 2027 need not meet the Annex I requirements: it must still be reported.
How do we proceed?
Scope: what do you place on the market, under whose name, in which market? The result is a written assessment, even if it says „not affected"
Inventory: which products, which software components, which suppliers
Reporting path: who reports, to whom, within which deadline, using which template
Exercise: a dry run with a fictitious vulnerability, so the path holds when it matters
Ongoing operation: monitoring your own product components for known vulnerabilities
What we do not do
We do not make you CRA-compliant. Nobody can: the regulation obliges the manufacturer, and that responsibility stays with you. We support the implementation, set up the reporting path and rehearse it with you: you sign the declaration.
How do we start?
With a thirty-minute conversation that establishes whether the Cyber Resilience Act applies to you. If it does not, you have a written justification for your records. Book an appointment.

Solutions in a new dimension.
One conversation is enough to find out where IT, Microsoft Cloud and AI can take real weight off day-to-day business.
Your contact: Jan Emmerich, Managing Director