Cyber ​​​​Resilience Act: What changes after September 11, 2026

The Cyber ​​Resilience Act (CRA) is the first European Union regulation to introduce mandatory cybersecurity requirements for all connected hardware and software products, applying the principle of secure by design throughout the product's entire lifecycle.

Cyber Resilience Act: What changes from September 11, 2026

September 11, 2026, marks one of the first operational deadlines of the Cyber ​​Resilience Act. From that date, the reporting obligations set out in Article 14 of the Regulation will begin to apply.

Sending communications to CSIRT and ENISA

Article 14 requires the entities involved in the CRA (the manufacturers) to report to the CSIRT and ENISA vulnerabilities in their products when active exploitation is detected, as well as serious incidents that compromise their security. The obligations will apply from 11 September 2026 also to products already placed on the market and falling within the scope of the CRA, thus anticipating the full application of the Regulation scheduled for December 2027.

Reporting template

The reporting model envisaged by the CRA follows the progressive evolution of the analysis, from the first early warning within 24 hours of awareness to the full report to be sent within 14 days of the availability of a corrective or mitigation measure. For a serious incident, the final report must be submitted within one month of the initial notification. The reporting process therefore does not end with the first report, but requires ongoing analysis and updating of information as knowledge of the event increases.

Component vulnerabilities

Another clarification concerns components developed by third parties, for which the exploited vulnerability must be evaluated against the product into which the component was integrated. However, the obligations relating to vulnerability management and, where applicable, communication to the entity producing or maintaining the affected component remain applicable. This clarification is relevant in products that depend on a large number of third-party components, because evaluation requires actual knowledge of the dependencies and how they are used in the product.

The Cyber Risk Assessment

The guidelines strengthen the role of the cybersecurity risk assessment required by Article 13, requiring that the residual risk be assessed in relation to the appropriate security level for the product and its foreseeable use.
Risk tolerance and economic considerations alone do not justify failing to address significant risks, which must be assessed while also considering external dependencies and third-party components.

How we support CRA compliance

The ESRA platform provides manufacturers with a concrete information base to understand, assess, and manage cyber risk, transforming knowledge of the technological environment into useful elements to support the CRA compliance process.

Recommended Articles

September 8, 2025

DORA and Business Continuity: the new pillars for banks and insurance companies

The context: why finance cannot afford fragility Operational continuity is now one of the essential conditions for the banking, financial, and insurance world. A prolonged downtime […]