Access to the EU market
Products that cannot show they meet the Act cannot be placed on the EU market after the main obligations apply. Distributors and large buyers will ask for evidence in contracts before then.
The Cyber Resilience Act makes manufacturers answerable for the security of every connected product they sell in the EU. Reporting duties start 11 September 2026, so now is the time to find and close gaps.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting EU Cyber Resilience Act wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Products that cannot show they meet the Act cannot be placed on the EU market after the main obligations apply. Distributors and large buyers will ask for evidence in contracts before then.
Penalties reach €15M or 2.5% of worldwide turnover, and authorities can order recalls or withdrawal. Missed reporting is a breach in its own right.
A product exploited in the field and reported late damages trust fast. Showing a tested, supported product helps in sales and tenders.
Reporting starts 11 September 2026 and the main rules follow on 11 December 2027. Someone at executive level needs to own product security for the full support period.
Operating systems, mobile apps, desktop software and firmware sold in the EU fall in scope.
Routers, cameras, wearables, industrial controllers and smart home products carry the heaviest load.
They must check that manufacturers have done the work before placing products on the EU market.
Commercial use of open source brings duties for those who monetise it, with lighter rules for stewards.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
We map each in-scope product to the Annex I essential requirements and your vulnerability handling, and rank the gaps by risk.
Human-led testing of firmware, mobile and web apps, APIs, cloud back ends and update mechanisms, with proof of impact.
We check that secure defaults, access control, encryption and update controls work as described, not only that they exist.
Scope, method, findings and results organised so they can sit in your technical file and answer customer questions.
Clear fix guidance for your engineers, then a retest that confirms each issue is closed.
A plain-language summary of exposure, progress and decisions needed, for executives and non-technical readers.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
List every product and service, decide which are in scope and identify the likely product class for each.
Compare each product against the Annex I essential requirements and your current vulnerability handling.
Build the 24 hour, 72 hour and final report process, ahead of or in line with the September 2026 date.
Run penetration testing and review of firmware, apps and update channels, then fix and retest.
Assemble the risk assessment, SBOM and test evidence for the conformity route, and keep testing each release.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Ask for a product list with the likely class for each. Scope drives cost, route and timing.
Name one accountable executive and a deputy, and check the route works out of hours.
Ask for the SBOM status. Unknown components are unknown risk.
Confirm the support period is set, shown to buyers and funded.
Ask to see tested, dated proof, not only policies.
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets mandatory cybersecurity rules for products with digital elements: hardware and software that connect, directly or indirectly, to a device or network. That covers smart devices, routers, operating systems, mobile apps, firmware, and software sold on its own. It entered into force in December 2024.
Obligations fall mainly on manufacturers, who must build security in, handle vulnerabilities for the whole support period and prepare technical documentation. Importers and distributors have duties too. Some products are outside scope because other EU law already covers them, such as certain medical devices and vehicles, and pure software-as-a-service is generally out unless it is a remote data processing solution that a product needs to function.
The rules arrive in stages: conformity assessment body provisions from June 2026, reporting obligations from 11 September 2026 and the main obligations from 11 December 2027. If you sell connected products into the EU, buyers and distributors will start asking for evidence well before the last date.
The core of the Act is a set of essential requirements, a vulnerability handling process, reporting duties and proof that you did the work. Here is what each means in practice.
Products must be designed, developed and produced to an appropriate level of cybersecurity based on risk. That means no known exploitable vulnerabilities at release, secure default settings, protection from unauthorised access, encryption of data and minimal attack surface.
Manufacturers must find, document and fix vulnerabilities, ship security updates free of charge and promptly, run regular tests and reviews, publish a coordinated vulnerability disclosure policy and provide a contact point for reports.
From 11 September 2026, manufacturers must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a fuller notification within 72 hours and a final report later. Reports go to the designated national CSIRT and ENISA.
Most products can follow a self-assessment route. Important products (Class I and II) and critical products face stricter routes, and some need an external body. Either way you must keep technical documentation and a declaration of conformity for ten years.
You must set a support period of at least five years, unless the product is expected to be used for less, and tell users what it is. Instructions must explain secure use, where to report problems and how updates are delivered.
The Act expects manufacturers to test their products and to show that vulnerabilities are found and fixed. Penetration testing gives technical evidence for the file and a record that you acted on findings.
Penetration testing of firmware, apps, APIs and update mechanisms before release shows you looked for them.
The Act requires effective and regular tests of product security. Retests after fixes show the loop is closed.
Test scope, methods, findings and retest results sit naturally in the documentation you must keep for ten years.
Testing helps you understand which weaknesses could become reportable if exploited.
Remote data processing that a product needs to work can be in scope. Check each product, not just the company.
Reporting duties start in September 2026. The reporting process cannot be built in a week.
You cannot fix or report what you cannot see. Build the component list now.
Authorities and customers will expect real testing and fixes, not only documents.
In stages. Reporting obligations apply from 11 September 2026 and most other obligations, including the essential requirements, from 11 December 2027. Provisions on conformity assessment bodies started earlier, in June 2026.
Yes, software sold or distributed as a product with digital elements is in scope. Pure SaaS is generally outside unless it is a remote data processing solution a product needs in order to function.
Actively exploited vulnerabilities and severe incidents. Send an early warning within 24 hours, a notification within 72 hours and a final report afterwards, to the national CSIRT designated under the Act.
Up to €15M or 2.5% of worldwide annual turnover for breaching the essential requirements, up to €10M or 2% for other obligations, and up to €5M or 1% for incorrect information. Market surveillance authorities can also order recalls.
Many products can follow self-assessment. Important products in Class I and II, and critical products, face stricter routes, and some require an external body. Confirm your class early.
The Act requires regular testing of product security. A documented test, remediation and retest cycle gives you evidence for the technical file and for customers who ask.
No. It is general education about the regulation. Confirm your product class and obligations with qualified counsel.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.