Media Centre
Industry Spotlight & Insights

EU Cyber Resilience Act: New Reporting Duties and Key Compliance Requirements

4 October 2026

Recently, the reporting obligations under the EU Cyber Resilience Act (“CRA”) entered into force.

The CRA establishes a new, horizontal cybersecurity framework for hardware and software products made available on the EU market. It applies broadly to “products with digital elements” that connect, directly or indirectly, to a device or network, including software, mobile applications, connected devices and other products incorporating digital functionality, and is therefore particularly relevant to companies that develop, manufacture, distribute or import such apps, software and products.

The CRA makes cybersecurity an integral part of product compliance, imposing requirements relating to the design, development and production of products, as well as vulnerability handling throughout the applicable support period.

The CRA’s main requirements will apply from 11 December 2027. However, its mandatory reporting regime has already become applicable, as of 11 September 2026.

To assist companies in assessing the CRA’s relevance to their products and preparing for compliance, we have prepared our practical guide, which provides an overview of the CRA’s key provisions, implementation timeline and practical implications, taking into account the European Commission’s recent guidance.

For the guide >> click here

Have a question on this topic? We are here to help

Every case is unique. Let's talk about yours.

Contact Us Now