Key provisions of the Cyber Resilience Act (CRA) become applicable on 11 September 2026

As of 11 September 2026, the reporting obligations under the Cyber Resilience Act (CRA) become applicable. Manufacturers of products with digital elements now need to have procedures in place to be able to quickly report actively exploited vulnerabilities and serious security incidents.

The Cyber Resilience Act (CRA) aims to strengthen cybersecurity within the EU through mandatory requirements for products with digital elements. Products must be secure from the design stage onwards ("secure by design") and protected continuously throughout their entire lifecycle. The regulation harmonises the rules between the EU member states and imposes requirements on transparency regarding products' security properties, as well as prescribing responsibility for addressing vulnerabilities.

The regulation covers a broad range of products, both hardware (e.g. IoT devices and industrial control systems) and software (e.g. apps and computer programs).

The regulation will mainly apply from 11 December 2027, but as early as 11 September 2026 the reporting obligations for manufacturers will start to apply. Manufacturers must notify the coordinating CSIRT and the EU cybersecurity agency ENISA of any actively exploited vulnerability in a product with digital elements that the manufacturer becomes aware of. In Sweden, CERT-SE at the National Cyber Security Centre (NCSC) is the national CSIRT.

The notification takes place in three steps: an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure has become available. The same model applies to serious incidents affecting the security of the product.

Manufacturers covered by the CRA must already now have operational routines and internal processes in place to detect, assess and report actively exploited vulnerabilities and serious security incidents within the short deadlines. This includes having designated contact channels to the CSIRT and ENISA and being able to use the joint reporting platform, even though the products do not yet need to fully comply with the essential cybersecurity requirements (these will only apply from 11 December 2027).

Non-compliance may result in sanctions, including fines of up to 2.5 percent of global annual turnover.

Please feel free to contact Advokatfirman Lindahl if you have any questions about what the CRA means for your business.

Laptop and cellphone on desk

Do you want to know more? Contact:

Alexander Tham

Partner | Advokat