Key provisions of the Cyber Resilience Act (CRA) become applicable on 11 September 2026
As of 11 September 2026, the reporting obligations under the Cyber Resilience Act (CRA) become applicable. Manufacturers of products with digital elements now need to have procedures in place to be able to quickly report actively exploited vulnerabilities and serious security incidents.
The Cyber Resilience Act (CRA) aims to strengthen cybersecurity within the EU through mandatory requirements for products with digital elements. Products must be secure from the design stage onwards ("secure by design") and protected continuously throughout their entire lifecycle. The regulation harmonises the rules between the EU member states and imposes requirements on transparency regarding products' security properties, as well as prescribing responsibility for addressing vulnerabilities.
The regulation covers a broad range of products, both hardware (e.g. IoT devices and industrial control systems) and software (e.g. apps and computer programs).
The regulation will mainly apply from 11 December 2027, but as early as 11 September 2026 the reporting obligations for manufacturers will start to apply. Manufacturers must notify the coordinating CSIRT and the EU cybersecurity agency ENISA of any actively exploited vulnerability in a product with digital elements that the manufacturer becomes aware of. In Sweden, CERT-SE at the National Cyber Security Centre (NCSC) is the national CSIRT.
The notification takes place in three steps: an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure has become available. The same model applies to serious incidents affecting the security of the product.
Manufacturers covered by the CRA must already now have operational routines and internal processes in place to detect, assess and report actively exploited vulnerabilities and serious security incidents within the short deadlines. This includes having designated contact channels to the CSIRT and ENISA and being able to use the joint reporting platform, even though the products do not yet need to fully comply with the essential cybersecurity requirements (these will only apply from 11 December 2027).
Non-compliance may result in sanctions, including fines of up to 2.5 percent of global annual turnover.
Please feel free to contact Advokatfirman Lindahl if you have any questions about what the CRA means for your business.
Do you want to know more? Contact:
Alexander Tham
Partner | AdvokatCarousel items
-
Knowledge
9/11/2026
Key provisions of the Cyber Resilience Act (CRA) become applicable on 11 September 2026
Key provisions of the Cyber Resilience Act (CRA) come into effect on 11 September 2026. Read about the new reporting requirements and what companies need to do.
-
Cases and transactions
9/9/2026
Lindahl advises Image Systems AB (publ) on fully subscribed rights issue of shares
Lindahl acted as legal adviser to Image Systems AB (publ) on a fully subscribed rights issue of approximately SEK 21.4 million.
-
News articles
9/4/2026
Mikael Wärnsby represents Sweden at international conference on new nuclear power
Mikael Wärnsby represented Sweden at EFELA’s international conference on licensing and regulatory frameworks for new nuclear power in Europe.
-
Portraits
7/3/2026
Jesper on business-oriented legal advice in energy: "It is not enough for the advice to be correct"
Lindahl's energy team is recognised in Legal 500 for combining deep regulatory expertise with broad commercial legal experience – find out how they support clients in a rapidly evolving sector.
-
Read more news and insights?