The First CRA Obligation Took Effect on September 11
The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies in stages. Manufacturers' reporting obligations (Article 14) began on September 11, 2026, while the remaining duties — essential cybersecurity requirements, conformity assessment, and CE marking — apply in full from December 11, 2027.
Two points deserve attention. First, the reporting obligations also cover products already placed on the EU market before December 11, 2027, so this is not only about new products. Second, every "product with digital elements" supplied to the EU is in scope, wherever the manufacturer is located. NIS2 places duties on the companies that operate equipment; the CRA places them on the manufacturers that build the equipment and its software.
Is Your Product in Scope — Industrial IoT, PLCs, HMIs, Gateways, and Embedded Software
A product with digital elements is hardware or software whose intended use involves a direct or indirect data connection to a device or network. The items most often overlooked are:
Products listed in Annex III (important) and Annex IV (critical) face stricter procedures, including third-party assessment. The final annexes list items such as routers and switches, operating systems, firewalls, and microcontrollers with security-related functions. Industrial automation and control systems, unlike in the legislative draft, do not appear as a separate entry as far as we can determine. Classification depends on a product's core functionality, however, so you should confirm it against the annex text itself.
In OEM/ODM supply, the company that places the product on the EU market under its own brand is the legal manufacturer. Because only the actual developer can provide vulnerability information and patches, buyers are likely to impose response deadlines by contract.
What to Report, by When, and to Whom
Two things must be reported: actively exploited vulnerabilities and severe incidents affecting the security of the product.
Reports go simultaneously to the competent CSIRT and ENISA through the single reporting platform operated by ENISA. For non-EU manufacturers, the competent Member State is determined by where the EU authorised representative is established (or, failing that, the importer and so on). Affected users must also be informed of the issue and of any mitigating measures.
Breaches of the reporting obligations fall into the fine bracket of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Micro and small enterprises are exempt from fines only for missing the 24-hour early warning deadline.
Four Things You Need Before You Can Report in 24 Hours
A 14-Month Roadmap to Full Application in December 2027
At full application, manufacturers must provide secure-by-design development, secure default configuration, security updates throughout the support period (in principle at least five years), and technical documentation. Most products can follow self-declaration of conformity, but Class I important products need third-party assessment unless harmonised standards are applied, while Class II important products and critical products need third-party assessment (or EU certification) regardless — so the standardisation timeline is worth tracking.
For equipment with AI functions, it is more efficient to review AI Act requirements at the same time and design the technical file once.
Support Programs for SMEs and How KITIM Can Help
Testing and certification costs can be partly covered through programs such as the Export Voucher and the Overseas Standard Certification Acquisition Support Program. Coverage and ceilings change every year, so checking the latest call for applications is a prerequisite. If you already hold ISO/IEC 27001 or IEC 62443 certification, its procedures and risk assessment framework can serve as the backbone of your CRA response. Security update functions and SBOM automation can also be framed as development scope in R&D projects or smart manufacturing supplier support programs.
KITIM helps you plan overseas certification, R&D project design, and export regulation response together. If you need support ranging from a CRA scope assessment to matching with government programs, please reach out through the KITIM consulting inquiry page.
