Skip to content

EU Cyber Resilience Act: Three-Year Deadline for Product Manufacturers

Key point: Manufacturers of digital products have three years to demonstrate compliance with the new EU Cyber Resilience Act regulation.

The EU’s Cyber Resilience Act (CRA) entered into force on 11 December 2024. Companies offering products with digital components must demonstrate full compliance by 11 December 2027.

The Cyber Resilience Act has been in effect since 11 December 2024 and establishes uniform security requirements for products with digital elements in the EU. The regulation requires manufacturers to maintain higher cybersecurity standards across their entire product portfolio and to report transparently on security measures and vulnerabilities.

For CISOs, the three-year deadline until 11 December 2027 means that significant organisational adjustments will be required in the medium term. Compliance extends across the entire supply chain: from product development through security testing to documentation of vulnerability management and incident reporting.

Companies should conduct a timely audit of their current product portfolio and assess which products fall under the CRA. In parallel, establishing appropriate governance processes, technical control measures, and compliance documentation will be necessary to meet the requirements by the deadline.


Source: itwelt.at · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: