Skip to content

Cyber Resilience Act: Implementation deadline December 2027 for product manufacturers

Summary: The Cyber Resilience Act requires all manufacturers of products with digital elements to achieve comprehensive compliance with enhanced security requirements starting 11 December 2027.

The EU’s Cyber Resilience Act (CRA) entered into force on 11 December 2024. Companies offering products with digital elements must demonstrate full compliance by 11 December 2027.

The Cyber Resilience Act imposes significant cybersecurity requirements for products with digital components. The regulation applies to manufacturers placing such products on the EU market. The three-year transition period from the entry into force on 11 December 2024 to 11 December 2027 gives companies time to adapt their processes and systems.

For CISOs, the CRA entails concrete obligations: manufacturers must document security concepts, establish vulnerability management processes, embed cybersecurity requirements in development, and conduct regular security testing. Additionally, obligations to report critical vulnerabilities to the relevant authorities are provided for. Compliance is demonstrated through conformity assessments and certifications.

The remaining time until end of 2027 should be used for systematic analysis of affected product portfolios, assessment of existing security processes, and identification of adjustment needs. Companies that already develop according to high security standards will require fewer adjustments than those with deficits in vulnerability management or secure development lifecycle.


Source: itwelt.at · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: