EU Cyber Resilience Act Set to Reshape Software and Connected Device Markets

5 August 2026

The European Union is moving closer to one of its most significant cybersecurity reforms with the gradual implementation of the Cyber Resilience Act (CRA), legislation that will introduce mandatory cybersecurity standards for software and connected hardware sold across the EU.

Although the regulation entered into force in December 2024, its obligations will be phased in over the next two years. The European Commission has now published detailed implementation guidance clarifying how businesses should determine whether their products fall within the scope of the new rules and what level of compliance they will require.

For technology companies, manufacturers and software developers, the guidance provides greater certainty but also confirms that compliance will extend far beyond traditional cybersecurity products.

A Wide Range of Digital Products Will Be Affected

The legislation applies to products that contain digital functionality and are capable of connecting directly or indirectly to networks or other devices.

This means the rules will cover not only cybersecurity software but also connected consumer electronics, industrial equipment, business applications and many Internet of Things (IoT) devices.

Examples include smart home equipment, enterprise software, networking hardware, industrial control systems and operating systems. Cloud services that are essential to a product’s functionality may also fall within the legislation.

Products developed solely for internal company use and never placed on the market are generally excluded, as are devices without any form of digital connectivity.

Three Levels of Compliance

A central feature of the Cyber Resilience Act is a risk-based classification system that determines the level of regulatory scrutiny required before products can enter the European market.

Most connected products will fall into the standard category, where manufacturers are permitted to assess their own compliance provided they meet the legislation’s cybersecurity requirements and maintain appropriate technical documentation.

Products considered to present greater cybersecurity risks will face stricter assessment procedures. These include technologies such as identity management systems, password managers, operating systems, internet routers, network equipment and security software.

The highest-risk category covers specialised cryptographic hardware and secure infrastructure used in critical sectors, where independent certification will generally be required before products can be marketed within the EU.

The European Commission retains the authority to update these classifications as technology and cyber threats evolve, meaning products could move into more demanding compliance categories over time.

Security Responsibilities Extend Beyond Product Launch

The regulation introduces ongoing obligations that continue throughout a product’s commercial life rather than ending when it is sold.

Manufacturers will be expected to monitor cybersecurity vulnerabilities, provide security updates throughout an appropriate support period and maintain detailed records of software components used within their products.

Many products will require support for at least five years, although equipment expected to remain operational for longer periods may require extended maintenance commitments.

The legislation also introduces stricter reporting obligations for actively exploited cybersecurity vulnerabilities, requiring rapid notification to the European Union Agency for Cybersecurity (ENISA) within defined timeframes.

Software Supply Chains Face Greater Scrutiny

Another significant feature of the legislation is the emphasis on software transparency.

Manufacturers must maintain comprehensive records of third-party software components incorporated into their products, commonly known as Software Bills of Materials (SBOMs). These inventories are intended to improve visibility across increasingly complex software supply chains and allow vulnerabilities to be identified and addressed more quickly.

The requirements reflect growing concern among regulators about the cybersecurity risks created by open-source libraries and externally developed software components that are widely reused across multiple products.

Open-Source Software Receives Special Treatment

The legislation distinguishes between community-driven open-source projects and commercial software built around open-source technologies.

Projects distributed without commercial intent generally remain outside the regulation’s scope. However, companies that package, market or monetise open-source software as commercial products will be subject to the same obligations as other software manufacturers.

The legislation also introduces a separate category for organisations that actively support commercially significant open-source projects. These organisations face lighter regulatory obligations but are still expected to maintain security policies and cooperate with market surveillance authorities where appropriate.

Some Industries Remain Outside the Regulation

Not every connected product will be governed by the Cyber Resilience Act.

Products already subject to sector-specific European legislation with equivalent cybersecurity requirements, including many medical devices, vehicles and aviation systems, are generally excluded from the new framework.

Equipment developed exclusively for national defence or security purposes also falls outside its scope.

Nevertheless, many businesses operating across multiple sectors will need to determine carefully whether individual products remain covered by existing legislation or whether the Cyber Resilience Act applies in full or in part.

Businesses Face a Tight Preparation Window

Although most compliance requirements do not become fully applicable until 11 December 2027, manufacturers have considerably less time to prepare.

Mandatory reporting requirements for actively exploited vulnerabilities and significant cybersecurity incidents begin on 11 September 2026, requiring companies to establish internal monitoring, reporting and incident response procedures well before the broader compliance framework comes into force.

Industry experts expect many businesses to spend the next 18 months reviewing product portfolios, reassessing development processes and strengthening software governance to ensure continued access to the European market.

Cybersecurity Becomes a Product Requirement

The Cyber Resilience Act represents a significant shift in European technology regulation by treating cybersecurity as a mandatory product characteristic rather than an optional feature.

Manufacturers will increasingly be expected to demonstrate not only that products function as intended, but also that they can withstand evolving cyber threats throughout their operational life.

For companies developing software, connected devices and digital services, cybersecurity is becoming a permanent component of product design, supply chain management and regulatory compliance. As implementation deadlines approach, organisations that begin preparing early are likely to be better positioned to meet the new standards while maintaining uninterrupted access to one of the world’s largest technology markets.

Source: CMS

front page info
LATEST NEWS