What changes for connected products

The Cyber Resilience Act frames cybersecurity for many products with digital elements made available in the European Union. It also concerns manufacturers established outside the EU when their products are sold in Europe.

The timeline is a product and commercial matter: certain vulnerability-reporting obligations apply from September 11, 2026, while most requirements apply from December 11, 2027. Exact scope depends on the product, intended use and distribution chain.

Why selling can become more difficult

A functional product that cannot show how it is built, updated, maintained and secured creates risk for brands, importers, distributors and professional buyers. Evidence requests arrive earlier: architecture, versions, patches, support policy, vulnerability handling and documentation.

This is not only a marking exercise. Missing security processes can slow customer validation, weaken a distribution relationship or make late compliance much more expensive. The goal is to avoid security becoming a blocker when a product enters the European market.

Product intended for the European market?

Check technical evidence before the next commercial milestone

A technical scoping phase identifies firmware, SBOM, update, vulnerability and documentation gaps before they become a blocker for a customer, distributor or importer.Contact us

Technical capabilities to establish

For a router, IoT gateway, industrial device, camera or appliance, useful foundations include a reliable product inventory, controlled build chain, signed updates, access control and usable logs.

Teams should also track components and vulnerabilities, maintain a useful SBOM, receive reports, assess product impact, coordinate fixes and retain evidence for every delivered version. These practices improve security and commercial credibility together.

How to start without slowing product teams

Start with a short scope: products and versions, manufacturer-importer-distributor roles, software components, update mechanisms, support lifecycle and existing evidence. This separates urgent actions from longer engineering work.

Then prioritise controls that reduce market-access risk: administration access, exposed interfaces, secrets, signing, patches, CVE tracking, SBOM, disclosure process and security documentation. The manufacturer retains legal responsibility; technical work makes that responsibility demonstrable.

FAQ

Does the CRA apply to a Chinese or American manufacturer?

Yes, when a product with digital elements is made available on the EU market. Exact scope and obligations must be confirmed for the product concerned.

Should a team wait until 2027?

No. Firmware security, updates, components and documentation are built into the product lifecycle. Waiting for launch or a customer request usually makes remediation more expensive.

Does a technical audit replace legal advice?

No. An audit provides evidence and a technical plan. Legal responsibilities and the applicable conformity route must be confirmed with competent advisers.

Related expertise

Official sources

This article is informational and does not replace a legal assessment of a product or its market-access route.