Leadership1 publisher3 min readPublished
Cyber Resilience Act reporting duties start 15 months before the regulation fully applies
The Commission's plain-language summary of Regulation (EU) 2024/2847 lays out staggered start dates for anyone shipping hardware or software into the EU, the earliest in June 2026 and the last in December 2027.
The Board Room · Leadership desk
What happened
- The Cyber Resilience Act applies to hardware and software products made available on the EU market, and it covers both final products and components placed on the market separately.
- Regulation (EU) 2024/2847 entered into force on 10 December 2024 and becomes fully applicable on 11 December 2027.
- Two parts start earlier: Chapter IV on the notification of conformity assessment bodies from 11 June 2026, and the Article 14 reporting obligations from 11 September 2026.
- The manufacturer definition covers any person marketing a product with digital elements under its own name or trademark, whether for payment, monetisation or free of charge.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A firm shipping a module for someone else to integrate is reachable in its own right, so it cannot leave assessment to the integrator that puts the finished product on the market.
- decision A corporately funded open-source project has to decide which definition it falls under, because a steward and a manufacturer are not carrying the same set of obligations.
- constraint Any vendor that needs third-party assessment is competing for capacity that can only be designated inside an 18-month window, and designation of the bodies has to happen before they can take work.
- precedent Because reporting bites more than a year before the rest of the regime, the first thing companies are likely to be judged on under the CRA is how they report an incident.
The order of those dates decides what a 2026 product plan has to carry. Designation of conformity assessment bodies opens 18 months before the regulation binds in full [2]. The Article 14 reporting duty starts three months after designation opens, and runs 15 months ahead of full applicability [4][1]. From entry into force to full applicability is three years and a day [3].
Scope turns on one definition in the glossary. A product with digital elements includes its remote data processing solutions. Those are data processing at a distance for which the software is designed and developed by the manufacturer, or under the manufacturer's responsibility, and whose absence would prevent the product from performing one of its functions [8]. A sensor that cannot report without its vendor's cloud service is therefore assessed with that service attached.
The glossary also fixes where one party's obligation stops and another's begins. A distributor is a supply-chain party other than the manufacturer or importer that makes a product available on the Union market without affecting its properties [10]. An importer is established in the Union and places on the market a product bearing the name or trademark of a person established outside it [11]. Conformity assessment itself is defined as the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled [12].
A plain-language webpage is not a legal event. The text was prepared by Commission services. It is "not meant to systematically cover the full scope of the Regulation", and it states that it "is not representative of the European Commission's official position". Persons who may be subject to the CRA are told to refer to the text of the Regulation published in the Official Journal of the European Union [9]. Compliance work has to sit on that published text. What the page adds is the sequence and the definitions in language an engineering lead can read without counsel in the room, alongside FAQs published with it [15].
There is a second definition that a corporate-funded project has to place itself against. An open-source software steward is a legal person other than a manufacturer. Its purpose is to provide sustained, systematic support for the development of specific free and open-source products intended for commercial activities, and it ensures the viability of those products [7].
For a vendor selling into the EU, the choice this quarter is when to start assessing. Start early and design decisions get locked before harmonised standards exist. A harmonised standard is one adopted by a European standardisation organisation on the basis of a request from the Commission for the application of Union harmonisation legislation [16]. Start late and the queue forms inside that 18-month window, in front of notified bodies that are conformity assessment bodies designated in accordance with Article 43 [13][2].
What to watch
- Whether harmonised standards under the CRA are published early enough for a vendor to design against them before December 2027.
- How many conformity assessment bodies are actually notified once Chapter IV starts applying on 11 June 2026.
- Whether the FAQs published alongside the summary narrow or widen the open-source steward category.