Cyber Resilience Act Phase 1: Reporting for Manufacturers (2026)

by Anika Shah - Technology
0 comments

On December 10, 2024, the EU’s Cyber Resilience Act officially came into force. Transition periods will expire this year, which will require manufacturers of devices and software to report in Phase 1. From September 11, 2026, the “Obligations to report actively exploited vulnerabilities and serious security incidents“. Here is a brief overview of the topic.

Der Cyber Resilience Act (CRA)

Cyber Resilience Act Phase 1: Reporting for Manufacturers (2026)Der EU Cyber Resilience Act (I CRA) creates a uniform legal framework for cybersecurity in the EU Products with digital elements. CRA requires manufacturers to securely develop digital products and provide support throughout the cybersecurity lifecycle of those products. The relevant EU information page is linked above.

OpenKritis is working this website to the EU CRA, and the BSI has the document Cyber Resilience Act published on the topic. It explains that all products sold in the EU that contain “digital elements” must comply with the CRA’s requirements.

In addition to inexpensive consumer products, this also includes B2B software and complex high-end industrial systems. “Products with digital elements” are defined in the CRA as products, including remote data processing solutions, that can be connected directly or indirectly to a device or a network.

The CRA therefore applies to both networked hardware products (e.g. smartphones, laptops, smart home products, smartwatches, networked toys, but also microprocessors, firewalls and smart meter gateways in intelligent metering systems) as well as pure software products (e.g. accounting software, computer games, mobile apps). Non-commercial open source software products are exempt from the CRA and therefore do not have to comply with the CRA’s requirements.

Fristen des Cyber Resilience Act (CRA)

The CRA entered into force on December 11, 2024, 20 days after publication in the Official Journal of the EU. The CRA will be implemented in various stages until the end of 2027. New products placed on the market must meet all requirements at this point. The following deadlines are relevant for companies that offer products that fall under the CRA:

  • September 11, 2026: Mandatory reporting of vulnerabilities and security incidents
  • December 11, 2027: All CRA requirements must be met for new products.

From December 11, 2026, there should be sufficient conformity assessment bodies for testing. The BSI is open this page Some information on this has been compiled for companies.

ONEKEY points out the obligation to report

The Düsseldorf cybersecurity company ONEKEY recently provided me with some guidance on these corporate reporting requirements with respect to the CRA. The company operates a platform for checking device software (firmware) for security defects and CRA compliance.

ONEKEY points out that the Cyber Resilience Act (CRA) will have direct effects for the first time from 2026, which manufacturers of digital devices, machines and systems with an internet connection will have to prepare for.

Meldefrist ab 11. September 2026

The Cyber Resilience Act, which officially came into force on December 10, 2024, marks a particularly important point in time for companies this year. From September 11, 2026, the “obligations to report actively exploited vulnerabilities and serious security incidents” will take effect. ONEKEY writes: Manufacturers must report security gaps and security-relevant incidents as soon as they become aware of them – within a short period of time.

To this end, the EU Agency for Cybersecurity (ENISA) is currently setting up a uniform central reporting platform – CRA Single Reporting Platform (SRP) – through which all reports must be submitted in the future.

As mentioned above, the comprehensive requirements of the CRA such as security by design, lifecycle management or CE marking under CRA proof of conformity apply in full from December 11, 2027. “The operational phase of the Cyber Resilience Act begins in 2026,” says ONEKEY Managing Director Jan Wendenburg.

In a few months, from June 11, 2026, the first conformity assessment bodies (CABs) are expected to begin their activities and check the conformity of products in advance. These are approved, independent testing centers. This allows manufacturers to obtain external proof of CRA compliance. ONEKEY CEO Jan Wendenburg explains that haste is necessary: “The affected manufacturers must have prepared their internal processes, documentation, technical evidence and security requirements by then at the latest in such a way that a CAB can check anything at all.”

External conformity assessment is mandatory for products with a high safety risk (CRA classes “critical” and “highly critical”), such as critical infrastructure components, IoT devices with high potential for damage, and industrial control systems.

“For around 90 percent of all connected products, however, a self-declaration is sufficient,” explains Jan Wendenburg. This is a declaration by the manufacturer that a digital product meets the requirements of the CRA and is placed on the market in a legally compliant manner. This must include a detailed conformity assessment, as can be achieved via the ONEKEY platform. Without such a declaration, these products may no longer be sold on the EU market after December 11, 2027.

It’s high time for the manufacturers

Jan Wendenburg explains: “It is high time for manufacturers to subject their networked devices, machines and systems to a CRA conformity assessment.” From experience with the relevant tests on the ONEKEY platform, Wendenburg knows that in most cases there are gaps, many of which are not easy to fix. Manufacturers should be prepared to invest a corresponding amount of time, money and personnel in order to meet the legal requirements that will apply to them. Wendenburg cites weaknesses in external programs from partners outside the EU with little understanding of CRA compliance, purchased components with incomplete documentation or open source software as examples.

Software BOMs required

The ONEKEY managing director explains: “One of the first steps is to create a complete software bill of materials for every networked product, a so-called Software Bill of Materials, or SBOM for short. And that often proves to be difficult.” The aim is to identify possible software vulnerabilities that could serve as a target for hackers so that they can be remedied promptly.

The CRA therefore requires a detailed list of all programs, libraries, frameworks and dependencies with exact version numbers of the individual components, information about the respective licenses, information about the authors and an overview of all known vulnerabilities and security gaps.

According to Wendenburg, many manufacturers find it difficult to meet these requirements, if only because they do not receive the required information from their suppliers in the necessary completeness. Jan Wendenburg makes it clear: “Many SBOMS are incomplete, outdated or without context about vulnerabilities. These incomplete and partially outdated software parts lists are unusable for the mandatory proof requirement in EU regulations.”

Much of the effort can be automated

However, the CRA requirements go far beyond simply providing a correct SBOM. Manufacturers are obliged to implement safety requirements during the conception and development phase of their products. This includes secure software and hardware designs, clear guidelines for dealing with vulnerabilities, the introduction of consistent risk management and mandatory security updates across defined product life cycles.

“All of these measures not only have to be carried out, but also evaluated, documented and proven,” says Jan Wendenburg, outlining the effort. He summarizes: “The upcoming first phase of implementation of the Cyber Resilience Act undoubtedly represents a milestone for digital security in Europe, but it also results in considerable effort for manufacturers.”

date: 2026-02-14 23:27:00

Related Posts

Leave a Comment