Contact

What are you looking for?

The CRA Reporting Obligation Enters into Force

Sep 29, 2026

The Cyber Resilience Act (CRA), also known as Regulation (EU) 2024/2847, defines common minimum cybersecurity requirements and standards for products with digital elements, including hardware, software and remote data processing solutions made available on the EU market. Its aim is to improve the digital security of products, reduce product vulnerabilities and thereby create trust and added value for end users. The CRA improves the level of cybersecurity in many products and throughout the supply chain, and requires up-to-date security updates for products and software. It also lays down due diligence obligations for manufacturers and reporting obligations for incidents. The three key areas of cyber resilience are risk management, recovery and response, and business continuity.
In the future, the CRA will be a mandatory part of CE marking requirements for placing products on the European market.

The Cyber Resilience Act (CRA) applies to economic operators such as manufacturers, software developers, distributors and importers that place new or updated digital products on the European market. It is important to understand that the CRA regulates products, unlike NIS2 or DORA, which regulate the network and information systems of critical economic operators.

The Cyber Resilience Act defines four categories of regulated products:

  1. Default category
  2. Class I important products
  3. Class II important products
  4. Critical products

Reporting of vulnerabilities and security incidents enters into force in September 2026

Manufacturers, importers, distributors and open-source software stewards should now be aware of their obligations under the new CRA. From 11 September 2026, manufacturers must actively report actively exploited product vulnerabilities and severe incidents affecting product security through the Single Reporting Platform (SRP) maintained by ENISA. The obligation applies not only to new products but also to products already placed on the EU market.

When you become aware of a vulnerability or security incident affecting your product, remember to report it via the ENISA SRP platform:

  • Early warning notification within 24 hours
    Verify the mandatory information and submit the early warning notification.
  • Incident notification within 72 hours
    Check the mandatory information and submit the incident notification.
  • Final vulnerability report 14 days after a corrective or mitigating measure is available
    Check the mandatory information and submit the final report.
  • Final incident report within one month of submitting the incident notification
    Check the mandatory information and submit the final report.

More detailed reporting instructions for manufacturers are available on the ENISA Single Reporting Platform website.

Prepare for CE marking requirements in good time

There is still time to prepare without panic: the essential cybersecurity requirements of the CRA for products will apply from 11 December 2027 as a mandatory part of CE marking. Products placed on the market after that date must meet the essential cybersecurity requirements. Time passes quickly, so it is worth becoming familiar with the general CRA requirements and following the development of product-specific cybersecurity standards.

In August 2026, ETSI launched the approval process for 17 draft product standards proposed for harmonization in support of the CRA.

Timeline

Prepare now. There is only until 2027 to prepare for mandatory product approval.

  • 2024: The CRA enters into force
  • 11 September 2026: Incident reporting becomes mandatory, including for uncertified products
  • 11 December 2027: The CRA applies in full and becomes a mandatory part of CE marking.

How SGS can help you achieve CRA compliance

What exactly does the CRA mean for your company? How can you identify gaps in your product’s cybersecurity measures? This is where SGS can help. We provide information to support decision-making through gap assessment and by verifying conformity independently and impartially, in a way that creates added value for your company and trust among your customers. The CRA covers a wide range of products, and SGS can provide value-adding services throughout the product value chain. SGS can be especially helpful when it comes to Class II important products and critical products, which require mandatory third-party certification. We are involved in industry standardization work and closely monitor how the requirements develop. We have expertise that can benefit you.

Need more information? We are ready to review the cybersecurity measures you are planning and create a service solution in a tailored joint meeting, so that you can ensure your product meets the CRA requirements.

Interested? Contact us and start the conversation.

About SGS

SGS is the world’s leading Testing, Inspection and Certification company. We operate a network of over 2,500 laboratories and business facilities across 115 countries, supported by a team of over 100,000 dedicated professionals. With more than 145 years of service excellence, we combine the precision and accuracy that define Swiss companies to help organizations achieve the highest standards of quality, compliance and sustainability.

Our brand promise – when you need to be sure – underscores our commitment to trust, integrity and reliability, enabling businesses to thrive with confidence. We proudly deliver our expert services through the SGS name and a portfolio of trusted specialized brands, including Applied Technical Services, Brightsight, Bluesign and Nutrasource.

SGS is publicly traded on the SIX Swiss Exchange under the ticker symbol SGSN (ISIN CH1256740924, Reuters SGSN.S, Bloomberg SGSN SW).

News & Insights

  • SGS - Finland - Helsinki

Takomotie 8,

FI-00380,

Helsinki,

Finland