REGULATORY WATCH BRIEF Moderate 49 📜 Final Regulation in effect

EU Cyber Resilience Act reporting obligations take effect for manufacturers

The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.

ImpactModerate 49
Type📜 Final Regulation
Statusin effect in force
JurisdictionEU
Effective11 September 2026

What happened

As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related to their products.

Why it matters for trust and compliance

  • Its status is in effect. It is in force now.
  • The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
  • Takes effect September 11, 2026.
  • It relates to CRA. The regulations library explains what that law requires.

Who is affected

technology manufacturing manufacturer manufacturers of products with digital elements

Recommended actions

  1. Map the security requirements to existing controls and close gaps.
  2. Check breach-notification procedures and timelines against the requirement.